Cybersecurity researchers have uncovered a global cybercrime operation dubbed ‘StopAndProtect’ that abuses nearly 2,000 hacked WordPress websites to distribute malware, steal data, and conduct ransomware attacks. The campaign, tracked by Check Point Research, leverages a toolkit of malicious components including ransomware, an SMB/USB worm, a lock screen, a VBS spreader, a chat utility, and a credential stealer.
The infection chain begins with a ClickFix social engineering attack, tricking users into running a PowerShell command that deploys .NET downloaders and loaders. These lead to the main components, though ransomware is not always deployed; in many cases, attackers covertly steal file lists and specific documents. The compromised WordPress sites serve as malware staging, command-and-control (C2) servers, and storage for exfiltrated logs.
Check Point identified operational security blunders by the threat actors that exposed detailed infection logs and screenshots. The attackers used a custom WordPress plugin to upload arbitrary files, enabling remote code execution. The campaign has compromised over 6,000 unique IP addresses, with most victims in the U.S., Russia, and India. The attackers also inadvertently infected themselves, leaking internal development tools.
Experts urge organizations to be cautious of unexpected CAPTCHA prompts that instruct copying and running commands, and to keep systems updated.
Attack groups: StopAndProtect
Malware: SilentEncryptor, NetworkShareScanner, VBS spreader, LockScreen, SimpleChatProxy, SilentDataCollector
Companies: Check Point Research
Original source: thehackernews.com