Invest2 publishersReports disagree3 min readPublished
Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
The Investor · Invest desk

What happened
- Check Point Research says nearly 2,000 compromised WordPress sites are being used by a malware operation it calls StopAndProtect.
- The payloads, the command-and-control channel and the storage for stolen files all sit on those borrowed domains rather than rented servers.
- Infection starts with a fake CAPTCHA that tells Windows visitors to run a PowerShell command, which installs a stealer and ransomware bundle.
- By July 24 more than 6,000 unique IP addresses had been compromised, with 1,852 in the United States and 630 each in Russia and India.
- The operators left directories open, exposing infection logs, victim screenshots and the source code of their site-management tooling.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint Blocking the malicious host now means blocking a working business blog whose owner is also a victim, so the cheap URL-reputation control comes with collateral its operators did not previously have...
- capability A single operator can flip the phishing page and push updates across the whole set of hacked sites from one utility, so removing individual domains does not degrade the operation.
- cost The bandwidth, the storage of other people's stolen documents and the eventual remediation land on the site owners, while the attacker's infrastructure line item is zero.
Renting hosting costs money and leaves a billing trail. A neglected WordPress blog costs nothing and arrives with a domain that has been resolving normally for years. According to Check Point researcher Jaromir Horejsi, every layer of the operation sat on that borrowed ground: the payload, the redirect instructions sent to infected machines, and the storage for exfiltrated files [4]. A single compromised site can do all three jobs at once [5].
The yield per domain is thin. Around 6,000 infected IP addresses spread across nearly 2,000 hosting domains is about three victims per site [20], and the United States share of those infections is under a third [21]. The domains are not being picked for their traffic. They are being picked because they are free and because they are believed.
What turns 2,000 unrelated victims into one asset is the tooling. Check Point recovered source code for an automation utility written in Visual Basic 6 that switches the fake CAPTCHA page on and off, redirects visitors and pushes malware updates across the hacked sites, with the domain list sitting in an attached text file [11]. That is fleet management. Pulling one node out of it does not cost the operator a server, because there was never a server to seize.
Cleaning a site is also not the end of it. When the researchers examined the WordPress instance behind one of the malicious domains, they counted close to 40 separate vulnerabilities, some dating back to 2021 [16]. Sites in that state are re-enrollable, which is the practical reason a takedown list ages badly.
The data volume argues against reading this purely as a wallet drainer. Check Point collected more than 31,000 screenshots from victim machines between mid-May and the end of July [22], roughly 400 a day [23], plus over 700 archives of documents, passwords and wallet files [9]. Newer builds log keystrokes and capture the screen every 30 seconds [7]. Horejsi describes not one piece of malware but a toolkit, including a component that works as a live chat between attacker and victim [15]. All of that upstream visibility exists because the operators left directories and logs open, and because they appear to have infected one of their own machines [10][12].
One gap in the report matters for anyone reading this as a Windows problem. Check Point does not say whether macOS or Linux users are affected [14], and the same ClickFix pattern has been aimed at Macs elsewhere this year: Jamf Threat Labs traced a sponsored ad on X in July to a Terminal command that installed a variant of the Atomic infostealer [17], and Microsoft warned in August about fake CAPTCHAs served from compromised sites and BNB Chain smart contracts [18].
Which leaves the one control that does not depend on the domain being honest. Decrypt's advice is to leave any page that prompts you to paste or type something [13]. As Security Affairs puts it, a hacked website is no longer just a hacked website [19], and its owner is unlikely to know the difference.
What to watch
- Whether the nearly 2,000 listed domains get notified and patched, and how many are still serving the CAPTCHA page a month after the report.
- Whether the leaked Visual Basic 6 management tool turns up in other campaigns, which would show the fleet tooling was reused rather than burned.
- Whether any researcher documents a macOS or Linux payload behind the same prompts, which would widen the exposed population beyond Windows.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence66
- Adoption68
- Hype gap+14
- Incentives61
- Confidence64
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Check Point Research identified nearly 2,000 compromised WordPress sites used by the StopAndProtect malware operation.
ReportedSupportedSource: Check Point Research2 sources— create a free account to open themView cited source - [2]
Check Point published the report on Tuesday, August 18, having first discovered the StopAndProtect ransomware family in mid-May before tracing it to a broader extortion and surveillance operation.
- [3]
The malware targets Windows devices and steals cryptocurrency wallet seed phrases, passwords, files and other sensitive data.
- [4]
Check Point researcher Jaromir Horejsi said the ransomware, payloads, command-and-control infrastructure and storage for stolen data are all hosted on WordPress domains the criminals did not have to pay for.
ReportedSupportedSource: Check Point researcher Jaromir Horejsi, via Cryptopolitan2 sources— create a free account to open themView cited source - [5]
One compromised server can host the payload, send redirect instructions to infected computers, and store stolen files.
- [6]
The attack begins with a fake CAPTCHA (ClickFix) prompt on a compromised website that instructs Windows victims to run a PowerShell command, installing malware capable of stealing credentials and wallet seed phrases, spreading through networks and USB drives, locking screens and deploying ransomware.
- [7]
Newer versions of the malware can log keystrokes, take screenshots every 30 seconds, and use WhatsApp to photograph the victim's contact list.
- [8]
As of July 24 the campaign had compromised more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India.
- [9]
Researchers collected more than 700 archives containing stolen data, including documents, passwords and cryptocurrency wallet files, between mid-May and the end of July.
- [10]
Operational security failures by the developer exposed infection logs from victims' machines, screenshots from infected computers, and the source code of tools used to mass-manage compromised websites.
- [11]
The exposed automation tool, written in legacy Visual Basic 6, lets the operator remotely toggle the CAPTCHA phishing page, redirect site visitors and update the malware on compromised sites; attached text files list the nearly 2,000 hacked domains.
- [12]
Check Point believes that in one instance the threat actor infected themselves, as one exfiltrated archive contained unusual files with suspicious content.
- [13]
Decrypt advises that users should be wary of sites prompting them to paste or type anything and should leave the page as soon as they see such a request.
ReportedSupportedSource: Decrypt, cited by Cryptopolitan2 sources— create a free account to open themView cited source - [14]
Check Point's report did not say whether macOS and Linux users are affected.
- [15]
Horejsi wrote that the operation relies on a whole toolkit of criminal software: some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims.
ReportedSupportedSource: Check Point researcher Jaromir Horejsi2 sources— create a free account to open themView cited source - [16]
Examining the WordPress instance behind one malicious domain, Horejsi's team found nearly 40 different vulnerabilities in the software, dating back to 2021.
- [17]
In July, Jamf Threat Labs found ClickFix-style malware distributed through a sponsored ad on X that redirected users to a site instructing them to run a Terminal command installing a variant of the Atomic infostealer.
- [18]
In August, Microsoft researchers warned that hackers were using compromised websites and BNB Chain smart contracts to distribute malware through fake CAPTCHAs.
- [19]
According to Security Affairs, a hacked website is no longer just a hacked website: it can turn into a launchpad for attacks by other bad actors.
- [20]
More than 6,000 infected IP addresses across nearly 2,000 hosting domains is roughly three victims per compromised site.
- [21]
The 1,852 United States infections are under a third of the more than 6,000 unique IP addresses recorded by July 24.
- [22]
Researchers collected over 31,000 screenshots from infected computers between mid-May and the end of July.
- [23]
31,000 screenshots collected from mid-May to the end of July is roughly 400 a day over about 11 weeks.
Sources
2 independent publishers whose own reporting we read for this story.
- cryptopolitan.comHackers set traps on over 2,000 hacked WordPress sites for crypto users
1 article · August 21, 2026
- decrypt.coNearly 2,000 Hacked WordPress Sites Turned Into Criminal Infrastructure
1 article · August 20, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- ClickFix-Style Social EngineeringFollow
- Threat Actor OPSEC FailuresFollow
- Infostealers and Crypto Wallet TheftFollow
- WordPress SecurityFollow
- Compromised Infrastructure AbuseFollow
- Ransomware OperationsFollow