Published · 5d agoSecurity3 min read
Attacker self-infection exposes a 2,000-site WordPress delivery network
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Check Point Research conducted an investigation into a newly identified cyber crime operation called StopAndProtect.
- Researchers uncovered a series of operational security mistakes that exposed the attackers' own infrastructure, including victim logs, screenshots, source code and internal management tools; they discovered publicly accessible directories containing malware logs, victim screenshots, stolen files and internal tools used to manage the campaign.
- The investigation uncovered files referencing close to 2,000 compromised WordPress domains associated with the operation.
- The exposed material included evidence of a campaign impacting more than 5,000 infected computers worldwide.
- Instead of relying on dedicated command-and-control servers, the StopAndProtect operators built a distributed infrastructure by abusing compromised WordPress websites.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Check Point Research has published an investigation into an operation it calls StopAndProtect, in which the attackers' own operational security failures left victim logs, screenshots, stolen files, source code and internal management tools in publicly accessible directories [1][2]. What makes the disclosure useful is not the malware but the inventory: files referencing close to 2,000 compromised WordPress domains, and evidence of a campaign affecting more than 5,000 infected computers worldwide [3][4].
According to Check Point, the operators did not run dedicated command-and-control servers [5]. Compromised WordPress sites carried the whole lifecycle: hosting malware, delivering follow-on payloads, talking to infected devices, and storing stolen documents, screenshots and activity logs [6]. That is a deliberate design choice. Traffic to a real business's website looks like traffic to a real business's website, and the researchers describe the result as resilient infrastructure blended into legitimate internet traffic [7].
The supply of raw material is the part operators should sit with. Check Point cites Statista's figure that WordPress accounts for more than 43% of the global website builder market as of 2026 [8]. Many installations run outdated core software and plugins [9]. In one case the researchers found a compromised site still running a 2021 WordPress version carrying nearly 40 known vulnerabilities [10]. On the exposed numbers, the campaign averaged roughly two and a half infected machines per compromised domain, which says the domains were the cheap, expendable half of the operation [11].
They were also managed like an estate rather than picked off one at a time. Researchers recovered source code for automation tools built to manage compromised WordPress sites at scale [12]. That is the difference between opportunism and infrastructure.
The front door is equally unglamorous. Victims are shown a fake CAPTCHA using the ClickFix technique and instructed to copy, paste and run commands on their own machines, which starts a multi-stage chain pulling further malware from the compromised sites [13]. No exploit, no patch to apply. Eli Smadja of Check Point Research says the operation shows how thousands of poorly maintained WordPress sites can be turned into distributed criminal infrastructure for malware delivery, surveillance, data theft and ransomware [14], and advises leaving any site that asks a user to perform unusual steps outside the browser [15]. Ransomware is only one possible output: the same toolkit can steal documents, harvest credentials or quietly exfiltrate data [16].
The exposure itself was accidental. Check Point says it suspects one operator may have infected their own computer, causing internal development files to be uploaded to the same infrastructure used for stolen victim data [17]. The archive was removed a few days later [18].
Caveats matter here. This is a single vendor account, the compromised domains are not named publicly, and the source material does not attribute the operation to a named group or give a timeline or victim geography beyond "worldwide" [4][1].
Two things to watch. First, whether the archive's removal means the operators noticed and rotated, in which case the exposed tooling describes a stack that no longer exists. Second, whether the roughly 2,000 sites get cleaned, since site owners who never learn they were used will keep serving payloads. In the meantime, the practical control is not a signature but a policy: users pasting commands from a webpage into a terminal or Run dialog is a detectable, blockable behaviour, and ClickFix depends entirely on it working [13].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Check Point Research conducted an investigation into a newly identified cyber crime operation called StopAndProtect.
ReportedView cited source - [2]
Researchers uncovered a series of operational security mistakes that exposed the attackers' own infrastructure, including victim logs, screenshots, source code and internal management tools; they discovered publicly accessible directories containing malware logs, victim screenshots, stolen files and internal tools used to manage the campaign.
ReportedView cited source - [3]
The investigation uncovered files referencing close to 2,000 compromised WordPress domains associated with the operation.
ReportedView cited source - [4]
The exposed material included evidence of a campaign impacting more than 5,000 infected computers worldwide.
ReportedView cited source - [5]
Instead of relying on dedicated command-and-control servers, the StopAndProtect operators built a distributed infrastructure by abusing compromised WordPress websites.
ReportedView cited source - [6]
The attackers used compromised websites throughout the attack lifecycle to host malware, deliver additional payloads, communicate with infected devices, and store stolen documents, screenshots and activity logs.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.



