Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
Brief
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal command-and-control (C2) infrastructure .
The campaign blends double-extortion ransomware with covert data theft, quietly harvesting sensitive corporate documents, system screenshots, user credentials, and active communication logs from compromised machines worldwide.
Internal logs exposed through the threat actors’ operational security failures reveal over 6,000 unique victim IP addresses across the globe, with the highest infection rates concentrated in the United States, Russia, and India.
The operators actively manage close to 2,000 compromised WordPress domains, creating a resilient, rotating pool of infrastructure to distribute payloads, maintain control channels, and store exfiltrated files.
