Check Point Research uncovered StopAndProtect, a large-scale cybercrime operation that used compromised WordPress sites to host malware, provide command-and-control, and store stolen data. The campaign began with a ClickFix fake CAPTCHA lure that tricked victims into launching PowerShell, then deployed multiple .NET loader stages that installed a broad toolset including SilentEncryptor ransomware, the SilentDataCollector stealer, an SMB/USB worm, a VBS spreader, a lock-screen module, a credential stealer, and a custom chat utility for interacting with victims.
Researchers said the operators made significant OPSEC mistakes that exposed their infrastructure, including open PHP directory listings, accessible log and screenshot folders, and archived files that appeared to show the actors had infected themselves. Those leaks revealed source code and operational files used to mass-manage compromised WordPress domains. Monitoring from mid-May through late July 2026 found more than 700 stolen-data archives and about 31,000 victim screenshots, while internal logs and exposed systems indicated the campaign hit thousands of IP addresses worldwide, with the highest concentrations in the United States, Russia, and India.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Stairwell authored the SilentEncryptor_Ransomware_HiFi YARA rule using three analyzed SilentEncryptor samples, detecting characteristic ransomware strings, cryptocurrency-wallet paths, and ransom-content markup. Its behavior- and characteristic-based hunting identified 22 related file variants assessed as consistent with StopAndProtect ransomware.
The Gurucul report published domains, SHA-256 hashes, and detection queries associated with the StopAndProtect campaign to help defenders identify related activity. The technical details accompanied reporting that the operation abused nearly 2,000 vulnerable WordPress sites for malware hosting, command-and-control, and victim log exfiltration.
Internal logs recovered from the exposed StopAndProtect infrastructure indicated more than 6,000 unique victim IP addresses. The highest concentrations of victims were in the United States, Russia, and India.
Between mid-May and the end of July 2026, researchers retrieved more than 700 archives of stolen victim data from compromised WordPress servers. The archives reflected theft of documents, password files, wallet files, file listings, encryption logs, screenshots, and progress logs.
Between mid-May and the end of July 2026, researchers collected about 31,000 victim screenshots from exposed directories on compromised WordPress servers. The screenshots included startup, activity, lock screen, and final images from infected systems.
Check Point Research first noticed the StopAndProtect ransomware family in the middle of May 2026. The operation combined ransomware, data theft, lateral movement, and tooling for interacting with victims.
Researchers found an exfiltrated archive that they believe resulted from the threat actor infecting themselves. It exposed internal project names, source code, a Visual Basic 6 tool for mass-managing compromised WordPress sites, and lists of roughly 1,400 domains still showing fake CAPTCHA ClickFix pages.
Researchers retrieved a ZIP archive from a hacked server containing mu-uploader-installer.php, which installed a persistent must-use plugin at wp-content/mu-plugins/wp-sec.php. The plugin created a hidden REST API upload endpoint with hardcoded credentials that could upload files, including PHP files, to nearly any path under the WordPress root.
During their investigation, researchers found exposed PHP scripts, open directory listings, and password-protected utilities on hacked WordPress sites used by the operation. These findings revealed malware hosting, command-and-control, and stolen-data storage infrastructure tied to StopAndProtect.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
stairwell.com
Open sourcecommunity.gurucul.com
Open sourcesecurityaffairs.com
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceitsecurityguru.org
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.