Infection Chain | Image: Check Point
At a glance
| Actor / group | Unnamed operator behind “StopAndProtect” (internal project names “0a_botnet” and “fake-captcha”) |
| Activity type | Ransomware, data theft, credential stealing, screen locking |
| Targets / victims | Windows users lured through hacked WordPress sites |
| Scale | More than 6,000 unique victim IPs; close to 2,000 compromised domains (claimed) |
| Status | Active; exposed through the operator’s own security failures |
| Source | Check Point Research; Check Point Blog |
TL;DR
Check Point Research exposed a new StopAndProtect malware operation. The attackers abuse thousands of hacked WordPress sites to spread malware and steal data. Their own security mistakes leaked victim logs, screenshots, and source code.
What happened
Researchers first spotted the StopAndProtect malware in mid-May 2026. The campaign starts on hacked WordPress sites, where visitors meet a fake CAPTCHA. This lure uses the ClickFix trick, which is spreading fast across the web.
The fake prompt tells users to copy, paste, and run a command. That command launches a PowerShell script. Then several .NET loaders download the real payloads from compromised WordPress servers.
The operation does not rely on one tool. Instead, it runs a whole toolkit. As Check Point puts it, the operation runs “a whole toolkit of criminal software working together”. Some parts encrypt files. Others steal documents or lock the screen. One even acts as a live chat between attacker and victim.
How the infection chain works
The chain moves in clear steps. First, ClickFix runs a PowerShell script. Next, two .NET stages load. Finally, stage three drops the main components.
Those components include an encryptor, an SMB/USB worm, a lock screen, a credential stealer, a VBS spreader, and a chat tool. Each stage also uploads logs. As a result, the operators watch every infection in near real time.
Who is behind it
Check Point has not named a person or group. Attribution confidence stays low. Still, the researchers learned a lot, because the operator got careless.
In one case, the operator seems to have infected their own machine. They then uploaded desktop files to a collection server. That archive held a custom Visual Basic 6 tool for mass-managing hacked sites. It also listed close to 2,000 compromised WordPress domains, which points to the scale of the work.
The internal project folders were named “0a_botnet” and “fake-captcha”. These names offer a rare peek inside the crew’s own setup.
Impact and scale
The numbers are large, though some remain claims. Check Point reports more than 6,000 unique victim IP addresses as of late July 2026. The Check Point Blog cites more than 5,000 infected computers worldwide.
Most victims sit in the United States, Russia, and India. During monitoring, researchers gathered roughly 31,000 screenshots from infected machines. They also collected more than 700 stolen data archives.
Many WordPress sites fall because owners skip updates. One compromised site still ran a 2021 version of WordPress. A scan of it found nearly 40 flaws, including SQL injection and authentication bypasses.
What the attackers steal
The stealer, called SilentDataCollector, hunts across every drive. It grabs documents, passwords, and wallet files. Newer builds add a keylogger and pull contacts from WhatsApp.
The ransomware side, SilentEncryptor, can lock files on command. Victims then see a ransom note demanding a small Bitcoin payment. The full research write-up details each of these tools.
What comes next and how to stay protected
The StopAndProtect malware shows how weak WordPress sites become weapons. Because the crew rotates thousands of domains, takedowns get harder. Therefore, defense starts with users and site owners.
Never run a command that a website tells you to paste. A real CAPTCHA never asks for that. Leave any page that pushes such steps.
Site owners should update WordPress core and every plugin. In addition, remove unused plugins and watch for strange files in mu-plugins. Keep your security software current, and back up important data offline.
As Check Point’s Eli Smadja warned, attackers can turn “poorly maintained WordPress sites into a distributed criminal infrastructure”. Staying patched is the simplest way to stay out of that pool.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!