Skip to content

Security3 publishers3 min readPublished Updated

Attacker self-infection exposes a 2,000-site WordPress delivery network

Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.

The Watch · Security desk

What happened

  • Check Point Research conducted an investigation into a newly identified cyber crime operation called StopAndProtect.
  • Researchers uncovered a series of operational security mistakes that exposed the attackers' own infrastructure, including victim logs, screenshots, source code and internal management tools; they discovered publicly accessible directories containing malware logs, victim screenshots, stolen files and internal tools used to manage the campaign.
  • The investigation uncovered files referencing close to 2,000 compromised WordPress domains associated with the operation.
  • The exposed material included evidence of a campaign impacting more than 5,000 infected computers worldwide.
  • Instead of relying on dedicated command-and-control servers, the StopAndProtect operators built a distributed infrastructure by abusing compromised WordPress websites.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Check Point Research has published an investigation into an operation it calls StopAndProtect, in which the attackers' own operational security failures left victim logs, screenshots, stolen files, source code and internal management tools in publicly accessible directories [1][2]. What makes the disclosure useful is not the malware but the inventory: files referencing close to 2,000 compromised WordPress domains, and evidence of a campaign affecting more than 5,000 infected computers worldwide [3][4].

According to Check Point, the operators did not run dedicated command-and-control servers [5]. Compromised WordPress sites carried the whole lifecycle: hosting malware, delivering follow-on payloads, talking to infected devices, and storing stolen documents, screenshots and activity logs [6]. That is a deliberate design choice. Traffic to a real business's website looks like traffic to a real business's website, and the researchers describe the result as resilient infrastructure blended into legitimate internet traffic [7].

The supply of raw material is the part operators should sit with. Check Point cites Statista's figure that WordPress accounts for more than 43% of the global website builder market as of 2026 [8]. Many installations run outdated core software and plugins [9]. In one case the researchers found a compromised site still running a 2021 WordPress version carrying nearly 40 known vulnerabilities [10]. On the exposed numbers, the campaign averaged roughly two and a half infected machines per compromised domain, which says the domains were the cheap, expendable half of the operation [11].

They were also managed like an estate rather than picked off one at a time. Researchers recovered source code for automation tools built to manage compromised WordPress sites at scale [12]. That is the difference between opportunism and infrastructure.

The front door is equally unglamorous. Victims are shown a fake CAPTCHA using the ClickFix technique and instructed to copy, paste and run commands on their own machines, which starts a multi-stage chain pulling further malware from the compromised sites [13]. No exploit, no patch to apply. Eli Smadja of Check Point Research says the operation shows how thousands of poorly maintained WordPress sites can be turned into distributed criminal infrastructure for malware delivery, surveillance, data theft and ransomware [14], and advises leaving any site that asks a user to perform unusual steps outside the browser [15]. Ransomware is only one possible output: the same toolkit can steal documents, harvest credentials or quietly exfiltrate data [16].

The exposure itself was accidental. Check Point says it suspects one operator may have infected their own computer, causing internal development files to be uploaded to the same infrastructure used for stolen victim data [17]. The archive was removed a few days later [18].

Caveats matter here. This is a single vendor account, the compromised domains are not named publicly, and the source material does not attribute the operation to a named group or give a timeline or victim geography beyond "worldwide" [4][1].

Two things to watch. First, whether the archive's removal means the operators noticed and rotated, in which case the exposed tooling describes a stack that no longer exists. Second, whether the roughly 2,000 sites get cleaned, since site owners who never learn they were used will keep serving payloads. In the meantime, the practical control is not a signature but a policy: users pasting commands from a webpage into a terminal or Run dialog is a detectable, blockable behaviour, and ClickFix depends entirely on it working [13].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories