Via securityweek.com
Nearly 2,000 hacked WordPress sites used in malware operation
Check Point Research found the StopAndProtect campaign stealing data and crypto wallet files while deploying ransomware through compromised websites.
Nearly 2,000 hacked WordPress websites were used by the StopAndProtect operation to distribute malware, steal data and deploy ransomware, according to Check Point Research.
The campaign targets Windows users through fake CAPTCHA prompts that use the ClickFix technique to trick victims into running a PowerShell command. The malware can steal credentials and cryptocurrency wallet seed phrases, spread through networks and USB drives, lock screens and deploy ransomware.
Check Point said the operation was first identified in mid-May. Its toolkit also hosted malware, sent commands to infected computers and stored stolen documents, screenshots and activity logs.
More than 6,000 unique IP addresses had been compromised by July 24, including 1,852 in the United States, 630 in Russia and 630 in India. Researchers collected more than 31,000 screenshots and over 700 archives containing documents, passwords and cryptocurrency wallet files.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Researchers said operational security failures exposed infection logs, source code and other tools. They also believe the attackers accidentally infected themselves in one instance.