ThreatCluster

StopAndProtect Malware Exploits Thousands of WordPress Sites for Ransomware and Data Theft

First seen 19 Aug 2026, 07:37 UTC CybersecuritynewsGbhackers 87% similarity 65

Article Content

Browse articles
ThreatCluster

The StopAndProtect malware campaign has compromised thousands of WordPress sites, turning them into command-and-control servers for ransomware and data theft. The operation employs deceptive ClickFix CAPTCHA prompts to distribute the malware, which has been active since mid-May 2026. Victims are subjected to double-extortion tactics, where sensitive corporate documents, user credentials, and communication logs are stolen. The attack affects organizations globally, with researchers highlighting a range of criminal tools used in the operation. The full scope of the impact is still being assessed as investigations continue. Security professionals are urged to monitor their WordPress installations for signs of compromise.

Key Points: • StopAndProtect malware exploits thousands of WordPress sites for ransomware and data theft. • The campaign utilizes deceptive ClickFix CAPTCHA prompts to distribute malware. • Active since mid-May 2026, the operation employs double-extortion tactics against victims.

ThreatCluster AI How this analysis works

Timeline

2026-05-15
StopAndProtect campaign first identified
Researchers discovered the StopAndProtect malware operation exploiting WordPress sites for malicious activities.
Gbhackers
2026-08-18
Cybersecuritynews reports on StopAndProtect
The campaign has transformed thousands of hacked WordPress sites into a C2 infrastructure for ransomware and data theft.
Cybersecuritynews
2026-08-19
Gbhackers updates on StopAndProtect
The operation continues to exploit compromised WordPress sites, with ongoing investigations into its full impact.
Gbhackers

Community

Browse all →

Tracked Entities in This Story