StopAndProtect multi-stage malware toolkit
Malware Activity
Summary
Hide ▲
Show ▼
The StopAndProtect malware toolkit now combines encryption, document theft, screen locking, spreaders, and operator chat, increasing the impact of infections and making compromise harder to contain.
Related Happenings
StopAndProtect hacked-WordPress cybercrime campaign
Campaign
H score49
First: 19.08.2026 14:25
Last: 19.08.2026 14:25
Sources 1
How related:
The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026.
About this happening:
The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
StopAndProtect hacked-WordPress cybercrime campaign
CampaignHow related: The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026.
About this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score30
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityAbout this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware Activity
H score27
First: 18.06.2026 19:20
Last: 18.06.2026 19:20
Sources 1
About this happening:
A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware ActivityAbout this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
SSHStalker IRC-controlled Linux botnet
Malware Activity
H score23
First: 11.02.2026 11:56
Last: 11.02.2026 11:56
Sources 1
About this happening:
Researchers disclosed SSHStalker, a Linux botnet that uses IRC C2 and automated SSH scanning to compromise exposed systems, increasing the risk of persistent contr...
SSHStalker IRC-controlled Linux botnet
Malware ActivityAbout this happening: Researchers disclosed SSHStalker, a Linux botnet that uses IRC C2 and automated SSH scanning to compromise exposed systems, increasing the risk of persistent contr...
Timeline
-
19.08.2026 14:25 1 articles · 1h ago
StopAndProtect compromises more than 6,000 unique IP addresses
Campaign Scope UpdateAs of July 24, 2026, the StopAndProtect campaign had compromised more than 6,000 unique IP addresses, underscoring the scale of the WordPress-based infrastructure used in the operation.
Show sources
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data — thehackernews.com — 19.08.2026 14:25
-
19.08.2026 14:25 2 articles · 1h ago
StopAndProtect malware toolkit combines encryption, theft, locking, and operator chat
Initial DisclosureCheck Point Research identified StopAndProtect as a global campaign that abuses hacked WordPress sites to deliver malware, steal files, and support ransomware-style activity. The toolkit combines file encryption, document theft, screen locking, a live chat channel between operators and victims, and staged ClickFix, PowerShell, and .NET components used to deploy the main modules.
Show sources
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data — thehackernews.com — 19.08.2026 14:25
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data — thehackernews.com — 19.08.2026 14:25