Hackers Set Traps on Over 2000 Hacked WordPress Sites for Cryptocurrency Users

cryptonews.ruPublicado a 2026-08-21Actualizado a 2026-08-21

Resumen

Cybersecurity firm Check Point Research has uncovered a hacking campaign, dubbed "StopAndProtect," that has compromised over 2,000 poorly maintained WordPress sites. These legitimate-looking websites are used to host malware that specifically targets cryptocurrency users and Windows systems. The campaign employs a deceptive tactic where visitors are shown a fake CAPTCHA page. Attempting to solve it instructs the user to run a malicious PowerShell command. This downloads .NET malware capable of stealing cryptocurrency wallet seed phrases, saved passwords, and files from the infected computer. The malware can also encrypt data for ransom, take screenshots, and even record keystrokes. The attackers' unique method involves using these hijacked WordPress domains as free infrastructure to host malicious payloads, command-and-control servers, and stolen data storage. Researchers gained significant insight because the hackers left directories and log files publicly accessible online. These logs revealed an infection of over 6,000 unique IP addresses between mid-May and late July, with victims primarily in the U.S., Russia, and India. The uncovered data also included an attacker's tool for managing the compromised sites and a list of the nearly 2,000 domains involved in the scheme.

A criminal group, which Check Point Research has named StopAndProtect, is using about 2000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seed phrases, passwords, and files from infected Windows computers.

For cryptocurrency owners, the most alarming aspect is that the hijackings occur on legitimate-looking websites that appear as ordinary business blogs or sites.

Check Point published details on August 18, linking a ransomware sample discovered in mid-May to a larger campaign of extortion and surveillance.

Why the author places this story?

Most malware is distributed from servers rented or hacked by attackers. StopAndProtect uses a different approach, says researcher Yaromyr Gorieishi. Their ransomware, payloads, command-and-control infrastructure, and stolen data storage are hosted on WordPress domains that the criminals did not have to pay for or hack.

"That's the most interesting part of the campaign," noted Gorieishi. One server can host the payload, redirect commands to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can become a springboard for attacks by other malicious actors.

The sites are poorly maintained, as Gorieishi's team discovered when they decided to examine the WordPress instance behind one of the malicious domains. The researcher found almost 40 different vulnerabilities in the software, dating back to 2021.

How the Fake CAPTCHA Phishing Attack Works

Cryptocurrency owners should be especially wary of this threat. The phishing campaign tricks Windows users into believing they need to pass a CAPTCHA to access a website. However, the CAPTCHA is actually fraudulent, and users attempting to pass it will be prompted to copy and paste a PowerShell command into the command line.

This PowerShell command will start downloading .NET malware, which will allow the attacker to trac stored passwords, cryptocurrency wallet seed phrases, and other data from the compromised computer.

The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it, demanding a ransom. According to Decrypt, users should be wary of sites that ask them to paste or type something in, and leave the page as soon as they see such a request.

Cryptocurrency wallets are not the only target of this campaign. In many cases, the attackers use the malware to steal files from the victim's computer. Reports indicate that the attackers scan files on the infected computer and choose the most interesting ones to steal.

Newer versions of the malware are also capable of recording keystrokes, taking screenshots every 30 seconds, and even using WhatsApp to photograph the victim's contact list.

What the attackers dentpublished online

The most valuable information about the StopAndProtect campaign came from the attackers' own servers. The attackers used inefficient cybersecurity methods, leaving directories and log files open for access from the internet. Check Point suspects that one of the attackers' computers was compromised, and that the criminals dentuploaded some files to the server.

Among the files, Gorieishi found the source code of an automation tool that the attackers used to manage the hacked websites.

The tool, written in the legacy language Visual Basic 6, allows the attacker to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update malware on the compromised sites. The attached text files also contain a list of nearly 2000 domains that were hacked and turned into phishing sites.

Event logs also helped the researcher understand the scale of the attack. As of July 24, over 6000 unique IP addresses had been infected as a result of the campaign. Of these, 1852 users were in the USA, with 630 each in Russia and India.

From mid-May to the end of July, researchers discovered over 700 archives of stolen files. One open folder on the server contained over 20,000 screenshots of victims' computers.

end-content

Preguntas relacionadas

QWhat method does the StopAndProtect criminal group use to distribute malware, according to Check Point Research?

AThe StopAndProtect group uses around 2000 poorly-maintained WordPress blogs to host malware.

QWhat is the initial trick used in the phishing campaign described in the article to target Windows users?

AThe phishing campaign tricks users by displaying a fake CAPTCHA check, prompting them to copy and paste a PowerShell command into their command line.

QWhat sensitive data does the malware primarily target from infected computers?

AThe malware primarily targets and steals cryptocurrency wallet seed phrases, stored passwords, and other files from the compromised computers.

QHow did researchers obtain significant information about the StopAndProtect campaign's operations?

AResearchers obtained significant information because the attackers used poor cybersecurity practices, leaving directories and log files openly accessible on the internet from their own servers.

QWhat tool did the attackers use to manage the compromised websites, and what was notable about its programming language?

AThe attackers used an automation tool written in the outdated Visual Basic 6 language to manage the compromised websites, allowing them to control phishing pages and update malware.

Lecturas Relacionadas

Stripe’s 16-Year Chronicle: From 7 Lines of Code to a $100 Billion Valuation

Stripe's 16-year journey began with a simple promise: "7 lines of code to accept payments." Founded by Patrick and John Collison, the company started by hiding the complexity of bank integrations and merchant accounts behind a clean API, initially targeting developers at startups. This early focus on user experience and technical simplicity fueled rapid adoption. A key early milestone was establishing vital bank partnerships, a challenge overcome by hiring Billy Alvarado, who brought crucial institutional relationship skills. From this foundation, Stripe systematically expanded its product boundaries. It launched Connect for platform payments, Atlas for company formation, Radar for fraud prevention, and Billing for subscriptions. This transformed Stripe from a payment processor into a broader financial infrastructure suite for internet businesses. The COVID-19 pandemic accelerated growth but also led to over-hiring. A 14% layoff in 2022 marked a period of organizational correction. Subsequently, Stripe shifted its growth strategy towards strategic acquisitions to enter new domains quickly. It acquired Bridge (stablecoin infrastructure), Privy (wallet infrastructure), Metronome (usage-based billing), and agreed to buy OpenRouter (AI model routing). These moves signal Stripe's ambition to build a "programmable money system" for the emerging AI and agent-based economy, managing not just currency flows but also the measurement and pricing of computational resources like AI tokens. Internally, Stripe leverages AI agents (like "Minions") to boost engineering productivity. Despite scaling to nearly 8,000 employees and processing $1.9 trillion in payment volume annually, the company remains private. A recent employee tender offer valued it at $159 billion. The core question for Stripe's future is whether it can successfully integrate its expanding product matrix—spanning payments, crypto, and AI infrastructure—into a cohesive platform, positioning itself as the foundational economic layer for autonomous software agents.

marsbitHace 26 min(s)

Stripe’s 16-Year Chronicle: From 7 Lines of Code to a $100 Billion Valuation

marsbitHace 26 min(s)

Treasury Secretary's Move to Suppress Treasury Yields Ignites 'Currency Debasement Trade'! Gold Hits Three-Month High, Bitcoin Surges Over 25% in a Single Week

US Treasury Secretary Besant's efforts to lower long-term Treasury yields by announcing expanded buybacks had only a brief market impact. However, this move fueled a "currency devaluation trade," weakening the US dollar while boosting both gold (to a three-month high) and Bitcoin (up over 25% for the week). Analysts attribute this reaction to deepening market concerns over the massive US fiscal deficit and structural pressures keeping long-term rates elevated, including fierce competition for capital from global government borrowing and massive AI sector financing. Despite the Treasury's actions, fundamental forces like growth, inflation, and capital demand are seen as limiting its ability to sustainably suppress yields. Bitcoin's strong positive correlation with gold has reinforced its narrative as a hedge against devaluation. While equity markets have shown resilience, some strategists warn that Treasury yields nearing 5% increase pressure on the dollar and high-leverage assets. Figures like Ray Dalio have advised reducing bond exposure in favor of gold and some Bitcoin, citing US debt risks. Market opinions are divided on the sustainability of the devaluation trade, with some noting the lack of a near-term catalyst for its next leg higher. The underlying tension between the Treasury's desire for lower borrowing costs and the Federal Reserve's focus on inflation and reducing market intervention remains a key theme. Upcoming events like Nvidia's earnings and the Jackson Hole symposium will test whether AI profits can continue supporting stocks and if the Fed aligns more with Washington's preference for easier financial conditions.

华尔街日报Hace 2 hora(s)

Treasury Secretary's Move to Suppress Treasury Yields Ignites 'Currency Debasement Trade'! Gold Hits Three-Month High, Bitcoin Surges Over 25% in a Single Week

华尔街日报Hace 2 hora(s)

Alexander Shokhin: Business Needs an Interest Rate Below 10% and the Dollar at 90-95 Rubles

Alexander Shokhin, head of the Russian Union of Industrialists and Entrepreneurs (RSPP), has advocated for potentially using "non-market" tools to keep the ruble within a target exchange rate corridor. This, he argues on August 21, would help avoid excessive volatility, though he called the topic a separate discussion. Shokhin had previously raised the idea of a currency corridor in late May, noting the ruble's current exchange rate is not fully market-driven due to a limited currency segment and reduced foreign currency demand. He stated that many business community colleagues propose fixing a corridor, even through non-market methods, to ensure predictability. The business community's key targets, as outlined by Shokhin in late December 2025, are a Central Bank key rate of 12%, inflation of 4–5%, and a US dollar exchange rate of 90–95 rubles by the end of 2026. A turning point for investment, he said, would be lowering the rate to 12% with 6% inflation, though truly comfortable business conditions would require a rate below 10%. He stressed the critical importance of currency predictability for corporate investment decisions. From a data analysis perspective, the idea of a ruble corridor is not new. A similar mechanism was used in Russia from 1995 to 1998, where the central bank held the dollar within fixed boundaries through regular interventions. This regime lasted three years before ending abruptly during the 1998 default, illustrating the fragility of rigid targets under external shocks. The macro-economic link is clear: stricter corridors require more reserves to defend against currency pressure. The key unresolved technical aspect is the specific sources and volume of such interventions given the current market's limited liquidity. Whether this discussion remains theoretical or leads to concrete corridor parameters will be seen in the coming months.

cryptonews.ruHace 4 hora(s)

Alexander Shokhin: Business Needs an Interest Rate Below 10% and the Dollar at 90-95 Rubles

cryptonews.ruHace 4 hora(s)

Trading

Spot
活动图片