StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance. The operation is notable for abusing large numbers of compromised WordPress websites as distributed infrastructure for malware hosting, command and control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure on hacked WordPress sites that tricks victims into executing a PowerShell command, leading to a staged infection chain involving PowerShell scripts and .NET downloaders and loaders.
The toolkit associated with StopAndProtect includes a ransomware component known as SilentEncryptor, a stealer known as SilentDataCollector, an SMB and USB propagation component, a VBS spreader, a lock-screen ransom module, and a custom chat utility for operator-victim interaction. Reported capabilities include targeted file inventory and exfiltration, credential theft, keylogging, screenshot capture, network share discovery and mapping, scraping of local communication data including WhatsApp-related information, and selective deployment of encryption. Available reporting indicates the operators often prioritize reconnaissance and theft before deciding whether to encrypt systems, and ransomware is not deployed against every victim.
The operation also leveraged malicious WordPress plugins and must-use plugins to maintain access to compromised sites and enable arbitrary file upload, supporting persistent reuse of hacked web infrastructure. Exposed operational data indicated global victimization, with particularly high concentrations observed in the United States, Russia, and India, and showed that the campaign targeted organizations worldwide rather than a single sector. StopAndProtect is best characterized as a modular double-extortion ransomware operation with substantial infostealing, surveillance, lateral movement, and hands-on-keyboard post-exploitation functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VBS spreader , which propagates the malware to hard disks and removable media, scans the network, and laterally moves via WMI
Les visiteurs sont invités à copier-coller une commande PowerShell malveillante dans leur terminal... Étape 1 : Scripts PowerShell (stages 1 et 2)
This leads to two stages of additional downloaders and loaders written in .NET, followed by several main functional components, such as ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer.
The malware can then encrypt files, spread through SMB shares and USB devices, steal credentials, capture screenshots, collect selected documents or show a ransom message.
In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems.
Newer iterations of the stealer also implement extra features, including a keylogger with valid email address detection
The sites hosted malware stages, delivered commands, received logs and stored stolen files.
The sites hosted malware stages, delivered commands, received logs and stored stolen files.
Les sites WordPress compromis servent à la fois de ... Serveurs C2 pour transmettre les commandes ... T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-component malware operation delivered via fake CAPTCHA/ClickFix lures and compromised WordPress sites. It uses staged .NET downloaders/loaders and can encrypt files, steal credentials and documents, capture screenshots, monitor activity, spread via SMB shares and USB devices, lock screens, and exfiltrate selected files; ransomware behavior is only one component of the broader surveillance and theft operation.
Multi-component malware operation combining file encryption and covert data theft, delivered via ClickFix fake CAPTCHA pages on compromised WordPress sites and using those sites for staging, C2, and exfiltration storage.
Malware/toolkit modulaire multi-composants utilisé dans une campagne active. Il s’appuie sur des leurres CAPTCHA et des commandes PowerShell pour déployer des loaders .NET puis un ensemble d’outils incluant un encrypteur, un voleur d’identifiants, un screen locker, un spreader VBS, un ver SMB/USB et un utilitaire de chat pour l’exfiltration. Il réalise aussi de l’énumération de documents, du keylogging, des captures d’écran, la cartographie de partages réseau et le scraping de données de communication avant chiffrement.
A malware operation whose ransomware component was identified by researchers; the broader operation reportedly used nearly 2,000 hacked WordPress websites to infect computers, steal files, and deploy ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.