WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
Key Takeaways A new malware campaign, “StopAndProtect,” is weaponizing thousands of compromised WordPress sites as command-and-control (C2) infrastructure. The operation employs a...
Key Takeaways
- A new malware campaign, “StopAndProtect,” is weaponizing thousands of compromised WordPress sites as command-and-control (C2) infrastructure.
- The operation employs a sophisticated double-extortion model, combining ransomware deployment with extensive data exfiltration, including sensitive documents, credentials, and communication logs.
- Initial infection relies on fake CAPTCHA prompts that trick users into executing malicious PowerShell commands.
- Over 6,000 unique victim IP addresses have been identified globally, with the United States, Russia, and India showing the highest infection rates.
A sophisticated new malware operation, dubbed StopAndProtect, is leveraging thousands of hijacked WordPress websites to establish a vast, resilient command-and-control (C2) network. This campaign engages in a dual-pronged attack, combining ransomware deployment with the surreptitious theft of critical corporate data, including confidential documents, system snapshots, user credentials, and active communication records from infected machines worldwide.
Table Of Content
Internal logs, inadvertently exposed due to the threat actors’ operational security lapses, reveal a staggering count of over 6,000 distinct victim IP addresses across the globe. The highest concentrations of these infections have been observed in the United States, Russia, and India. The operators actively manage approximately 2,000 compromised WordPress domains, utilizing them as a dynamic and robust infrastructure for distributing malicious payloads, maintaining persistent control channels, and storing exfiltrated data.
Hackers Weaponize WordPress Sites as C2 Servers
The primary method of initial compromise involves injecting deceptive fake CAPTCHA lures directly onto vulnerable WordPress websites. When unsuspecting visitors navigate to these compromised pages, they are confronted with a fraudulent human verification prompt. This prompt instructs them to copy and paste a malicious PowerShell command directly into their system’s terminal.
Upon execution, this command triggers a complex, multi-stage infection process. This sequence is orchestrated by a pair of PowerShell scripts and several modular .NET loaders, culminating in the deployment of a comprehensive suite of malicious tools. This toolkit encompasses ransomware, credential stealers, screen lockers, VBS spreaders, and USB network worms.
As detailed in an investigative report published by Check Point Research, the StopAndProtect operation deviates significantly from typical “smash-and-grab” cyberattacks. Instead, it prioritizes meticulous intelligence gathering and strategic monetization. The threat actors engage in extensive document enumeration, log keystrokes, map connected network shares, capture periodic screenshots, and scrape local communication data. This comprehensive reconnaissance precedes any decision to deploy ransomware, allowing them to target high-value assets effectively.
Security researchers were able to gain insight into the operation’s inner workings due to several compromised WordPress staging servers that were left with exposed PHP endpoints and open directory listings accessible to the public. This oversight allowed researchers to examine internal activity logs, victim telemetry, and even the raw source code of the malicious components. In a particularly revealing incident, one of the operators seemingly infected their own personal machine, inadvertently uploading internal development files. These files included a custom Visual Basic 6 tool designed for the mass management of hijacked WordPress domains, enabling them to toggle fake CAPTCHA overlays and deploy new payloads across their botnet.
This campaign starkly underscores the severe risks associated with unmaintained Content Management Systems. Analysis of one compromised site revealed it had been running without updates since 2021, leaving it exposed to nearly 40 unpatched vulnerabilities. Unaddressed WordPress security flaws and outdated plugins provide adversaries with persistent backdoors, transforming legitimate websites into malicious relays. Addressing these compromised endpoints is crucial for disrupting modern ransomware deployment tactics before adversaries can move laterally within internal networks.
Compromised websites are no longer merely serving as simple phishing hosts or traffic redirectors; they are now being weaponized as fully functional C2 servers, capable of blending malicious communications with legitimate web traffic. This evolution necessitates a heightened focus on web security.
What You Should Do
- For Website Administrators:
- Enforce rigorous update schedules for WordPress core files, active themes, and all third-party plugins.
- Regularly scan your website for unauthorized PHP scripts, modified
.htaccessfiles, and suspicious administrator accounts. - Implement strong access controls and multi-factor authentication for all administrative interfaces.
- For End Users:
- Never copy and paste commands into your terminal or command prompt based on prompts from websites, even if they appear to be for “human verification.”
- Be suspicious of any unexpected CAPTCHA or verification requests on websites.
- Ensure your operating system and web browsers are kept up to date.
- For Security Teams:
- Monitor endpoint telemetry for unauthorized PowerShell execution and other anomalous script activity.
- Implement robust network monitoring to detect unusual outbound data transfers from internal systems.
- Educate users about social engineering tactics, particularly those involving unexpected command execution prompts.
IOCs
| compromised websites | maximumrock[.]ro platinumcar[.]ca norakremer.co[.]uk pharmart[.]ae ksr-racingparts[.]com |
| compromised base C&C websites | v-k.com[.]ua www.lapellelaser[.]pl www.parsrulman[.]com mectcalcutta[.]com discherniation[.]com |
| PowerShell script stage 1 | cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0 |
| PowerShell script stage 2 | cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9 |
| stage 1 – downloader | 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b 8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5 4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504 |
| stage 2 – downloader & loader | 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527 7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c 976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153 |
| stage 3 – encryptor | b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489 65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143 0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40 |
| stage 3 – SMB/USB worm | 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4 10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0 f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41 |
| stage 3 – lockscreen | 11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e 2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c 38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9 |
| stage 3 – credential stealer | 23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70 |
| stage 3 – VBS spreader | b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad |
| stage 3 – chat utility | 3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9 3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8 |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.