Nearly 2,000 hacked WordPress sites used to spread malware and steal crypto
Hacked WordPress sites turned into malware hubs
Cybersecurity firm Check Point Research discovered nearly 2,000 hacked WordPress websites being used to distribute malware, steal data, and deploy ransomware. The operation, called StopAndProtect, targets Windows users through fake security prompts on compromised sites.
The attackers use these sites to host malicious software, send commands to infected computers, and store stolen information like documents, screenshots, and activity logs.
How the malware infects users
The infection starts with a fake CAPTCHA prompt on a hacked WordPress site. Victims are tricked into running a PowerShell command that installs malware. This malware can:
- Steal login credentials and crypto wallet seed phrases (a set of words that gives access to crypto funds)
- Spread through networks and USB drives
- Lock computer screens
- Deploy ransomware, which encrypts files and demands payment to unlock them
The report did not confirm whether macOS or Linux users are affected.
Key details from the investigation
- Check Point identified nearly 2,000 compromised WordPress sites used in the operation
- Over 6,000 unique IP addresses were compromised as of July 24, including 1,852 in the United States
- The malware includes multiple tools working together, such as file encryption, data theft, and live chat for attackers to communicate with victims
- Researchers believe the attackers accidentally infected themselves, exposing internal files and tools used to manage the compromised sites
What is confirmed
- The StopAndProtect operation uses hacked WordPress sites to distribute malware
- The malware targets Windows users through fake CAPTCHA prompts
- The malware can steal crypto wallet seed phrases and deploy ransomware
- Nearly 2,000 WordPress sites and over 6,000 IP addresses were compromised
What is still unclear
- Whether macOS and Linux users are also targeted by this malware
- The total number of victims or amount of stolen funds
- The identity or location of the attackers
Why this matters for website owners and crypto users
This discovery highlights the risks of visiting compromised websites, especially for those who store crypto assets. Malware that steals seed phrases can give attackers full access to crypto wallets, leading to financial losses. Website owners using WordPress should ensure their sites are secure to prevent being used as part of such operations.