Server Mistake Exposes StopAndProtect’s Hacked WordPress Network

Server Mistake Exposes StopAndProtect’s Hacked WordPress Network

StopAndProtect used nearly 2,000 hacked WordPress sites to spread malware, steal files and deploy ransomware before an open server exposed its global operation.

Listen to this article

0:00

Press play to start listening

A server mistake by cybercriminals has exposed the inner workings of a global malware operation that used nearly 2,000 hacked WordPress websites to infect computers, steal files and deploy ransomware.

Check Point Research identified the operation as StopAndProtect after first encountering its ransomware component in May 2026. Further investigation found a complete malware toolkit supported by compromised websites used to distribute files, issue commands and store information stolen from infected computers.

Fake CAPTCHA Starts the Infection

Visitors to a compromised WordPress site were shown a fake CAPTCHA that instructed them to run a PowerShell command. This technique, commonly called ClickFix, causes users to infect their own computers while believing they are completing a verification process.

Once executed, the command downloaded two PowerShell stages followed by .NET-based loaders. Those loaders could install different components depending on the operator’s instructions, including ransomware, a credential stealer, a lock-screen tool, an SMB and USB worm, a VBS network spreader and a chat utility for communicating with victims.

However, not every infected computer received ransomware. According to Check Point’s report, the operators sometimes collected file listings and selected documents without encrypting the device.

Exposed Server Reveals Victim Data

While examining one of the compromised websites, Check Point found that a PHP endpoint displayed its directory contents when accessed without parameters. The open listing gave researchers access to malware files, operational logs and folders containing information uploaded from infected computers.

One directory contained screenshots showing victims’ desktops, open documents, browser activity, antivirus programs and ransom messages. Between mid-May and late July, Check Point collected approximately 31,000 screenshots and more than 700 archives containing stolen files, password data, cryptocurrency wallet information and infection records.

Furthermore, internal logs contained more than 6,000 unique IP addresses as of July 24. The United States accounted for 1,852 addresses, while Russia and India each accounted for 630. Check Point warned that the numbers do not represent confirmed victims because some entries belonged to research systems and malware sandboxes.

Server Mistake Exposes StopAndProtect’s Hacked WordPress Network
StopAndProtect’s open directory with logs

Operator May Have Infected Their Own Computer

Among the stolen archives, researchers found files that appeared to originate from the malware operator’s computer. The folder names referred to internal projects called 0a_botnet and fake-captcha, while the contents included source code and lists of compromised WordPress domains.

One recovered Visual Basic 6 project was designed to manage infected websites in bulk. It allowed the operator to upload or delete files, activate fake CAPTCHA pages, and disable caching plugins. Text files found in the same archive indicated that the operation controlled close to 2,000 WordPress websites.

To retain control of compromised WordPress sites, the attackers planted a file named wp-sec.php in the must-use plugins folder. It opened a concealed upload route protected by hard-coded credentials, allowing them to place PHP files almost anywhere inside the WordPress installation. The installer then removed itself, but wp-sec.php remained and loaded whenever the website received a request.

Malware Steals Data and Spreads Through Networks

After infecting a Windows computer, StopAndProtect searched local drives, shared network folders, and connected USB devices. Later versions could record keystrokes, take screenshots every 30 seconds, search for WhatsApp contacts chosen by the operator, and steal selected files.

The ransomware also gave away the information needed to reverse its encryption. It placed the password and computer name used to create each file’s encryption key inside the encrypted filename, allowing affected files to be decrypted without paying the attackers.

Server Mistake Exposes StopAndProtect’s Hacked WordPress Network
Infection flow

Cybercriminals Have Exposed Their Own Operations Before

StopAndProtect is not the first criminal operation exposed through its operators’ poor security. In 2020, a misconfigured server associated with Iranian hacking group Charming Kitten exposed around five hours of training videos showing operators accessing Gmail and Yahoo accounts, downloading inboxes and stealing files from Google Drive. The exposed server held about 40GB of stolen data, including roughly five hours of operator-recorded videos.

A Pakistan-based cybercrime network suffered a similar failure in 2025 when its operators were infected by infostealer malware. Their private logs exposed identities, internal messages, financial records and an operation estimated to have earned at least $4.67 million.

Later that year, a publicly accessible Elasticsearch server exposed 6.19 billion records gathered from breaches and website scraping. Evidence suggested the server may have belonged to cybercriminals, although its owner was never confirmed.

In May 2026, “The Gentlemen” ransomware gang suffered an internal breach that exposed backend systems, affiliate discussions, operational tools, and victim-management data. Investigators identified more than 1,570 likely victims connected to the group.

Nevertheless, WordPress administrators should install current core and plugin updates, inspect the mu-plugins directory for unauthorized files, and review server logs for unfamiliar PHP endpoints. Users should never run PowerShell commands copied by a CAPTCHA or browser verification page.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts