2,000 hacked WordPress sites become traps for crypto users

- StopAndProtect has compromised nearly 2,000 WordPress sites, turning them into infrastructure for malware attacks.
- The malware targets crypto users, stealing wallet seed phrases, passwords, files and other sensitive data from Windows devices.
- Attackers use fake CAPTCHA pages to trick victims into running malicious PowerShell commands that install the malware.
A criminal group that Check Point Research has dubbed StopAndProtect has been using nearly 2,000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seeds, passwords, and files from infected Windows computers.
For crypto holders, the most alarming part is that the takeovers are distributed across legitimate sites that appear to be standard business blogs or sites.
Check Point published the details on August 18, having tied the ransomware sample it spotted in mid-May to a larger extortion and surveillance campaign.
Why is the hosting the story
Most malware campaigns these days are distributed from servers rented or compromised by the attackers. StopAndProtect takes a different route, said the researcher JaromÃr HoÅ™ejÅ¡Ã. Their ransomware, payloads, command-and-control infrastructure, and storage for stolen data are all hosted on WordPress domains that the criminals did not have to pay for or compromise.
This is the most interesting part of the campaign, Hořejšà noted. One server can host the payload, redirect instructions to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can turn into a launchpad for attacks by other bad actors.
The sites are poorly maintained, as HořejšÒs team discovered when they decided to look at the WordPress instance behind one of the malicious domains. The researcher found nearly 40 different vulnerabilities in the software dating back to 2021.
How a fake CAPTCHA phishing scam works
Crypto holders should be especially wary of this threat. The phishing campaign tricks Windows users into believing that they need to complete a CAPTCHA test to gain access to a website. However, the CAPTCHA is actually a scam, and users who try to complete it will be instructed to copy and paste a PowerShell command into their command prompt.
This PowerShell command will then begin downloading .NET payloads that will allow the attacker to extract saved passwords, crypto wallet seeds, and other data from the compromised computer.
The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it and demand payment in ransomware. According to Decrypt, users should be wary of sites that prompt them to paste or type anything and leave the page as soon as they see such a request.
Crypto wallets are not the only target of this campaign. In many cases, the attackers are using the malware to steal files from the victim’s computer. According to reports, the threat actors are scanning the files on the infected computer and selecting the most interesting ones to steal.
The newer versions of the malware also have the ability to log keystrokes, take screenshots every 30 seconds, and even use WhatsApp to take photos of the victim’s contact list.
What the attackers accidentally posted on the web
The most valuable intelligence on the StopAndProtect campaign came from the criminals’ own servers. The attackers had poor cybersecurity practices, leaving directories and log files open to the web. Check Point suspects that one of the attackers’ own computers had been compromised and that the criminal had accidentally uploaded some files to the server.
Among the files, Hořejšà found the source code for an automation tool that the attackers were using to control the hacked websites.
The tool, written in legacy Visual Basic 6, allows the criminal to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update the malware on the compromised sites. Text files attached to the tool also include a list of the nearly 2,000 domains that have been hacked and turned into phishing sites.
The log files also helped the researcher understand the scale of the attack. As of July 24, the campaign had already infected more than 6,000 unique IP addresses. Of these, 1,852 users were located in the United States, and 630 each in Russia and India.
Between mid-May and the end of July, researchers discovered more than 700 archives of stolen files. One of the open directories on the server contained more than 20,000 screenshots of victims’ computers.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What is StopAndProtect?
StopAndProtect is a cybercrime operation identified by Check Point Research that combines file encryption with data theft and runs its infrastructure on nearly 2,000 hacked WordPress websites rather than dedicated servers.
How does the StopAndProtect malware infect a computer?
A compromised WordPress site shows Windows visitors a fake CAPTCHA using the ClickFix technique, instructing them to run a PowerShell command that installs downloaders and then components capable of stealing credentials, crypto wallet seed phrases, and files.
How many systems has StopAndProtect affected?
As of July 24, 2026, the campaign had compromised more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India, according to Check Point Research.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar
Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.
















