Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure

Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure

N
News Editor
2026-08-20 16:33:38
Nearly 2,000 compromised WordPress sites were used as part of a broader cybercriminal operation that distributed malware, stole files, monitored victims, and deployed ransomware, according to a report from Check Point Research published Tuesday. The firm said it first identified the StopAndProtect ransomware family in mid-May and later linked it to a larger toolkit-driven campaign rather than a single malware strain. Researchers said the operation targeted Windows users through fake CAPTCHA prompts on hacked websites, tricking victims into running a PowerShell command that installed malware capable of stealing credentials, harvesting cryptocurrency wallet seed phrases, spreading through networks and USB drives, locking screens, and dropping ransomware. Check Point said operational security failures by the attackers exposed internal files, infection logs, screenshots from victim machines, and source code used to manage compromised websites at scale. By July 24, the campaign had affected more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India. The researchers also collected more than 31,000 screenshots and over 700 archives containing stolen documents, passwords, and crypto wallet files.

Nearly 2,000 hacked WordPress websites were used to distribute malware, steal data, monitor victims, and deploy ransomware, according to cybersecurity firm Check Point Research.

Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure 2

In a report published Tuesday, the firm said it first identified the StopAndProtect ransomware family in mid-May and later traced it to a wider operation. The compromised sites were used to host malware, issue commands to infected machines, and store stolen documents, screenshots, and activity logs.

A criminal toolkit rather than a single malware strain

Check Point researcher Jaromír Horejsi wrote that the campaign did not depend on one malware sample, but on a broader toolkit of criminal software working together. Some components encrypted files. Others quietly stole documents or locked a victim’s screen. Another acted as a live chat channel between attackers and victims.

According to Check Point, the malware targeted Windows users and started with a fake CAPTCHA shown on a compromised website. The ClickFix prompt instructed victims to run a PowerShell command, which installed malware able to steal credentials, harvest cryptocurrency wallet seed phrases, spread across networks and USB drives, lock screens, and deploy ransomware.

The report did not say whether macOS or Linux users were also affected.

Attackers’ OPSEC mistakes exposed internal data

Check Point said operational security failures by the attackers gave researchers a deeper view into the operation.

Horejsi wrote: 「Operational security (OPSEC) failures by the developer exposed lots of files, including detailed infection logs from victims’ machines, screenshots from infected computers, and source code of tools the criminals use to mass-manage compromised websites.」

By July 24, the campaign had compromised more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India.

Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware Infrastructure 3

Exposed directories contained infection logs and screenshots from victims’ computers. Researchers said they collected more than 31,000 screenshots between mid-May and the end of July, along with more than 700 archives containing stolen data, including documents, passwords, and cryptocurrency wallet files.

Check Point said it believes the threat actor also infected themselves by mistake.

Horejsi wrote: 「We collected a few hundred files exfiltrated from victims’ machines, and we believe that in one instance the threat actor infected themselves, as one archive contained several unusual files with suspicious content. This also helps us better understand how the actor operates and how many compromised domains they likely control.」

ClickFix has appeared in other campaigns this year

ClickFix has shown up in several other malware campaigns this year.

In May, an apparel website linked to FBI Director Kash Patel was taken offline after macOS visitors were reportedly targeted with ClickFix malware. Users were prompted to paste a command into Terminal, which installed an infostealer capable of targeting browser data, session tokens, and crypto wallets.

In July, Jamf Threat Labs said it found ClickFix-style malware being distributed through a sponsored ad on X. The ad redirected users to a website that told them to open Terminal and run a command, which installed a variant of the Atomic infostealer.

In August, Microsoft researchers warned that hackers were using compromised websites and BNB Chain smart contracts to distribute malware through fake CAPTCHAs.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
70

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.