Hackers Set Traps on Over 2000 Hacked WordPress Sites for Cryptocurrency Users

cryptonews.ruPubblicato 2026-08-21Pubblicato ultima volta 2026-08-21

Introduzione

Cybersecurity firm Check Point Research has uncovered a hacking campaign, dubbed "StopAndProtect," that has compromised over 2,000 poorly maintained WordPress sites. These legitimate-looking websites are used to host malware that specifically targets cryptocurrency users and Windows systems. The campaign employs a deceptive tactic where visitors are shown a fake CAPTCHA page. Attempting to solve it instructs the user to run a malicious PowerShell command. This downloads .NET malware capable of stealing cryptocurrency wallet seed phrases, saved passwords, and files from the infected computer. The malware can also encrypt data for ransom, take screenshots, and even record keystrokes. The attackers' unique method involves using these hijacked WordPress domains as free infrastructure to host malicious payloads, command-and-control servers, and stolen data storage. Researchers gained significant insight because the hackers left directories and log files publicly accessible online. These logs revealed an infection of over 6,000 unique IP addresses between mid-May and late July, with victims primarily in the U.S., Russia, and India. The uncovered data also included an attacker's tool for managing the compromised sites and a list of the nearly 2,000 domains involved in the scheme.

A criminal group, which Check Point Research has named StopAndProtect, is using about 2000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seed phrases, passwords, and files from infected Windows computers.

For cryptocurrency owners, the most alarming aspect is that the hijackings occur on legitimate-looking websites that appear as ordinary business blogs or sites.

Check Point published details on August 18, linking a ransomware sample discovered in mid-May to a larger campaign of extortion and surveillance.

Why the author places this story?

Most malware is distributed from servers rented or hacked by attackers. StopAndProtect uses a different approach, says researcher Yaromyr Gorieishi. Their ransomware, payloads, command-and-control infrastructure, and stolen data storage are hosted on WordPress domains that the criminals did not have to pay for or hack.

"That's the most interesting part of the campaign," noted Gorieishi. One server can host the payload, redirect commands to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can become a springboard for attacks by other malicious actors.

The sites are poorly maintained, as Gorieishi's team discovered when they decided to examine the WordPress instance behind one of the malicious domains. The researcher found almost 40 different vulnerabilities in the software, dating back to 2021.

How the Fake CAPTCHA Phishing Attack Works

Cryptocurrency owners should be especially wary of this threat. The phishing campaign tricks Windows users into believing they need to pass a CAPTCHA to access a website. However, the CAPTCHA is actually fraudulent, and users attempting to pass it will be prompted to copy and paste a PowerShell command into the command line.

This PowerShell command will start downloading .NET malware, which will allow the attacker to trac stored passwords, cryptocurrency wallet seed phrases, and other data from the compromised computer.

The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it, demanding a ransom. According to Decrypt, users should be wary of sites that ask them to paste or type something in, and leave the page as soon as they see such a request.

Cryptocurrency wallets are not the only target of this campaign. In many cases, the attackers use the malware to steal files from the victim's computer. Reports indicate that the attackers scan files on the infected computer and choose the most interesting ones to steal.

Newer versions of the malware are also capable of recording keystrokes, taking screenshots every 30 seconds, and even using WhatsApp to photograph the victim's contact list.

What the attackers dentpublished online

The most valuable information about the StopAndProtect campaign came from the attackers' own servers. The attackers used inefficient cybersecurity methods, leaving directories and log files open for access from the internet. Check Point suspects that one of the attackers' computers was compromised, and that the criminals dentuploaded some files to the server.

Among the files, Gorieishi found the source code of an automation tool that the attackers used to manage the hacked websites.

The tool, written in the legacy language Visual Basic 6, allows the attacker to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update malware on the compromised sites. The attached text files also contain a list of nearly 2000 domains that were hacked and turned into phishing sites.

Event logs also helped the researcher understand the scale of the attack. As of July 24, over 6000 unique IP addresses had been infected as a result of the campaign. Of these, 1852 users were in the USA, with 630 each in Russia and India.

From mid-May to the end of July, researchers discovered over 700 archives of stolen files. One open folder on the server contained over 20,000 screenshots of victims' computers.

end-content

Domande pertinenti

QWhat method does the StopAndProtect criminal group use to distribute malware, according to Check Point Research?

AThe StopAndProtect group uses around 2000 poorly-maintained WordPress blogs to host malware.

QWhat is the initial trick used in the phishing campaign described in the article to target Windows users?

AThe phishing campaign tricks users by displaying a fake CAPTCHA check, prompting them to copy and paste a PowerShell command into their command line.

QWhat sensitive data does the malware primarily target from infected computers?

AThe malware primarily targets and steals cryptocurrency wallet seed phrases, stored passwords, and other files from the compromised computers.

QHow did researchers obtain significant information about the StopAndProtect campaign's operations?

AResearchers obtained significant information because the attackers used poor cybersecurity practices, leaving directories and log files openly accessible on the internet from their own servers.

QWhat tool did the attackers use to manage the compromised websites, and what was notable about its programming language?

AThe attackers used an automation tool written in the outdated Visual Basic 6 language to manage the compromised websites, allowing them to control phishing pages and update malware.

Letture associate

You'll Be Surprised How Much WeChat's Architecture Differs from Telegram's

An article compares the core architectural philosophies of WeChat and Telegram, highlighting fundamental differences in data storage, monetization, and developer ecosystems. **Data Storage:** Telegram offers unlimited, synchronized cloud storage for seamless access across all devices. In contrast, WeChat stores chat history locally on each device, requiring a manual migration process for transfer and tethering desktop sessions to an active smartphone. **Features & Ecosystem:** Telegram's open Bot API allows for easy, free bot creation, while WeChat's massive ecosystem of over 4.8 million "mini-programs" operates within a closed, curated, and more regulated platform. Commenting also differs: Telegram uses integrated discussion threads for channels, whereas WeChat relies on pre-moderated comments for official accounts and separate chats for interaction. **File Sharing & Payments:** Telegram supports large file transfers (up to 4GB for Premium), while WeChat limits most files to 200MB. A key divergence is in payments: WeChat Pay is deeply integrated into daily life and commerce in China, whereas Telegram lacks a comparable built-in fiat payment system, focusing instead on third-party bots and crypto. **Analysis:** The comparison reveals two distinct models: WeChat is a tightly integrated, closed ecosystem deeply embedded in the real economy, while Telegram prioritizes open protocols, flexible data handling, and low barriers for developers. An added perspective notes that WeChat's fusion of messaging and payments in a single interface without end-to-end encryption for chats potentially broadens the attack surface, raising security questions as more functions converge.

cryptonews.ru2 h fa

You'll Be Surprised How Much WeChat's Architecture Differs from Telegram's

cryptonews.ru2 h fa

Trading

Spot
活动图片