Key facts
- Nearly 2,000 hacked WordPress websites were utilized for malware distribution, data theft, and ransomware deployment.
- The StopAndProtect malware operation employs a suite of criminal software for various malicious activities.
- Attackers' operational security lapses led to the exposure of internal tools and victim data, including screenshots and stolen files.
- As of July 24, the campaign had compromised over 6,000 unique IP addresses worldwide.
Nearly 2,000 compromised WordPress websites have been transformed into criminal infrastructure by the StopAndProtect malware operation, according to a report by cybersecurity firm Check Point Research. These sites were used to distribute malware, steal data, monitor victims, and deploy ransomware.
The operation utilizes a comprehensive toolkit of malicious software, with components designed for file encryption, silent data theft, screen locking, and facilitating live communication between attackers and their victims. The malware primarily targets Windows users, initiating with a deceptive CAPTCHA on compromised websites. Victims are then prompted to execute a PowerShell command that installs malware capable of stealing credentials, cryptocurrency wallet seed phrases, spreading via networks and USB drives, and deploying ransomware.
Significant operational security failures by the attackers provided researchers with deep insights into the operation. These failures exposed internal files, including detailed infection logs from victims' machines, screenshots from infected computers, and the source code for tools used to manage the compromised websites. Between mid-May and the end of July, researchers collected over 31,000 screenshots and more than 700 archives containing stolen data, such as documents, passwords, and cryptocurrency wallet files.
By July 24, the campaign had compromised more than 6,000 unique IP addresses globally, with 1,852 in the United States, and 630 each in Russia and India. Check Point researchers believe the threat actor may have accidentally infected themselves, further aiding their understanding of the operation and the number of controlled domains. The ClickFix malware, associated with this campaign, has appeared in other malware campaigns this year, including those targeting macOS visitors and distributed via sponsored ads on X.
