Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: Medusa Ransomware Steals Data, Disables Security, Encrypts Networks
August 18, 2026
WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
August 18, 2026
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
Home/CyberSecurity News/WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
CyberSecurity News

WordPress Sites Hijacked for StopAndProtect Malware C2 Servers

Key Takeaways A new malware campaign, “StopAndProtect,” is weaponizing thousands of compromised WordPress sites as command-and-control (C2) infrastructure. The operation employs a...

Sarah simpson
Sarah simpson
August 18, 2026 4 Min Read
3 0

Key Takeaways

  • A new malware campaign, “StopAndProtect,” is weaponizing thousands of compromised WordPress sites as command-and-control (C2) infrastructure.
  • The operation employs a sophisticated double-extortion model, combining ransomware deployment with extensive data exfiltration, including sensitive documents, credentials, and communication logs.
  • Initial infection relies on fake CAPTCHA prompts that trick users into executing malicious PowerShell commands.
  • Over 6,000 unique victim IP addresses have been identified globally, with the United States, Russia, and India showing the highest infection rates.

A sophisticated new malware operation, dubbed StopAndProtect, is leveraging thousands of hijacked WordPress websites to establish a vast, resilient command-and-control (C2) network. This campaign engages in a dual-pronged attack, combining ransomware deployment with the surreptitious theft of critical corporate data, including confidential documents, system snapshots, user credentials, and active communication records from infected machines worldwide.

Table Of Content

  • Key Takeaways
  • Hackers Weaponize WordPress Sites as C2 Servers
  • What You Should Do
  • IOCs

Internal logs, inadvertently exposed due to the threat actors’ operational security lapses, reveal a staggering count of over 6,000 distinct victim IP addresses across the globe. The highest concentrations of these infections have been observed in the United States, Russia, and India. The operators actively manage approximately 2,000 compromised WordPress domains, utilizing them as a dynamic and robust infrastructure for distributing malicious payloads, maintaining persistent control channels, and storing exfiltrated data.

Hackers Weaponize WordPress Sites as C2 Servers

The primary method of initial compromise involves injecting deceptive fake CAPTCHA lures directly onto vulnerable WordPress websites. When unsuspecting visitors navigate to these compromised pages, they are confronted with a fraudulent human verification prompt. This prompt instructs them to copy and paste a malicious PowerShell command directly into their system’s terminal.

Upon execution, this command triggers a complex, multi-stage infection process. This sequence is orchestrated by a pair of PowerShell scripts and several modular .NET loaders, culminating in the deployment of a comprehensive suite of malicious tools. This toolkit encompasses ransomware, credential stealers, screen lockers, VBS spreaders, and USB network worms.

As detailed in an investigative report published by Check Point Research, the StopAndProtect operation deviates significantly from typical “smash-and-grab” cyberattacks. Instead, it prioritizes meticulous intelligence gathering and strategic monetization. The threat actors engage in extensive document enumeration, log keystrokes, map connected network shares, capture periodic screenshots, and scrape local communication data. This comprehensive reconnaissance precedes any decision to deploy ransomware, allowing them to target high-value assets effectively.

Security researchers were able to gain insight into the operation’s inner workings due to several compromised WordPress staging servers that were left with exposed PHP endpoints and open directory listings accessible to the public. This oversight allowed researchers to examine internal activity logs, victim telemetry, and even the raw source code of the malicious components. In a particularly revealing incident, one of the operators seemingly infected their own personal machine, inadvertently uploading internal development files. These files included a custom Visual Basic 6 tool designed for the mass management of hijacked WordPress domains, enabling them to toggle fake CAPTCHA overlays and deploy new payloads across their botnet.

This campaign starkly underscores the severe risks associated with unmaintained Content Management Systems. Analysis of one compromised site revealed it had been running without updates since 2021, leaving it exposed to nearly 40 unpatched vulnerabilities. Unaddressed WordPress security flaws and outdated plugins provide adversaries with persistent backdoors, transforming legitimate websites into malicious relays. Addressing these compromised endpoints is crucial for disrupting modern ransomware deployment tactics before adversaries can move laterally within internal networks.

Compromised websites are no longer merely serving as simple phishing hosts or traffic redirectors; they are now being weaponized as fully functional C2 servers, capable of blending malicious communications with legitimate web traffic. This evolution necessitates a heightened focus on web security.

What You Should Do

  • For Website Administrators:
    • Enforce rigorous update schedules for WordPress core files, active themes, and all third-party plugins.
    • Regularly scan your website for unauthorized PHP scripts, modified .htaccess files, and suspicious administrator accounts.
    • Implement strong access controls and multi-factor authentication for all administrative interfaces.
  • For End Users:
    • Never copy and paste commands into your terminal or command prompt based on prompts from websites, even if they appear to be for “human verification.”
    • Be suspicious of any unexpected CAPTCHA or verification requests on websites.
    • Ensure your operating system and web browsers are kept up to date.
  • For Security Teams:
    • Monitor endpoint telemetry for unauthorized PowerShell execution and other anomalous script activity.
    • Implement robust network monitoring to detect unusual outbound data transfers from internal systems.
    • Educate users about social engineering tactics, particularly those involving unexpected command execution prompts.

IOCs

compromised websites maximumrock[.]ro
platinumcar[.]ca
norakremer.co[.]uk
pharmart[.]ae
ksr-racingparts[.]com
compromised base C&C websites v-k.com[.]ua
www.lapellelaser[.]pl
www.parsrulman[.]com
mectcalcutta[.]com
discherniation[.]com
PowerShell script stage 1 cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0
PowerShell script stage 2 cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9
stage 1 – downloader 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b
8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5
4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504
stage 2 – downloader & loader 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527
7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c
976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153
stage 3 – encryptor b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489
65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143
0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40
stage 3 – SMB/USB worm 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4
10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0
f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41
stage 3 – lockscreen 11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e
2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c
38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9
stage 3 – credential stealer 23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70
stage 3 – VBS spreader b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad
stage 3 – chat utility 3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9
3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarePatchphishingransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild

Next Post

CISA Warns: Medusa Ransomware Steals Data, Disables Security, Encrypts Networks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
JWR Phishing Framework Steals Banking Credentials via WebSocket Control
August 18, 2026
GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan
August 18, 2026
BTMob Fraud-as-a-Service Platform Uses 1,400 Servers for Android Takeovers
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us