StopAndProtect hacked-WordPress cybercrime campaign
Campaign
Summary
Hide ▲
Show ▼
The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal infrastructure. The operation uses ClickFix social engineering, PowerShell, and .NET downloaders/loaders to stage ransomware, credential theft, worming, and screen-locking components. By July 24, 2026, researchers associated the campaign with more than 6,000 unique IP addresses and over 700 uploaded archives from victim machines.
Related Happenings
StopAndProtect multi-stage malware toolkit
Malware Activity
H score40
First: 19.08.2026 14:25
Last: 19.08.2026 14:25
Sources 1
How related:
The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims,
About this happening:
The StopAndProtect malware toolkit now combines encryption, document theft, screen locking, spreaders, and operator chat, increasing the impact of infectio...
StopAndProtect multi-stage malware toolkit
Malware ActivityHow related: The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims,
About this happening: The StopAndProtect malware toolkit now combines encryption, document theft, screen locking, spreaders, and operator chat, increasing the impact of infectio...
StealC and Amadey infostealer infrastructure disruption
Malware Activity
H score69
First: 24.06.2026 18:25
Last: 24.06.2026 18:25
Sources 1
About this happening:
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
StealC and Amadey infostealer infrastructure disruption
Malware ActivityAbout this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
Operation Endgame takedown of Amadey and StealC infrastructure
Law Enforcement
H score66
First: 24.06.2026 18:02
Last: 24.06.2026 18:02
Sources 1
About this happening:
An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and i...
Operation Endgame takedown of Amadey and StealC infrastructure
Law EnforcementAbout this happening: An international law-enforcement takedown under Operation Endgame disrupted shared infrastructure used by Amadey and StealC, with Microsoft, Europol, and i...
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionAbout this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
SocGholish malware downloader hijacking WordPress sites
Malware Activity
H score57
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
About this happening:
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
SocGholish malware downloader hijacking WordPress sites
Malware ActivityAbout this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
Timeline
-
19.08.2026 14:25 2 articles · 2h ago
Check Point Research flags StopAndProtect WordPress malware campaign
Initial DisclosureCheck Point Research identifies StopAndProtect as a global campaign that abuses hacked WordPress sites to deliver malware, steal files, and manage infected hosts through fake CAPTCHA prompts, ClickFix social engineering, PowerShell execution, and staged .NET downloaders and loaders. Researchers associate the operation with close to 2,000 compromised WordPress sites, more than 700 uploaded archives from victim machines, and more than 6,000 unique IP addresses as of July 24, 2026.
Show sources
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data — thehackernews.com — 19.08.2026 14:25
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data — thehackernews.com — 19.08.2026 14:25