A criminal group, which Check Point Research has named StopAndProtect, is using about 2000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seed phrases, passwords, and files from infected Windows computers.
For cryptocurrency owners, the most alarming aspect is that the hijackings occur on legitimate-looking websites that appear as ordinary business blogs or sites.
Check Point published details on August 18, linking a ransomware sample discovered in mid-May to a larger campaign of extortion and surveillance.
Why the author places this story?
Most malware is distributed from servers rented or hacked by attackers. StopAndProtect uses a different approach, says researcher Yaromyr Gorieishi. Their ransomware, payloads, command-and-control infrastructure, and stolen data storage are hosted on WordPress domains that the criminals did not have to pay for or hack.
"That's the most interesting part of the campaign," noted Gorieishi. One server can host the payload, redirect commands to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can become a springboard for attacks by other malicious actors.
The sites are poorly maintained, as Gorieishi's team discovered when they decided to examine the WordPress instance behind one of the malicious domains. The researcher found almost 40 different vulnerabilities in the software, dating back to 2021.
How the Fake CAPTCHA Phishing Attack Works
Cryptocurrency owners should be especially wary of this threat. The phishing campaign tricks Windows users into believing they need to pass a CAPTCHA to access a website. However, the CAPTCHA is actually fraudulent, and users attempting to pass it will be prompted to copy and paste a PowerShell command into the command line.
This PowerShell command will start downloading .NET malware, which will allow the attacker to trac stored passwords, cryptocurrency wallet seed phrases, and other data from the compromised computer.
The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it, demanding a ransom. According to Decrypt, users should be wary of sites that ask them to paste or type something in, and leave the page as soon as they see such a request.
Cryptocurrency wallets are not the only target of this campaign. In many cases, the attackers use the malware to steal files from the victim's computer. Reports indicate that the attackers scan files on the infected computer and choose the most interesting ones to steal.
Newer versions of the malware are also capable of recording keystrokes, taking screenshots every 30 seconds, and even using WhatsApp to photograph the victim's contact list.
What the attackers dentpublished online
The most valuable information about the StopAndProtect campaign came from the attackers' own servers. The attackers used inefficient cybersecurity methods, leaving directories and log files open for access from the internet. Check Point suspects that one of the attackers' computers was compromised, and that the criminals dentuploaded some files to the server.
Among the files, Gorieishi found the source code of an automation tool that the attackers used to manage the hacked websites.
The tool, written in the legacy language Visual Basic 6, allows the attacker to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update malware on the compromised sites. The attached text files also contain a list of nearly 2000 domains that were hacked and turned into phishing sites.
Event logs also helped the researcher understand the scale of the attack. As of July 24, over 6000 unique IP addresses had been infected as a result of the campaign. Of these, 1852 users were in the USA, with 630 each in Russia and India.
From mid-May to the end of July, researchers discovered over 700 archives of stolen files. One open folder on the server contained over 20,000 screenshots of victims' computers.
end-content




