← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 18, 2026 · 13:05via Check Point Research

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Brief

Research by: Jaromír Hořejší ( @JaromirHorejsi )

Key points

  • StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their infrastructure – using them to spread the malware, control infected machines, and store stolen documents, screenshots, and activity logs (records created by malware to track its actions, progress, or status during execution).
  • Operational security (OPSEC) failures by the developer exposed lots of files, including detailed infection logs from victims’ machines, screenshots from infected computers, and source code of tools the criminals use to mass-manage compromised websites.
Read more on Check Point Research