Find notable cyber news and cases, enriched with sources, timelines, and signals.

StopAndProtect multi-stage malware toolkit

Malware Activity
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

The StopAndProtect malware toolkit now combines encryption, document theft, screen locking, spreaders, and operator chat, increasing the impact of infections and making compromise harder to contain.

Related Happenings

StopAndProtect hacked-WordPress cybercrime campaign

Campaign
H score49 First: 19.08.2026 14:25 Last: 19.08.2026 14:25 Sources 1

How related: The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026.

About this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
H score30 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

USB-spreading clipboard-stealing malware targeting cryptocurrency wallets

Malware Activity
H score27 First: 18.06.2026 19:20 Last: 18.06.2026 19:20 Sources 1

About this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...

SSHStalker IRC-controlled Linux botnet

Malware Activity
H score23 First: 11.02.2026 11:56 Last: 11.02.2026 11:56 Sources 1

About this happening: Researchers disclosed SSHStalker, a Linux botnet that uses IRC C2 and automated SSH scanning to compromise exposed systems, increasing the risk of persistent contr...

Timeline

  1. 19.08.2026 14:25 2 articles · 1h ago

    StopAndProtect malware toolkit combines encryption, theft, locking, and operator chat

    Initial Disclosure

    Check Point Research identified StopAndProtect as a global campaign that abuses hacked WordPress sites to deliver malware, steal files, and support ransomware-style activity. The toolkit combines file encryption, document theft, screen locking, a live chat channel between operators and victims, and staged ClickFix, PowerShell, and .NET components used to deploy the main modules.

    Show sources