Nearly 2,000 hacked WordPress sites used to spread malware and steal crypto

Nearly 2,000 hacked WordPress sites used to spread malware and steal crypto

Hacked WordPress sites turned into malware hubs

Cybersecurity firm Check Point Research discovered nearly 2,000 hacked WordPress websites being used to distribute malware, steal data, and deploy ransomware. The operation, called StopAndProtect, targets Windows users through fake security prompts on compromised sites.

The attackers use these sites to host malicious software, send commands to infected computers, and store stolen information like documents, screenshots, and activity logs.

How the malware infects users

The infection starts with a fake CAPTCHA prompt on a hacked WordPress site. Victims are tricked into running a PowerShell command that installs malware. This malware can:

  • Steal login credentials and crypto wallet seed phrases (a set of words that gives access to crypto funds)
  • Spread through networks and USB drives
  • Lock computer screens
  • Deploy ransomware, which encrypts files and demands payment to unlock them

The report did not confirm whether macOS or Linux users are affected.

Key details from the investigation

  • Check Point identified nearly 2,000 compromised WordPress sites used in the operation
  • Over 6,000 unique IP addresses were compromised as of July 24, including 1,852 in the United States
  • The malware includes multiple tools working together, such as file encryption, data theft, and live chat for attackers to communicate with victims
  • Researchers believe the attackers accidentally infected themselves, exposing internal files and tools used to manage the compromised sites

What is confirmed

  • The StopAndProtect operation uses hacked WordPress sites to distribute malware
  • The malware targets Windows users through fake CAPTCHA prompts
  • The malware can steal crypto wallet seed phrases and deploy ransomware
  • Nearly 2,000 WordPress sites and over 6,000 IP addresses were compromised

What is still unclear

  • Whether macOS and Linux users are also targeted by this malware
  • The total number of victims or amount of stolen funds
  • The identity or location of the attackers

Why this matters for website owners and crypto users

This discovery highlights the risks of visiting compromised websites, especially for those who store crypto assets. Malware that steals seed phrases can give attackers full access to crypto wallets, leading to financial losses. Website owners using WordPress should ensure their sites are secure to prevent being used as part of such operations.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!