All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Nearly 2,000 Hacked WordPress Sites Used for Malware Distribution

Created at 20 Aug · 4:41 PM1 source↑ Market-relevant
IN SHORT

Cybersecurity firm Check Point Research discovered nearly 2,000 compromised WordPress websites being used to distribute malware, steal data, and deploy ransomware. The attackers' operational security failures exposed internal tools and victim data, including over 31,000 screenshots.

Key Numbers

2,000hacked WordPress sites used for malware
6,000unique IP addresses compromised
1,852compromised IP addresses in the United States
630compromised IP addresses each in Russia and India
31,000screenshots collected from victims' computers
700archives containing stolen data

Who's Involved

Check Point Research
cybersecurity firm that identified the malware operation
StopAndProtect
malware family and operation
Jaromír Horejsi
Check Point researcher
Kash Patel
FBI Director linked to an apparel website
Jamf Threat Labs
security firm that found ClickFix-style malware
Microsoft
researchers who warned of hackers using compromised websites
Nearly 2,000 Hacked WordPress Sites Used for Malware Distribution

↳ Why This Matters

This incident highlights the pervasive threat of compromised websites being weaponized for cybercrime, impacting users through data theft, ransomware, and credential harvesting. The attackers' operational failures offer valuable insights into their methods, aiding cybersecurity efforts.

Key facts

  • Nearly 2,000 hacked WordPress websites were utilized for malware distribution, data theft, and ransomware deployment.
  • The StopAndProtect malware operation employs a suite of criminal software for various malicious activities.
  • Attackers' operational security lapses led to the exposure of internal tools and victim data, including screenshots and stolen files.
  • As of July 24, the campaign had compromised over 6,000 unique IP addresses worldwide.

Nearly 2,000 compromised WordPress websites have been transformed into criminal infrastructure by the StopAndProtect malware operation, according to a report by cybersecurity firm Check Point Research. These sites were used to distribute malware, steal data, monitor victims, and deploy ransomware.

The operation utilizes a comprehensive toolkit of malicious software, with components designed for file encryption, silent data theft, screen locking, and facilitating live communication between attackers and their victims. The malware primarily targets Windows users, initiating with a deceptive CAPTCHA on compromised websites. Victims are then prompted to execute a PowerShell command that installs malware capable of stealing credentials, cryptocurrency wallet seed phrases, spreading via networks and USB drives, and deploying ransomware.

Significant operational security failures by the attackers provided researchers with deep insights into the operation. These failures exposed internal files, including detailed infection logs from victims' machines, screenshots from infected computers, and the source code for tools used to manage the compromised websites. Between mid-May and the end of July, researchers collected over 31,000 screenshots and more than 700 archives containing stolen data, such as documents, passwords, and cryptocurrency wallet files.

By July 24, the campaign had compromised more than 6,000 unique IP addresses globally, with 1,852 in the United States, and 630 each in Russia and India. Check Point researchers believe the threat actor may have accidentally infected themselves, further aiding their understanding of the operation and the number of controlled domains. The ClickFix malware, associated with this campaign, has appeared in other malware campaigns this year, including those targeting macOS visitors and distributed via sponsored ads on X.

Frequently asked questions

It is a cybercrime operation that uses nearly 2,000 hacked WordPress websites to distribute malware, steal data, and deploy ransomware. It employs a toolkit of various malicious software components.

The malware typically starts with a fake CAPTCHA on a compromised website. Victims are then tricked into running a PowerShell command that installs malware capable of stealing credentials, crypto wallet information, and spreading through networks and USB drives.

The stolen data includes credentials, cryptocurrency wallet seed phrases, documents, passwords, and activity logs. Researchers collected over 31,000 screenshots and hundreds of archives of sensitive information.

The attackers made operational security mistakes, exposing internal files, infection logs, victim screenshots, and the source code of their management tools, which allowed researchers to analyze their methods.

What Happens Next

01The report did not specify if macOS and Linux users are affected.
02Researchers continue to analyze the exposed files to understand the full scope of the operation.

How It Developed

Check Point Research identified nearly 2,000 hacked WordPress sites used by the StopAndProtect malware operation.
The operation uses a toolkit of criminal software for encryption, data theft, and ransomware.
Attackers' operational security failures exposed internal files, tools, and victim data.
Over 6,000 unique IP addresses were compromised globally by July 24.
Researchers collected over 31,000 screenshots and 700 archives of stolen data.

Sources

T1
Nearly 2,000 Hacked WordPress Sites Turned Into Criminal InfrastructureDecrypt

Related Stories

One-third of web pages published since ChatGPT's launch show AI authorship
20 Aug · 5:56 PM
Canvas data breach impacts over 153,000 students, staff
20 Aug · 7:40 AM
People-search service ClarityCheck exposed millions of face images
20 Aug · 1:41 PM
Student Thwarts AI's Attempt to Inject Malware into Open-Source Software
20 Aug · 12:06 PM
Grok LLM Exfiltrates User Data Via Encrypted Instructions
20 Aug · 1:06 PM