Cybersecurity researchers have uncovered a global cybercrime operation that has compromised nearly 2,000 WordPress websites and turned them into infrastructure for distributing malware, controlling infected systems and storing stolen data.
Check Point Research is tracking the campaign as StopAndProtect after discovering a ransomware family with the same name in May 2026. Researchers found that the operation does not depend on a single malware strain but instead uses a collection of tools designed for different purposes, including data theft, ransomware, screen locking, credential stealing and communication with victims.
The attacks begin with ClickFix-style social engineering. Visitors are shown fake CAPTCHA pages that instruct them to perform unusual actions, eventually leading to the execution of a PowerShell command. This launches a series of .NET downloaders and loaders before deploying the campaign’s main components.
The malware toolkit includes SilentEncryptor, NetworkShareScanner, a VBS spreader, LockScreen, SimpleChatProxy and SilentDataCollector. Depending on the attack, the operators can encrypt computers, spread through network shares and removable drives, lock victims’ screens, communicate with victims and collect information about files stored on infected systems.
However, researchers said ransomware is not always deployed. In many cases, the attackers appear to focus on quietly identifying files and stealing specific documents from compromised computers.
The operation relies heavily on hacked WordPress websites. These sites are used to host malware, act as command-and-control infrastructure and store logs and information collected from victims.
Check Point estimates that nearly 2,000 WordPress sites have been compromised. Many of the affected websites were running outdated versions of WordPress and vulnerable plugins. One compromised website examined by researchers was running a WordPress version from 2021 and was potentially exposed to around 40 different vulnerabilities.
The attackers also modified compromised websites to display fake CAPTCHA prompts to visitors. These pages were designed to make malicious commands appear legitimate and trick users into executing them on their own computers.
The infection process uses multiple stages. The first .NET downloader reports information to the command-and-control server and retrieves the next stage. A second downloader performs additional checks, including sandbox detection, before launching the campaign’s main components.
SilentEncryptor can encrypt infected computers or target specific host names. NetworkShareScanner is designed to spread through SMB and USB connections, while the VBS spreader can move the malware across hard drives and removable media and use WMI for lateral movement.
The LockScreen component blocks user input and displays a ransom message containing a payment QR code. SimpleChatProxy provides a custom communication channel between attackers and victims, while SilentDataCollector creates a list of drives, encrypts the information and sends it back to the command-and-control server.
Newer versions of the data-stealing component have added more surveillance capabilities. Researchers observed functionality for keylogging, detecting valid email addresses, stealing information from WhatsApp, managing network shares and taking screenshots of user activity every 30 seconds.
The WhatsApp feature is particularly notable. Operators can provide a search keyword, such as a contact name, and the malware waits until the victim becomes inactive. It then uses WhatsApp automation to search for the specified contact, open the contact information and capture a screenshot.
Researchers also discovered that attackers were using a ZIP archive containing a PHP file called uploader-installer.php to install a custom WordPress plugin. The plugin creates a must-use plugin inside the WordPress wp-content/mu-plugins directory.
The malicious plugin allows anyone with valid credentials to upload arbitrary files, including PHP files, to locations within the WordPress installation. Because PHP files can be uploaded and executed, the functionality can potentially provide a path to remote code execution.
After the attackers interfere with a website, the plugin can deactivate and delete itself, making the activity harder to detect.
The compromised WordPress sites were also used to store stolen information. Researchers identified more than 700 archives uploaded between mid-May and the end of July 2026. Some of the stolen material reportedly included internal development files and tools belonging to the attackers themselves.
Among the discovered files was a custom automation utility called fMain.frm, which the researchers said was designed to help the operators manage large numbers of compromised WordPress websites.
The automation tool could reportedly upload and delete PHP scripts, control fake CAPTCHA pages and manage caching on compromised websites. This gave the attackers a way to operate their network of hacked websites at scale.
Researchers also found a malicious WordPress plugin named “verify” that could replace a site’s legitimate content with a fake CAPTCHA page for visitors using non-Windows devices. The plugin was activated using a file called activator.php, which was subsequently deleted.
By July 24, 2026, the campaign had compromised more than 6,000 unique IP addresses. The largest numbers were recorded in the United States with 1,852 addresses, followed by Russia and India with 630 each.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Check Point said the StopAndProtect campaign demonstrates how attackers can transform large numbers of poorly maintained WordPress websites into distributed infrastructure for malware delivery, surveillance, data theft and ransomware.
Researchers recommend keeping WordPress, plugins and security software updated and being cautious of unexpected CAPTCHA pages that ask users to copy, paste or execute commands. Users should leave websites that instruct them to perform unusual actions outside the normal browser experience.
Nearly 2,000 WordPress Sites Hacked in Global Malware Campaign





