Nearly 2,000 Hacked WordPress Sites Turned Into Criminal Infrastructure
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Nearly 2,000 hacked WordPress websites were used to distribute malware, steal data, monitor victims, and deploy ransomware, according to cybersecurity firm Check Point Research.
Key facts
- By July 24, the campaign had compromised more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India
- Nearly 2,000 hacked WordPress websites were used to distribute malware, steal data, monitor victims, and deploy ransomware, according to cybersecurity firm Check Point Research
- In May, an apparel website linked to FBI Director Kash Patel was taken offline after macOS visitors were reportedly targeted with ClickFix malware
- In July, Jamf Threat Labs found ClickFix-style malware being distributed through a sponsored ad on X
Summary
Check Point Research identified nearly 2,000 compromised WordPress sites used by the StopAndProtect malware operation. More than 6,000 unique IP addresses had been compromised as of July 24, including 1,852 in the United States. Researchers believe the attackers accidentally infected themselves, exposing internal files and tools used to manage compromised sites. In the report published on Tuesday, researchers said the StopAndProtect ransomware family was first discovered in mid-May before tracing it to a broader operation.