threat-intel
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
High
Summary
A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack chain initiated by social engineering (ClickFix), resulting in a complex infrastructure for surveillance and data theft. The campaign utilizes a custom WordPress plugin to facilitate remote code execution and mass-manage infected sites, with a significant number of compromised IPs located in the U.S., Russia, and India.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
