StopAndProtect Malware Exploits Thousands of WordPress Sites for Ransomware and Data Theft
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The StopAndProtect malware campaign has compromised thousands of WordPress sites, turning them into command-and-control servers for ransomware and data theft. The operation employs deceptive ClickFix CAPTCHA prompts to distribute the malware, which has been active since mid-May 2026. Victims are subjected to double-extortion tactics, where sensitive corporate documents, user credentials, and communication logs are stolen. The attack affects organizations globally, with researchers highlighting a range of criminal tools used in the operation. The full scope of the impact is still being assessed as investigations continue. Security professionals are urged to monitor their WordPress installations for signs of compromise.
Key Points: • StopAndProtect malware exploits thousands of WordPress sites for ransomware and data theft. • The campaign utilizes deceptive ClickFix CAPTCHA prompts to distribute malware. • Active since mid-May 2026, the operation employs double-extortion tactics against victims.