StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations and individuals visiting compromised WordPress sites
Incident: A global campaign utilizing a network of hacked WordPress sites to distribute multi-component malware.
Impact: Potential for widespread data theft, system encryption via ransomware, and lateral network movement.
Attacker: Unidentified threat actors (tracked as StopAndProtect)
Analysis: Attackers are utilizing a multi-stage infection chain starting with social engineering to execute PowerShell commands. The campaign is highly versatile, employing both data exfiltration and ransomware payloads while using compromised web hosts for command-and-control. The reliance on outdated WordPress installations highlights a critical vulnerability in widespread CMS maintenance.
Recommendations: Update all WordPress core files and plugins to the latest versions to close known vulnerabilities.; Train users to identify and avoid fake CAPTCHA prompts that request copying or running commands.; Implement strict PowerShell execution policies to block unauthorized scripts from running on endpoints.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *