Overview
- Check Point Research has found nearly 2,000 compromised WordPress sites utilized by the StopAndProtect malware operation.
- As of July 24, over 6,000 unique IP addresses were affected, with 1,852 located in the United States.
- Investigators suspect that the attackers unintentionally infected their own systems, which exposed internal management files and tools for the compromised sites.
According to cybersecurity firm Check Point Research, nearly 2,000 hacked WordPress sites have been leveraged to distribute malware, steal sensitive data, surveil victims, and implement ransomware.
A report released on Tuesday indicated that the StopAndProtect ransomware was initially discovered in mid-May, leading researchers to uncover a larger operation. The compromised websites were used to host malware, issue commands to infected machines, and store stolen files, screenshots, and activity logs.
Check Point researcher Jaromír Horejsi explained, “The operation relies on a comprehensive toolkit of criminal software rather than a single malware variant. Some tools are designed to encrypt files, others to stealthily exfiltrate documents or lock screens, while another facilitates live communication between attackers and victims.”
The malware specifically targets Windows users, beginning with a deceptive CAPTCHA on an infected website. The ClickFix prompt misleads victims into executing a PowerShell command that installs malware capable of stealing credentials, cryptocurrency wallet seed phrases, and spreads through networks and USB drives, while also locking screens and deploying ransomware.
The report did not clarify whether users of macOS and Linux are affected.
However, the attackers’ operational mistakes allowed Check Point to gain deeper insights into their activities, the firm noted.
“Failures in operational security (OPSEC) by the developers revealed numerous files, including detailed logs of infections from victims’ systems, screenshots from infected devices, and the source code for tools used to manage compromised websites on a large scale,” Horejsi stated.
As of July 24, the campaign had compromised more than 6,000 unique IP addresses, with 1,852 in the United States and 630 each in Russia and India.
The exposed directories contained infection logs and screenshots from victims' systems. Researchers reported gathering over 31,000 screenshots from mid-May to late July, in addition to more than 700 archives filled with stolen data, including documents, passwords, and cryptocurrency wallet files.
Check Point suspects that the threat actors also inadvertently infected their own systems.
“We collected several hundred files exfiltrated from victims’ systems, and we believe that in one case, the threat actor infected themselves, as one archive included several unusual files with suspicious content,” Horejsi noted. “This also aids our understanding of the actor's operations and the extent of the compromised domains they control.”
ClickFix has appeared in various other malware campaigns this year.
In May, an apparel website linked to FBI Director Kash Patel was taken offline after macOS users were reportedly targeted by ClickFix malware. Users were instructed to paste a command into Terminal, which installed an infostealer that could access browser data, session tokens, and crypto wallets.
In July, Jamf Threat Labs identified ClickFix-style malware being advertised through a sponsored post on X. This ad led users to a website that prompted them to open Terminal and execute a command that installed a variant of the Atomic infostealer. In August, Microsoft researchers alerted that hackers were utilizing compromised websites and BNB Chain smart contracts to spread malware via fake CAPTCHAs.