Invest2 distinct publishers3 min readUpdated
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Renting hosting costs money and leaves a billing trail. A neglected WordPress blog costs nothing and arrives with a domain that has been resolving normally for years. According to Check Point researcher Jaromir Horejsi, every layer of the operation sat on that borrowed ground: the payload, the redirect instructions sent to infected machines, and the storage for exfiltrated files [4]. A single compromised site can do all three jobs at once [5].
The yield per domain is thin. Around 6,000 infected IP addresses spread across nearly 2,000 hosting domains is about three victims per site [1], and the United States share of those infections is under a third [3]. The domains are not being picked for their traffic. They are being picked because they are free and because they are believed.
What turns 2,000 unrelated victims into one asset is the tooling. Check Point recovered source code for an automation utility written in Visual Basic 6 that switches the fake CAPTCHA page on and off, redirects visitors and pushes malware updates across the hacked sites, with the domain list sitting in an attached text file [13]. That is fleet management. Pulling one node out of it does not cost the operator a server, because there was never a server to seize.
Cleaning a site is also not the end of it. When the researchers examined the WordPress instance behind one of the malicious domains, they counted close to 40 separate vulnerabilities, some dating back to 2021 [8]. Sites in that state are re-enrollable, which is the practical reason a takedown list ages badly.
The data volume argues against reading this purely as a wallet drainer. Check Point collected more than 31,000 screenshots from victim machines between mid-May and the end of July [11], roughly 400 a day [2], plus over 700 archives of documents, passwords and wallet files [10]. Newer builds log keystrokes and capture the screen every 30 seconds [7]. Horejsi describes not one piece of malware but a toolkit, including a component that works as a live chat between attacker and victim [20]. All of that upstream visibility exists because the operators left directories and logs open, and because they appear to have infected one of their own machines [12][14].
One gap in the report matters for anyone reading this as a Windows problem. Check Point does not say whether macOS or Linux users are affected [16], and the same ClickFix pattern has been aimed at Macs elsewhere this year: Jamf Threat Labs traced a sponsored ad on X in July to a Terminal command that installed a variant of the Atomic infostealer [17], and Microsoft warned in August about fake CAPTCHAs served from compromised sites and BNB Chain smart contracts [18].
Which leaves the one control that does not depend on the domain being honest. Decrypt's advice is to leave any page that prompts you to paste or type something [15]. As Security Affairs puts it, a hacked website is no longer just a hacked website [19], and its owner is unlikely to know the difference.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Check Point Research identified nearly 2,000 compromised WordPress sites used by the StopAndProtect malware operation.
Check Point published the report on Tuesday, August 18, having first discovered the StopAndProtect ransomware family in mid-May before tracing it to a broader extortion and surveillance operation.
The malware targets Windows devices and steals cryptocurrency wallet seed phrases, passwords, files and other sensitive data.
Check Point researcher Jaromir Horejsi said the ransomware, payloads, command-and-control infrastructure and storage for stolen data are all hosted on WordPress domains the criminals did not have to pay for.
One compromised server can host the payload, send redirect instructions to infected computers, and store stolen files.
The attack begins with a fake CAPTCHA (ClickFix) prompt on a compromised website that instructs Windows victims to run a PowerShell command, installing malware capable of stealing credentials and wallet seed phrases, spreading through networks and USB drives, locking screens and deploying ransomware.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor forensics, single primary source
Findings are unusually concrete for a campaign report: a named researcher, dated telemetry from the operators' own leaked logs, recovered tooling with a domain list, and counted exfiltration artifacts. But both articles derive entirely from one Check Point report with no independent confirmation, several capability details are single-sourced, and the two outlets disagree on screenshot volume, which caps confidence in the numbers.
Confirmed in-the-wild footprint at meaningful scale
This is an active campaign, not an announcement: nearly 2,000 hijacked hosting domains, more than 6,000 distinct infected IPs across at least three major geographies by July 24, 700-plus exfiltration archives and tens of thousands of screenshots. Density is modest at roughly three victims per compromised site, and the disclosed telemetry window ends in late July, so current scale is unknown.
Mildly overstated by crypto framing
Headline numbers are close to the underlying report, so the gap is small. It is positive rather than zero because the crypto-holder framing narrows a general-purpose infostealer and ransomware toolkit to wallet theft, the screenshot count is inflated in one telling and unreconciled between outlets, the report's silence on macOS and Linux is dropped by one publisher, and mitigation advice is attributed circularly between the two articles rather than to the researchers.
Vendor research amplified by crypto-audience outlets
The sole primary source is a commercial security vendor whose threat research doubles as marketing for its products, and both secondary publishers are crypto-focused outlets with an audience incentive to foreground wallet-theft risk; one carries a newsletter solicitation and an investment disclaimer inside the article. No source in the cluster discloses a commercial relationship or is a party to the incident, which limits the distortion.
Solid on mechanics, softer on magnitude
The infection chain, hosting model, exposed tooling and self-infection detail are corroborated across both articles and grounded in recovered artifacts, so mechanism confidence is high. Magnitude confidence is lower: everything traces to one vendor, one headline count conflicts between outlets, platform scope is explicitly unresolved, and no post-July telemetry or takedown status is available.
security
ClickFix operators install the signed Deno runtime to run their remote JavaScript1 distinct publisher
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
security
Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026
1 article · August 20, 2026