Skip to content

Invest2 publishersReports disagree3 min readPublished

Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit

The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit
Generated illustration

What happened

  • Check Point Research says nearly 2,000 compromised WordPress sites are being used by a malware operation it calls StopAndProtect.
  • The payloads, the command-and-control channel and the storage for stolen files all sit on those borrowed domains rather than rented servers.
  • Infection starts with a fake CAPTCHA that tells Windows visitors to run a PowerShell command, which installs a stealer and ransomware bundle.
  • By July 24 more than 6,000 unique IP addresses had been compromised, with 1,852 in the United States and 630 each in Russia and India.
  • The operators left directories open, exposing infection logs, victim screenshots and the source code of their site-management tooling.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Blocking the malicious host now means blocking a working business blog whose owner is also a victim, so the cheap URL-reputation control comes with collateral its operators did not previously have...
  • capability A single operator can flip the phishing page and push updates across the whole set of hacked sites from one utility, so removing individual domains does not degrade the operation.
  • cost The bandwidth, the storage of other people's stolen documents and the eventual remediation land on the site owners, while the attacker's infrastructure line item is zero.

Renting hosting costs money and leaves a billing trail. A neglected WordPress blog costs nothing and arrives with a domain that has been resolving normally for years. According to Check Point researcher Jaromir Horejsi, every layer of the operation sat on that borrowed ground: the payload, the redirect instructions sent to infected machines, and the storage for exfiltrated files [4]. A single compromised site can do all three jobs at once [5].

The yield per domain is thin. Around 6,000 infected IP addresses spread across nearly 2,000 hosting domains is about three victims per site [20], and the United States share of those infections is under a third [21]. The domains are not being picked for their traffic. They are being picked because they are free and because they are believed.

What turns 2,000 unrelated victims into one asset is the tooling. Check Point recovered source code for an automation utility written in Visual Basic 6 that switches the fake CAPTCHA page on and off, redirects visitors and pushes malware updates across the hacked sites, with the domain list sitting in an attached text file [11]. That is fleet management. Pulling one node out of it does not cost the operator a server, because there was never a server to seize.

Cleaning a site is also not the end of it. When the researchers examined the WordPress instance behind one of the malicious domains, they counted close to 40 separate vulnerabilities, some dating back to 2021 [16]. Sites in that state are re-enrollable, which is the practical reason a takedown list ages badly.

The data volume argues against reading this purely as a wallet drainer. Check Point collected more than 31,000 screenshots from victim machines between mid-May and the end of July [22], roughly 400 a day [23], plus over 700 archives of documents, passwords and wallet files [9]. Newer builds log keystrokes and capture the screen every 30 seconds [7]. Horejsi describes not one piece of malware but a toolkit, including a component that works as a live chat between attacker and victim [15]. All of that upstream visibility exists because the operators left directories and logs open, and because they appear to have infected one of their own machines [10][12].

One gap in the report matters for anyone reading this as a Windows problem. Check Point does not say whether macOS or Linux users are affected [14], and the same ClickFix pattern has been aimed at Macs elsewhere this year: Jamf Threat Labs traced a sponsored ad on X in July to a Terminal command that installed a variant of the Atomic infostealer [17], and Microsoft warned in August about fake CAPTCHAs served from compromised sites and BNB Chain smart contracts [18].

Which leaves the one control that does not depend on the domain being honest. Decrypt's advice is to leave any page that prompts you to paste or type something [13]. As Security Affairs puts it, a hacked website is no longer just a hacked website [19], and its owner is unlikely to know the difference.

What to watch

  • Whether the nearly 2,000 listed domains get notified and patched, and how many are still serving the CAPTCHA page a month after the report.
  • Whether the leaked Visual Basic 6 management tool turns up in other campaigns, which would show the fleet tooling was reused rather than burned.
  • Whether any researcher documents a macOS or Linux payload behind the same prompts, which would widen the exposed population beyond Windows.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence66
Adoption68
Hype gap+14
Incentives61
Confidence64
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Check Point Research identified nearly 2,000 compromised WordPress sites used by the StopAndProtect malware operation.

    ReportedSupportedSource: Check Point Research2 sources— create a free account to open themView cited source
  2. [2]

    Check Point published the report on Tuesday, August 18, having first discovered the StopAndProtect ransomware family in mid-May before tracing it to a broader extortion and surveillance operation.

  3. [3]

    The malware targets Windows devices and steals cryptocurrency wallet seed phrases, passwords, files and other sensitive data.

Sources

2 independent publishers whose own reporting we read for this story.

  1. cryptopolitan.com

    1 article · August 21, 2026

    Hackers set traps on over 2,000 hacked WordPress sites for crypto users
  2. decrypt.co

    1 article · August 20, 2026

    Nearly 2,000 Hacked WordPress Sites Turned Into Criminal Infrastructure

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories