Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Check Point uncovers the StopAndProtect ransomware operation infecting thousands of WordPress sites via ClickFix social engineering and PowerShell downloaders.
Check Point Research first observed the StopAndProtect ransomware family in mid-May 2026 and linked its infrastructure to thousands of hacked WordPress sites. The infection chain begins with ClickFix social engineering that prompts victims to run a PowerShell command, followed by two stages of additional downloaders. The research maps the shared infrastructure unifying the operation.
- StopAndProtect ransomware family first observed in mid-May 2026
- Infection starts with ClickFix social engineering prompting a PowerShell command
- Two downloader stages lead to the final payload
- Shared infrastructure ties the operation to thousands of compromised WordPress sites
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and […] The post Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect appeared first on Check Point Research.
This source does not provide full text. Read it at research.checkpoint.com.