Crypto

Attacker Blunder Exposes Global Network Hijacking 2,000 WordPress Sites

Check Point Research reveals how OPSEC mistakes exposed an extensive malware campaign targeting thousands of websites.

A massive cyber extortion and spying operation weaponized nearly 2,000 hacked WordPress websites to distribute harmful code, harvest sensitive data, monitor victims, and lock systems with ransomware, according to findings from cybersecurity firm Check Point Research.

Researchers revealed in a Tuesday report that the StopAndProtect ransomware strain was first detected in mid-May before investigators linked it to a broader network. The compromised sites served multiple roles in the campaign, hosting malicious files, issuing commands to infected devices, and storing stolen documents, screenshots, and logs.

“The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software working together,” Check Point researcher Jaromír Horejsi wrote. “Some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims.”

According to Check Point, the threat primarily targets Windows machines through a deceptive CAPTCHA prompt on hijacked web pages. Known as ClickFix, the prompt tricks users into running a PowerShell command that drops malware capable of exfiltrating login credentials and cryptocurrency wallet seed phrases, spreading across networks and USB drives, locking screens, and executing ransomware.

Cybersecurity analysts note that combining infostealer capabilities with ransomware deployment allows threat actors to maximize profits from a single breach—first exfiltrating high-value credentials and financial keys before extorting the target with file encryption.

The report did not clarify if macOS and Linux systems were impacted by the campaign.

However, severe operational blunders by the operators granted Check Point researchers an intimate view into the internal workings of the infrastructure, the company noted.

“Operational security (OPSEC) failures by the developer exposed lots of files, including detailed infection logs from victims’ machines, screenshots from infected computers, and source code of tools the criminals use to mass-manage compromised websites,” Horejsi wrote.

Telemetry gathered through July 24 indicated that the campaign had compromised more than 6,000 unique IP addresses, with 1,852 located in the United States and 630 each across Russia and India.

WordPress powers over 40 percent of all websites globally, making unpatched plugins and weak administrative credentials a primary target for cybercriminals seeking to turn legitimate web infrastructure into command-and-control hubs for malware operations.

Unsecured directories revealed extensive infection logs and screen captures harvested directly from compromised devices. Investigators managed to retrieve over 31,000 screenshots captured between mid-May and the end of July, alongside more than 700 archives containing exfiltrated documents, saved passwords, and cryptocurrency wallet files.

Check Point analysts suspect the threat actor accidentally infected their own systems during the campaign.

“We collected a few hundred files exfiltrated from victims’ machines, and we believe that in one instance the threat actor infected themselves, as one archive contained several unusual files with suspicious content,” Horejsi wrote. “This also helps us better understand how the actor operates and how many compromised domains they likely control.”

The ClickFix delivery vector has popped up in multiple distinct malware operations throughout the year.

In May, an apparel site associated with FBI Director Kash Patel was taken offline after macOS users visiting the page were targeted by ClickFix malware. Visitors were prompted to copy and paste a script into Terminal, installing an infostealer that targeted browser data, session tokens, and crypto wallets.

In July, Jamf Threat Labs discovered a ClickFix variant being pushed through a sponsored advertisement on X, directing users to a page that coaxed them to run a Terminal command installing the Atomic infostealer. By August, security analysts at Microsoft warned that threat actors were expanding beyond compromised websites to leverage BNB Chain smart contracts to distribute malware through fake CAPTCHAs.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button