Most cyber crime investigations reveal the aftermath of an attack. Few reveal the attackers themselves.

That’s what makes Check Point Research‘s latest investigation into StopAndProtect so unusual.

While analyzing a newly identified cyber crime operation, researchers uncovered a series of operational security (OPSEC) mistakes that exposed the attackers’ own infrastructure including: victim logs, screenshots, source code, internal management tools, and evidence of a campaign impacting more than 5,000 infected computers worldwide. The investigation also uncovered files referencing close to 2,000 compromised WordPress domains, providing a rare look inside how a modern cyber criminal operation is built and managed.

According to Eli Smadja at Check Point Research:
“StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware. Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser.”

Building a Criminal Infrastructure from Legitimate Websites

The exposed files revealed more than malware. They revealed the architecture behind the operation.

Instead of relying on dedicated command-and-control servers, the StopAndProtect operators built a distributed infrastructure by abusing compromised WordPress websites. According to Statista, WordPress accounts for more than 43% of the global website builder market as of 2026, making it an attractive target for cyber criminals seeking both scale and legitimacy.

The attackers used compromised websites throughout the attack lifecycle to host malware, deliver additional payloads, communicate with infected devices, and store stolen documents, screenshots, and activity logs. By repurposing trusted websites, they created resilient infrastructure that blended into legitimate internet traffic.

The investigation also highlights a persistent challenge for website owners. Many WordPress installations remain unpatched or run outdated software and plugins. In one example, Check Point Research identified a compromised website running a WordPress version from 2021 with nearly 40 known vulnerabilities, demonstrating how neglected websites can become part of a much larger cyber crime operation.

When the Attackers Became Their Own Weakest Link

Ironically, the same operation designed to avoid detection ultimately exposed itself.

During the investigation, researchers discovered publicly accessible directories containing malware logs, victim screenshots, stolen files, and internal tools used to manage the campaign. They also recovered source code for automation tools that helped manage compromised WordPress websites at scale, along with files referencing close to 2,000 compromised domains associated with the operation.

Researchers also suspect that one of the operators may have accidentally infected their own computer, causing internal development files to be uploaded to the same infrastructure used to collect stolen victim data. Although the archive was removed a few days later, the temporary exposure provided valuable insight into how the campaign was organized and operated.

The incident serves as a reminder that even threat actors can make costly operational mistakes, and when they do, defenders gain an advantage to better understand how modern cyber criminal campaigns function.

A Reminder That Trust Is Becoming the New Attack Surface

Like many of today’s cyber attacks, StopAndProtect doesn’t begin with a sophisticated exploit. Instead, victims are presented with a fake CAPTCHA using the increasingly common ClickFix social engineering technique. Users are instructed to copy, paste, and execute commands on their own computers, unknowingly launching a multi-stage infection chain that downloads additional malware from compromised WordPress websites.

The campaign reflects a broader shift in the threat landscape in which attackers are combining social engineering, trusted infrastructure, and modular malware to maximize their reach while reducing the likelihood of detection. In many cases, ransomware is only one possible outcome. The same toolkit can also steal documents, harvest credentials, or quietly exfiltrate sensitive information, depending on the attacker’s objectives.

Prevention Starts Before the Attack Succeeds

The StopAndProtect investigation demonstrates how cyber crime continues to evolve through the combination of trusted infrastructure, social engineering, and adaptable malware operating at scale. Organizations can reduce their risk by keeping WordPress installations and plugins up to date, educating users to recognize ClickFix-style social engineering techniques, monitoring for suspicious PowerShell activity, and adopting a prevention-first security strategy that stops attacks before malware establishes persistence or sensitive data is stolen.

For consumers, the advice is equally straightforward: be skeptical of websites that ask you to copy, paste, or run commands outside your browser. Legitimate CAPTCHA challenges should never require those steps.

Learn More

The StopAndProtect investigation offers a rare glimpse inside a modern cyber crime operation revealing how attackers weaponized thousands of compromised WordPress websites, but also how their own operational mistakes exposed the infrastructure behind the campaign.

For security practitioners interested in the complete technical analysis, including the infection chain, malware components, indicators of compromise (IOCs), and defensive recommendations, read the full Check Point Research report here.

 

You may also like