StopAndProtect Campaign Exploits Nearly 2,000 Hacked WordPress Sites for Malware Distribution and Data Theft

Published:

spot_img

Cybersecurity researchers have identified a significant cybercrime operation known as StopAndProtect, which exploits nearly 2,000 hacked WordPress websites to distribute malware and facilitate data theft. This operation utilizes a variety of malicious tools, including ransomware, credential stealers, and other components that work in tandem to compromise systems and exfiltrate sensitive information.

According to reporting by The Hacker News, the campaign was first detected in mid-May 2026, beginning with a social engineering attack that deploys a PowerShell command to install additional malware. The compromised sites serve multiple roles, including hosting malware, acting as command-and-control servers, and storing logs from infected systems.

Check Point Research noted that many of the hacked WordPress sites were running outdated versions of the platform, making them vulnerable to exploitation. The operation has been linked to a range of malicious activities, including the covert theft of files and the deployment of ransomware in some instances. The attackers have also been observed using a custom plugin that allows them to upload arbitrary files, potentially leading to remote code execution.

As of late July 2026, the campaign has affected over 6,000 unique IP addresses, primarily in the United States, Russia, and India. Researchers emphasize the importance of maintaining updated security measures and being cautious of unexpected prompts that could lead to malware infections.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

OpenAI Focuses on AI-Native Growth in UAE with Local Data Residency Initiatives

OpenAI Targets AI-Native Growth in UAE with Local Data Residency Initiatives Dubai — OpenAI is intensifying its focus on the UAE as it seeks to...

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild. These vulnerabilities have...

Red Hat OpenShift Container Platform 4.22.10 includes important security update

Red Hat has announced the release of OpenShift Container Platform version 4.22.10, which includes critical updates aimed at addressing various bugs and enhancing system...

CrowdStrike Enhances AI Detection Triage with Reasoning-Enabled Models

In the realm of cybersecurity, the ability to discern genuine threats from benign...