{"id":19165,"date":"2026-08-20T16:37:59","date_gmt":"2026-08-20T16:37:59","guid":{"rendered":"https:\/\/nile1.com\/en\/?p=19165"},"modified":"2026-08-20T16:38:03","modified_gmt":"2026-08-20T16:38:03","slug":"attacker-blunder-exposes-global-network-hijacking-2000-wordpress-sites","status":"publish","type":"post","link":"https:\/\/nile1.com\/en\/2026\/08\/20\/attacker-blunder-exposes-global-network-hijacking-2000-wordpress-sites\/","title":{"rendered":"Attacker Blunder Exposes Global Network Hijacking 2,000 WordPress Sites"},"content":{"rendered":"<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">A massive cyber extortion and spying operation weaponized nearly 2,000 hacked WordPress websites to distribute harmful code, harvest sensitive data, monitor victims, and lock systems with ransomware, according to findings from cybersecurity firm Check Point Research.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Researchers revealed in a Tuesday report that the StopAndProtect ransomware strain was first detected in mid-May before investigators linked it to a broader network. The compromised sites served multiple roles in the campaign, hosting malicious files, issuing commands to infected devices, and storing stolen documents, screenshots, and logs.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cThe operation doesn\u2019t rely on a single piece of malware, but on a whole toolkit of criminal software working together,\u201d Check Point researcher Jarom\u00edr Horejsi wrote. \u201cSome components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">According to Check Point, the threat primarily targets Windows machines through a deceptive CAPTCHA prompt on hijacked web pages. Known as ClickFix, the prompt tricks users into running a PowerShell command that drops malware capable of exfiltrating login credentials and cryptocurrency wallet seed phrases, spreading across networks and USB drives, locking screens, and executing ransomware.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Cybersecurity analysts note that combining infostealer capabilities with ransomware deployment allows threat actors to maximize profits from a single breach\u2014first exfiltrating high-value credentials and financial keys before extorting the target with file encryption.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The report did not clarify if macOS and Linux systems were impacted by the campaign.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">However, severe operational blunders by the operators granted Check Point researchers an intimate view into the internal workings of the infrastructure, the company noted.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cOperational security (OPSEC) failures by the developer exposed lots of files, including detailed infection logs from victims\u2019 machines, screenshots from infected computers, and source code of tools the criminals use to mass-manage compromised websites,\u201d Horejsi wrote.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Telemetry gathered through July 24 indicated that the campaign had compromised more than 6,000 unique IP addresses, with 1,852 located in the United States and 630 each across Russia and India.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">WordPress powers over 40 percent of all websites globally, making unpatched plugins and weak administrative credentials a primary target for cybercriminals seeking to turn legitimate web infrastructure into command-and-control hubs for malware operations.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Unsecured directories revealed extensive infection logs and screen captures harvested directly from compromised devices. Investigators managed to retrieve over 31,000 screenshots captured between mid-May and the end of July, alongside more than 700 archives containing exfiltrated documents, saved passwords, and cryptocurrency wallet files.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Check Point analysts suspect the threat actor accidentally infected their own systems during the campaign.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cWe collected a few hundred files exfiltrated from victims\u2019 machines, and we believe that in one instance the threat actor infected themselves, as one archive contained several unusual files with suspicious content,\u201d Horejsi wrote. \u201cThis also helps us better understand how the actor operates and how many compromised domains they likely control.\u201d<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The ClickFix delivery vector has popped up in multiple distinct malware operations throughout the year.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In May, an apparel site associated with FBI Director Kash Patel was taken offline after macOS users visiting the page were targeted by ClickFix malware. Visitors were prompted to copy and paste a script into Terminal, installing an infostealer that targeted browser data, session tokens, and crypto wallets.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In July, Jamf Threat Labs discovered a ClickFix variant being pushed through a sponsored advertisement on X, directing users to a page that coaxed them to run a Terminal command installing the Atomic infostealer. By August, security analysts at Microsoft warned that threat actors were expanding beyond compromised websites to leverage BNB Chain smart contracts to distribute malware through fake CAPTCHAs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A massive cyber extortion and spying operation weaponized nearly 2,000 hacked WordPress websites to distribute harmful code, harvest sensitive data, monitor victims, and lock systems with ransomware, according to findings from cybersecurity firm Check Point Research. Researchers revealed in a Tuesday report that the StopAndProtect ransomware strain was first detected in mid-May before investigators linked &hellip;<\/p>\n","protected":false},"author":1,"featured_media":19167,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[7],"tags":[20736,8748,13824,20733,20734,20735,20732,19216,20731,15868,237],"class_list":["post-19165","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","tag-atomic-infostealer","tag-bnb-chain","tag-check-point-research","tag-clickfix","tag-fbi-director-kash-patel","tag-jamf-threat-labs","tag-jaromir-horejsi","tag-powershell","tag-stopandprotect","tag-terminal","tag-united-states"],"_links":{"self":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/19165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/comments?post=19165"}],"version-history":[{"count":1,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/19165\/revisions"}],"predecessor-version":[{"id":19166,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/19165\/revisions\/19166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media\/19167"}],"wp:attachment":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media?parent=19165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/categories?post=19165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/tags?post=19165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}