Nearly 2,000 hacked WordPress sites used in malware operation

Via securityweek.com

Nearly 2,000 hacked WordPress sites used in malware operation

Check Point Research found the StopAndProtect campaign stealing data and crypto wallet files while deploying ransomware through compromised websites.

Nearly 2,000 hacked WordPress websites were used by the StopAndProtect operation to distribute malware, steal data and deploy ransomware, according to Check Point Research.

The campaign targets Windows users through fake CAPTCHA prompts that use the ClickFix technique to trick victims into running a PowerShell command. The malware can steal credentials and cryptocurrency wallet seed phrases, spread through networks and USB drives, lock screens and deploy ransomware.

Advertisement

Check Point said the operation was first identified in mid-May. Its toolkit also hosted malware, sent commands to infected computers and stored stolen documents, screenshots and activity logs.

More than 6,000 unique IP addresses had been compromised by July 24, including 1,852 in the United States, 630 in Russia and 630 in India. Researchers collected more than 31,000 screenshots and over 700 archives containing documents, passwords and cryptocurrency wallet files.

Researchers said operational security failures exposed infection logs, source code and other tools. They also believe the attackers accidentally infected themselves in one instance.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Nearly 2,000 hacked WordPress sites used in malware operation
Nearly 2,000 hacked WordPress sites used in malware operation

Check Point Research found the StopAndProtect campaign stealing data and crypto wallet files while deploying ransomware through compromised websites.

Share

Add us on Google

Via securityweek.com

Nearly 2,000 hacked WordPress websites were used by the StopAndProtect operation to distribute malware, steal data and deploy ransomware, according to Check Point Research.

The campaign targets Windows users through fake CAPTCHA prompts that use the ClickFix technique to trick victims into running a PowerShell command. The malware can steal credentials and cryptocurrency wallet seed phrases, spread through networks and USB drives, lock screens and deploy ransomware.

Advertisement

Check Point said the operation was first identified in mid-May. Its toolkit also hosted malware, sent commands to infected computers and stored stolen documents, screenshots and activity logs.

More than 6,000 unique IP addresses had been compromised by July 24, including 1,852 in the United States, 630 in Russia and 630 in India. Researchers collected more than 31,000 screenshots and over 700 archives containing documents, passwords and cryptocurrency wallet files.

Researchers said operational security failures exposed infection logs, source code and other tools. They also believe the attackers accidentally infected themselves in one instance.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.