Hackers Set Traps on Over 2000 Hacked WordPress Sites for Cryptocurrency Users

cryptonews.ruОпубліковано о 2026-08-21Востаннє оновлено о 2026-08-21

Анотація

Cybersecurity firm Check Point Research has uncovered a hacking campaign, dubbed "StopAndProtect," that has compromised over 2,000 poorly maintained WordPress sites. These legitimate-looking websites are used to host malware that specifically targets cryptocurrency users and Windows systems. The campaign employs a deceptive tactic where visitors are shown a fake CAPTCHA page. Attempting to solve it instructs the user to run a malicious PowerShell command. This downloads .NET malware capable of stealing cryptocurrency wallet seed phrases, saved passwords, and files from the infected computer. The malware can also encrypt data for ransom, take screenshots, and even record keystrokes. The attackers' unique method involves using these hijacked WordPress domains as free infrastructure to host malicious payloads, command-and-control servers, and stolen data storage. Researchers gained significant insight because the hackers left directories and log files publicly accessible online. These logs revealed an infection of over 6,000 unique IP addresses between mid-May and late July, with victims primarily in the U.S., Russia, and India. The uncovered data also included an attacker's tool for managing the compromised sites and a list of the nearly 2,000 domains involved in the scheme.

A criminal group, which Check Point Research has named StopAndProtect, is using about 2000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seed phrases, passwords, and files from infected Windows computers.

For cryptocurrency owners, the most alarming aspect is that the hijackings occur on legitimate-looking websites that appear as ordinary business blogs or sites.

Check Point published details on August 18, linking a ransomware sample discovered in mid-May to a larger campaign of extortion and surveillance.

Why the author places this story?

Most malware is distributed from servers rented or hacked by attackers. StopAndProtect uses a different approach, says researcher Yaromyr Gorieishi. Their ransomware, payloads, command-and-control infrastructure, and stolen data storage are hosted on WordPress domains that the criminals did not have to pay for or hack.

"That's the most interesting part of the campaign," noted Gorieishi. One server can host the payload, redirect commands to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can become a springboard for attacks by other malicious actors.

The sites are poorly maintained, as Gorieishi's team discovered when they decided to examine the WordPress instance behind one of the malicious domains. The researcher found almost 40 different vulnerabilities in the software, dating back to 2021.

How the Fake CAPTCHA Phishing Attack Works

Cryptocurrency owners should be especially wary of this threat. The phishing campaign tricks Windows users into believing they need to pass a CAPTCHA to access a website. However, the CAPTCHA is actually fraudulent, and users attempting to pass it will be prompted to copy and paste a PowerShell command into the command line.

This PowerShell command will start downloading .NET malware, which will allow the attacker to trac stored passwords, cryptocurrency wallet seed phrases, and other data from the compromised computer.

The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it, demanding a ransom. According to Decrypt, users should be wary of sites that ask them to paste or type something in, and leave the page as soon as they see such a request.

Cryptocurrency wallets are not the only target of this campaign. In many cases, the attackers use the malware to steal files from the victim's computer. Reports indicate that the attackers scan files on the infected computer and choose the most interesting ones to steal.

Newer versions of the malware are also capable of recording keystrokes, taking screenshots every 30 seconds, and even using WhatsApp to photograph the victim's contact list.

What the attackers dentpublished online

The most valuable information about the StopAndProtect campaign came from the attackers' own servers. The attackers used inefficient cybersecurity methods, leaving directories and log files open for access from the internet. Check Point suspects that one of the attackers' computers was compromised, and that the criminals dentuploaded some files to the server.

Among the files, Gorieishi found the source code of an automation tool that the attackers used to manage the hacked websites.

The tool, written in the legacy language Visual Basic 6, allows the attacker to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update malware on the compromised sites. The attached text files also contain a list of nearly 2000 domains that were hacked and turned into phishing sites.

Event logs also helped the researcher understand the scale of the attack. As of July 24, over 6000 unique IP addresses had been infected as a result of the campaign. Of these, 1852 users were in the USA, with 630 each in Russia and India.

From mid-May to the end of July, researchers discovered over 700 archives of stolen files. One open folder on the server contained over 20,000 screenshots of victims' computers.

end-content

Пов'язані питання

QWhat method does the StopAndProtect criminal group use to distribute malware, according to Check Point Research?

AThe StopAndProtect group uses around 2000 poorly-maintained WordPress blogs to host malware.

QWhat is the initial trick used in the phishing campaign described in the article to target Windows users?

AThe phishing campaign tricks users by displaying a fake CAPTCHA check, prompting them to copy and paste a PowerShell command into their command line.

QWhat sensitive data does the malware primarily target from infected computers?

AThe malware primarily targets and steals cryptocurrency wallet seed phrases, stored passwords, and other files from the compromised computers.

QHow did researchers obtain significant information about the StopAndProtect campaign's operations?

AResearchers obtained significant information because the attackers used poor cybersecurity practices, leaving directories and log files openly accessible on the internet from their own servers.

QWhat tool did the attackers use to manage the compromised websites, and what was notable about its programming language?

AThe attackers used an automation tool written in the outdated Visual Basic 6 language to manage the compromised websites, allowing them to control phishing pages and update malware.

Пов'язані матеріали

Trump Heads to South Carolina Amid Intensified Congressional Battle, Backed by Cryptocurrency and Artificial Intelligence Supporters

Former US President Donald Trump is re-engaging in the political arena as America prepares for upcoming Congressional elections, which will heavily influence the regulation of cryptocurrencies and artificial intelligence. Trump is reportedly leveraging his $400 million MAGA Inc. super PAC to aid vulnerable Republicans in maintaining their Congressional majority. The outcome of these elections is critical for major financial backers this cycle. The cryptocurrency industry seeks a Republican-led Congress to pass the CLARITY Act and secure favorable regulations from the SEC and CFTC. Simultaneously, the AI sector aims to counter the perception that it is a liability in elections. Trump's campaign begins with a rally in South Carolina for Senator Darlin Graham. Republican officials suggest his influence could be decisive. Concurrently, crypto, AI, and online gambling companies have contributed a record $517 million this election cycle, with significant sums directed toward Trump-aligned groups. For instance, AI-focused PACs have raised and spent tens of millions. However, AI investments face public skepticism, with concerns over data centers potentially harming local political candidates. The effectiveness of Trump's strategy will be tested in the upcoming elections, where Republican candidates may rely on his support despite its controversial nature.

cryptonews.ru1 год тому

Trump Heads to South Carolina Amid Intensified Congressional Battle, Backed by Cryptocurrency and Artificial Intelligence Supporters

cryptonews.ru1 год тому

Торгівля

Спот
活动图片