StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status …
Intelligence analysis by Llama

A large-scale campaign is being tracked by Check Point Research under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together.
Imagine a group of hackers using thousands of websites to spread malware and steal data. They use a special tool to infect the websites and make them do their bidding. The tool has different parts that work together to steal information and spread malware. It's like a big robot that can do many things to help the hackers.
Analysis
StopAndProtect Campaign Overview
The StopAndProtect campaign is a large-scale cybercrime operation that has been tracked by Check Point Research. The campaign involves the use of thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.
Infection Chain
The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders. This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility, and credential stealer.
Components of the Toolkit
The toolkit consists of six components:
- SilentEncryptor: encrypts either all currently infected computers or only computers with given host names
- NetworkShareScanner: functions like an SMB/USB worm to spread to other devices
- VBS spreader: propagates the malware to hard disks and removable media, scans the network, and laterally moves via WMI
- LockScreen: blocks user input and displays a ransom message with a payment QR code
- SimpleChatProxy: is a custom chat application for communicating between the victim and operator
- SilentDataCollector: generates a list of all drives, encrypts it, and exfiltrates this list to the C2 server
Features of the Stealer
The stealer has several features, including a keylogger with valid email address detection, exfiltration from WhatsApp, mapping and unmapping network shares, and capturing screenshots of user activity every 30 seconds. The operator can upload a command file to the server that the stealer reads to harvest specific files.
Compromised WordPress Sites
The threat actors make use of a ZIP archive containing a PHP file (
Key points
- The StopAndProtect campaign is a large-scale cybercrime operation that uses thousands of hacked WordPress websites to spread malware and steal data.
- The infection chain begins with a ClickFix social engineering attack and involves the deployment of additional .NET downloaders and loaders.
- The toolkit consists of six components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility, and credential stealer.
- The stealer has several features, including a keylogger with valid email address detection, exfiltration from WhatsApp, mapping and unmapping network shares, and capturing screenshots of user activity every 30 seconds.
- The campaign has compromised more than 6,000 unique IP addresses, with most of them located in the U.S.
If the StopAndProtect campaign is shut down, it could prevent thousands of websites from being used to spread malware and steal data. This could help protect individuals and organizations from cyber threats.
If the campaign is not shut down, it could continue to spread malware and steal data, causing significant harm to individuals and organizations.



