Nearly 2,000 hacked WordPress websites were used to distribute malware, steal data, monitor victims, and deploy ransomware, according to cybersecurity firm Check Point Research.

In a report published Tuesday, the firm said it first identified the StopAndProtect ransomware family in mid-May and later traced it to a wider operation. The compromised sites were used to host malware, issue commands to infected machines, and store stolen documents, screenshots, and activity logs.
A criminal toolkit rather than a single malware strain
Check Point researcher Jaromír Horejsi wrote that the campaign did not depend on one malware sample, but on a broader toolkit of criminal software working together. Some components encrypted files. Others quietly stole documents or locked a victim’s screen. Another acted as a live chat channel between attackers and victims.
According to Check Point, the malware targeted Windows users and started with a fake CAPTCHA shown on a compromised website. The ClickFix prompt instructed victims to run a PowerShell command, which installed malware able to steal credentials, harvest cryptocurrency wallet seed phrases, spread across networks and USB drives, lock screens, and deploy ransomware.
The report did not say whether macOS or Linux users were also affected.
Attackers’ OPSEC mistakes exposed internal data
Check Point said operational security failures by the attackers gave researchers a deeper view into the operation.
Horejsi wrote: 「Operational security (OPSEC) failures by the developer exposed lots of files, including detailed infection logs from victims’ machines, screenshots from infected computers, and source code of tools the criminals use to mass-manage compromised websites.」
By July 24, the campaign had compromised more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India.

Exposed directories contained infection logs and screenshots from victims’ computers. Researchers said they collected more than 31,000 screenshots between mid-May and the end of July, along with more than 700 archives containing stolen data, including documents, passwords, and cryptocurrency wallet files.
Check Point said it believes the threat actor also infected themselves by mistake.
Horejsi wrote: 「We collected a few hundred files exfiltrated from victims’ machines, and we believe that in one instance the threat actor infected themselves, as one archive contained several unusual files with suspicious content. This also helps us better understand how the actor operates and how many compromised domains they likely control.」
ClickFix has appeared in other campaigns this year
ClickFix has shown up in several other malware campaigns this year.
In May, an apparel website linked to FBI Director Kash Patel was taken offline after macOS visitors were reportedly targeted with ClickFix malware. Users were prompted to paste a command into Terminal, which installed an infostealer capable of targeting browser data, session tokens, and crypto wallets.
In July, Jamf Threat Labs said it found ClickFix-style malware being distributed through a sponsored ad on X. The ad redirected users to a website that told them to open Terminal and run a command, which installed a variant of the Atomic infostealer.
In August, Microsoft researchers warned that hackers were using compromised websites and BNB Chain smart contracts to distribute malware through fake CAPTCHAs.

