2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
Brief
A newly identified cybercrime operation dubbed StopAndProtect has been quietly running its entire criminal infrastructure through close to 2,000 hacked WordPress websites, according to new research from Check Point .
Rather than relying on dedicated command-and-control servers, which are relatively easy for defenders to identify and take down, the group behind StopAndProtect compromised thousands of legitimate WordPress sites and repurposed them to host malware, issue commands to infected machines, and store data stolen from victims.
Because the traffic blends in with ordinary website activity, the approach gave the operation a resilient, low-visibility footprint that could withstand takedown attempts on any single node.
Researchers first spotted the ransomware component behind the campaign in mid-May 2026.
