rootpwn

Threat Intel

StopAndProtect: Ransomware Operation Hijacking Thousands of WordPress Sites

RootPwn’s latest intel uncovers StopAndProtect, a multi‑stage ransomware campaign that exploits compromised WordPress sites for download, command & control, and data exfiltration. The attack chain starts with a ClickFix social‑engineering lure that forces victims to run a PowerShell command, spawning .NET loaders, a SMB/USB worm, a lock‑screen module, a VBS spreader, a chat utility and a credential stealer. While not all victims receive file encryption, attackers silently harvest documents, logs and screenshots, uploading them to the same compromised sites. OPSEC lapses exposed thousands of IP

In mid‑May 2026, security researchers first spotted a new ransomware family dubbed StopAndProtect. What followed was a sprawling operation that turns every hacked WordPress site into a node of the attackers’ infrastructure.

Infection Chain

  • Social‑engineering trigger: A fake ClickFix CAPTCHA prompts users to run a PowerShell command.
  • Two‑stage download: The command pulls down .NET loaders that bootstrap the rest of the payload.
  • Modular toolkit: Components include a ransomware engine, an SMB/USB worm, a lock‑screen module, a VBS spreader, a live‑chat utility and a credential stealer.
  • Selective payload: Not every victim gets encrypted; many are quietly exfiltrated for data theft.

WordPress as the Backbone

  • Compromised sites host additional downloaders, act as C&C servers, and store stolen logs and documents.
  • OPSEC failures exposed PHP scripts with directory listings, revealing thousands of logs and a 2,000‑domain compendium.
  • Scanning one infected site uncovered a 2021‑era WordPress core plus ~40 vulnerabilities—expired certs, SQLi, open redirects, auth bypasses, arbitrary file uploads, and more.

Scale & Impact

  • Thousands of IP addresses affected, primarily from the US, Russia and India.
  • Attackers captured telemetry, logs, and screenshots from infected machines, giving them a near‑real‑time view of progress.
  • Some operators even uploaded their own desktop files to the collection server—an accidental leak of source code and a list of compromised domains.

Mitigation Recommendations

  • Patch WordPress core, themes and plugins to the latest versions.
  • Disable or restrict file‑upload capabilities on all sites.
  • Block outbound PowerShell execution and monitor for suspicious .NET downloads.
  • Implement web‑application firewalls to detect and block ClickFix‑style prompts.
  • Regularly audit server directories for exposed listings and unexpected files.
“This is a textbook example of how a single compromised site can become a launchpad for a global cyber‑crime operation.” – RootPwn Threat Analyst

StopAndProtect WordPress Ransomware Cybercrime ThreatIntelligence Malware C&C SocialEngineering

← All news