"The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims," Check Point Research's Jaromír Hořejší said.
Discovery, scope and timing
Check Point Research began tracking this campaign under the name StopAndProtect after discovering a related ransomware family in mid‑May 2026. Researchers identified an ecosystem in which as many as close to 2,000 WordPress sites have been hacked and repurposed as the operation's infrastructure. By July 24, 2026 the campaign had affected more than 6,000 unique IP addresses; the largest country tallies were the United States (1,852), Russia (630), and India (630).
ClickFix fake CAPTCHA drives the infection chain
The attack begins with a social‑engineering lure Check Point describes as a ClickFix‑style prompt: compromised sites overlay content with a fake CAPTCHA that instructs visitors to perform actions which trigger a PowerShell command. That PowerShell call launches a staged .NET download sequence. Stage 1 is a .NET downloader that reports statistics to the C2 server and pulls the next stage; stage 2 is a .NET downloader/loader that performs sandbox checks, adds logging, and launches the main payloads.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe StopAndProtect toolkit: six stage‑3 components
Stage 3 comprises six distinct components that can be mixed and matched by operators:
- SilentEncryptor — encrypts either all infected machines or selectively by host name.
- NetworkShareScanner — acts like an SMB/USB worm to propagate to other devices.
- VBS spreader — copies to hard disks and removable media, scans networks, and moves laterally via WMI.
- LockScreen — blocks user input and displays a ransom message with a payment QR code.
- SimpleChatProxy — a custom chat application used for live communication between victim and operator.
- SilentDataCollector — enumerates drives, encrypts the list, and exfiltrates it to the C2; operators can upload a command file that instructs the stealer to harvest specific files.
Newer stealer builds add capabilities described by Check Point: a keylogger with valid‑email detection, exfiltration from WhatsApp (supporting web and desktop versions), the ability to map and unmap network shares, and automated screenshot capture every 30 seconds. Check Point also noted automation that “waits until the victim becomes inactive and then uses WhatsApp automation to focus the search box, enter the specified keyword (contact name), open the contact information, and capture a screenshot.”
Hacked WordPress sites become distributed C2, storage and delivery
Criminal operators use a ZIP archive containing a PHP file named "uploader‑installer.php" to install a custom WordPress plugin that creates a must‑use (MU) plugin in the "wp‑content/mu‑plugins" directory. That plugin allows anyone possessing valid credentials to upload arbitrary files — including PHP — to nearly any path under the WordPress root, enabling remote code execution. After activation the plugin deactivates and self‑deletes to avoid detection.
Check Point found more than 700 stolen‑data archives on compromised sites between mid‑May and the end of July 2026. Those archives included internal development files and tools; in at least one instance the operator appears to have accidentally leaked their own automation utility, a file named "fMain.frm," which Check Point described as a custom tool used to mass‑manage compromised WordPress pages. That automation uses secure upload and delete PHP scripts on compromised websites to perform actions such as uploading or deleting files and toggling fake CAPTCHA ClickFix overlays.
Operational security failures and researcher visibility
Check Point said much of its visibility came from the attackers' operational security blunders: exposed infection logs, screenshots from victim machines, and the mass‑management tools themselves. Those leaked artifacts let researchers map the toolkit, the workflows, and the supporting botnet of compromised WordPress hosts that serve as download stages, C2 servers, and repositories for exfiltrated logs and stolen documents.
What this means for technologists, affected enterprises, and the public
- Technologists and security teams — Check Point's reporting highlights the specific lure to watch for: unexpected CAPTCHA prompts that instruct users to copy, paste, or run commands, and PowerShell activity that pulls multi‑stage .NET downloaders. The presence of MU plugins and unexpected PHP upload points on WordPress sites is a concrete indicator tied to this campaign.
- Affected enterprises and procurement leaders — the campaign shows how poorly maintained WordPress instances and outdated plugins can be weaponized as distributed infrastructure; Check Point noted at least one compromised site was running a 2021 WordPress release susceptible to roughly 40 different vulnerabilities.
- End users and the general public — Check Point's Eli Smadja urged caution: "We urge organizations to be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser."
StopAndProtect is a reminder that credential‑protected but poorly maintained web properties can be turned into a scaleable criminal platform — for malware delivery, live surveillance, data theft, and selective or broad encryption. The campaign's exposed logs and tools give defenders a rare inside view of an attacker supply chain; they also show how much of the infrastructure rests on the continued neglect of thousands of WordPress sites.




