
According to Check Point Research, nearly 2,000 WordPress websites were compromised in the StopAndProtect cybercrime operation, turning them into infrastructure to spread malware, steal data and control infected devices. The cybersecurity firm identified the campaign while tracking a ransomware family in May 2026 and found that the hacked sites had become part of a wider attack network. The compromised websites were used to host malware, communicate with infected devices and store stolen data, including screenshots, logs and files. Latest reports from GBHackers cybersecurity bulletin confirm that compromised legitimate sites lend the campaign reach and credibility, making it one of the most significant WordPress-based cybercrime operations in recent months.
Check Point found that many of the compromised websites were running outdated versions of WordPress or had outdated plugins. In one case examined by researchers, a website was running a WordPress version from 2021 and had nearly 40 vulnerabilities. These included issues such as SQL injection, open redirects, authentication bypasses and unauthorised file uploads. The researchers also found open directories containing logs from infected machines, some containing screenshots showing victims' desktops, websites they had visited, documents and other activity. GBHackers reports highlight that these technical vulnerabilities continue to be exploited across multiple platforms, with attackers increasingly targeting outdated software and unpatched systems.
After gaining control of some websites, the attackers modified them to display fake CAPTCHA pages using a ClickFix-style social-engineering technique. According to Check Point, the fake CAPTCHA prompt was designed to persuade visitors to carry out an action outside the normal browser process, copying a PowerShell command to the victim's clipboard after which the user was tricked into executing it. Researchers collected about 31,000 screenshots between mid-May and the end of July from exposed logs, along with more than 700 archives containing stolen data from victims during the same period. GBHackers confirms that this social engineering technique has become increasingly sophisticated, with attackers using various methods to bypass traditional security measures.
As of July 26, Check Point had identified more than 6,000 unique IP addresses associated with the campaign. The US had the largest number at 1,852, followed by Russia and India, with 630 each. However, researchers noted that some logs could relate to researchers or sandbox environments rather than real victims. The operation included multiple malware components, including SilentEncryptor for file encryption, network scanning tools, screen locking ransomware, and data-stealing capabilities that could capture screenshots at 30-second intervals while victims were active. GBHackers reports indicate that similar campaigns are now targeting other platforms and operating systems, demonstrating the widespread adoption of these techniques.
According to Ranjeeth Bellary from EY Forensic and Integrity Services, WordPress website owners should continuously patch WordPress, plugins and themes to close security gaps. Unsupported, unused and vulnerable plugins or themes should be removed, while administrative access should be strengthened. Website owners should also use a WAF or CDN along with malware monitoring to detect and block suspicious activity. Bellary recommends maintaining tested backups and having an incident-response process in place to help recover faster and limit attack impact. GBHackers emphasizes that these recommendations are more critical than ever as cybercriminals continue to exploit known vulnerabilities across multiple platforms, with WordPress remaining a particularly attractive target for large-scale operations.