Monday, August 24, 2026 | 04:47 PM ISTहिंदी में पढें
Business Standard
Notification Icon
userprofile IconSearch

How hackers turned nearly 2,000 WordPress sites into malware infrastructure

A StopAndProtect cybercrime campaign compromised nearly 2,000 WordPress websites, turning them into infrastructure to spread malware, steal data and control infected devices

digital infrastructure, Cyberattacks, Pahalgam attack, terrorist attacks, central government, Meity

Hackers compromised WordPress websites and used them to distribute malware, steal data and target visitors, Check Point Research found.

Sweta Kumari New Delhi

Listen to This Article

Nearly 2,000 WordPress websites were compromised in the StopAndProtect cybercrime operation, with attackers using them to distribute malware, steal data and control infected computers, according to Check Point Research. The cybersecurity firm identified the campaign while tracking a ransomware family in May 2026 and found that the hacked sites had become part of a wider attack network. The websites were used to host malware, communicate with infected devices and store stolen data, including screenshots, logs and files.
 
“WordPress is enormously widespread, and therefore attackers do not necessarily need to build their own infrastructure. They can compromise legitimate sites and effectively "rent" the website's existing reputation, domain age, hosting environment and normal user traffic.” according to Ranjeeth Bellary, Partner, EY Forensic and Integrity Services – Cyber Forensics. 
 
 
Hacked websites became part of the attack
 
The operation shows how a compromised website can become more than a victim of a cyberattack. It can be turned into part of the infrastructure used to attack other people.
According to Check Point, the attackers used hacked WordPress sites for three main purposes: hosting different stages of the malware, acting as command-and-control servers to send instructions to infected machines and storing logs and stolen information.
 
This meant that visitors to an affected website could be exposed to malicious content even though they were not the original target.
 
According to Bellary, “A distributed network of compromised websites is harder to disrupt than one centrally hosted malicious server. A legitimate WordPress site can become a malware distribution point, command-and-control layer and even a repository for stolen data. Attackers get scale and legitimacy without having to build that infrastructure themselves.”
 
Check Point said many of the compromised websites were running outdated versions of WordPress or had outdated plugins. In one case examined by researchers, a website was running a WordPress version from 2021 and had nearly 40 vulnerabilities. These included issues such as SQL injection, open redirects, authentication bypasses and unauthorised file uploads.
 
Fake CAPTCHA tricks users
 
After gaining control of some websites, the attackers modified them to display fake CAPTCHA pages. CAPTCHA is normally used to check whether a visitor is a human rather than an automated bot. In this campaign, however, the attackers used a ClickFix-style social-engineering technique to make the security check part of the infection process.
 
Check Point mentioned that the fake CAPTCHA prompt was designed to persuade visitors to carry out an action outside the normal browser process. The page could copy a PowerShell command to the victim's clipboard, after which the user was tricked into executing it.
 
Bellary told Business Standard that CAPTCHA pages are familiar to almost every internet user. Attackers take that familiarity and imitate a legitimate security verification process. 
 
“In the ClickFix technique observed in these campaigns, the victim is told to perform an apparently harmless action such as "verify you are human", but the process causes a malicious command to be copied and then asks the victim to execute it.”, he said. 
 
He further explained that ClickFix is not technical complexity; it is psychological manipulation. Users have been trained to trust CAPTCHA and ‘verify you are human’ screens, so attackers are exploiting that familiarity to persuade the victim to execute the malware themselves. It effectively turns the user into the final step of the infection chain.
 
The use of a fake CAPTCHA is important because it relies on user behaviour rather than simply exploiting a technical weakness in the victim's computer. 
 
One operation, several types of malware
 
StopAndProtect did not rely on one piece of malware. Check Point identified several components that could perform different tasks. One component, called SilentEncryptor, could encrypt files and display a ransom message. Another could scan network shares and USB devices, allowing the malware to spread to other devices.
 
A separate component could spread through hard drives and removable media and move across networks. Another locked the victim's screen and displayed a ransom message. There was also a chat component that allowed communication between the attackers and victims.
 
The operation also included a data-stealing component. Check Point mentioned that it could create a list of files stored on infected machines and send that information to the attackers. The operators could then instruct the malware to collect specific files.
 
Newer versions of the data stealer included additional capabilities such as keylogging, WhatsApp contact searches, network-share mapping and screenshots of user activity. Check Point noted that the malware could capture screenshots at 30-second intervals while a victim was active.
 
This means that the operation was not limited to ransomware. In several cases, the attackers focused on collecting information from infected computers instead of encrypting files. 
 
The scale of the operation became clearer after researchers gained access to exposed logs stored on compromised infrastructure. As of July 26, Check Point had identified more than 6,000 unique IP addresses associated with the campaign. The US had the largest number at 1,852, followed by Russia and India, with 630 each.
 
Check Point also cautioned that these figures have limitations. Some logs could relate to researchers or sandbox environments rather than real victims. The researchers nevertheless said that most of the IP addresses appeared to belong to actual infected machines. 
 
Attackers exposed their own data
 
One of the more unusual parts of the investigation was how much information the attackers accidentally exposed themselves. Check Point found open directories containing logs from infected machines. Some directories contained screenshots showing victims' desktops, websites they had visited, documents and other activity. Researchers said they collected about 31,000 screenshots between mid-May and the end of July.
 
The researchers also found more than 700 archives containing stolen data from victims during the same period. These included files from desktops, password files, cryptocurrency wallet files, file lists, encryption logs and screenshots.
 
In one case, researchers believe the attackers may have infected one of their own machines. An archive recovered from the infrastructure contained files that appeared to belong to the attackers and included tools used to manage compromised WordPress sites.
 
One such tool could be used to manage multiple hacked websites, including uploading and deleting files and switching fake CAPTCHA pages on or off. According to Check Point, the tool gave researchers a clearer view of how the attackers managed the operation at scale. 
 
What this means for WordPress users
 
The campaign highlights the risks of outdated WordPress software and plugins. Check Point found compromised sites running old versions, including one that had not been updated since 2021 and had nearly 40 vulnerabilities.
 
Once hacked, websites can be used to spread malware to visitors. Users should be wary of fake CAPTCHA pages asking them to copy, paste or run commands. According to Ranjeeth Bellary, WordPress website owners should continuously patch WordPress, plugins and themes to close security gaps. Unsupported, unused and vulnerable plugins or themes should also be removed, while administrative access should be strengthened.
 
Website owners should also use a WAF or CDN along with malware monitoring to detect and block suspicious activity. Regular monitoring for unauthorised changes can help identify a compromised website early.
 
Bellary also recommends maintaining tested backups and having an incident-response process in place. These measures can help website owners recover faster and limit the impact of an attack.
 

Don't miss the most important news and views of the day. Get them on our Telegram channel

First Published: Aug 24 2026 | 4:36 PM IST