StopAndProtect: Thousands of Hacked WordPress Sites Exposed

Widespread campaign compromises thousands of WordPress sites

The StopAndProtect operation has compromised thousands of legitimate WordPress sites, weaponising them to distribute malware and target unsuspecting users. This campaign, tracked by Check Point Research (CPR) and corroborated by Rapid7, highlights a significant threat to both website owners and visitors, especially in the UK where several sites were affected.

StopAndProtect: Anatomy of a Global WordPress Compromise

In August 2026, CPR revealed the StopAndProtect operation, a sophisticated campaign abusing thousands of compromised WordPress websites. Researchers gained unprecedented access to the adversary’s infrastructure after a series of operational security mistakes by the attackers. This provided a rare glimpse into the scale and methods of the operation, confirming over 5,000 infected devices and nearly 2,000 compromised WordPress domains.

Unlike isolated website breaches, StopAndProtect leverages these WordPress sites for multiple purposes: hosting malicious payloads, acting as command and control (C2) nodes, and storing exfiltrated data such as stolen documents and screenshots. This distributed infrastructure helps attackers blend malicious activity with legitimate web traffic, making detection more difficult for defenders and users alike.

How the Attack Works: Technique and Timeline

The campaign’s technical sophistication lies in its use of compromised WordPress sites and the social engineering techniques it deploys. Rather than exploiting a single plugin or version, attackers inject malicious JavaScript into a wide variety of legitimate WordPress sites. These injections are not limited to any specific sector or geography, with at least 250 distinct infected sites tracked across 12 countries, including the UK.

ClickFix and Fake CAPTCHA Lures

A core component of StopAndProtect is its adaptation of the ClickFix social engineering technique. When a user visits an infected site, they are presented with a fake Cloudflare human verification CAPTCHA. Unlike normal CAPTCHAs, this prompt instructs users to copy and run a command in their operating system, often placing the command on the user’s clipboard automatically.

  • The prompt appears convincingly branded, increasing the likelihood of user compliance.
  • Users who run the command inadvertently launch a multi-stage infection chain on their Windows device.
  • This chain is largely fileless, using PowerShell stagers and in-memory shellcode loaders to avoid detection.

CPR and Rapid7 warn that legitimate sites weaponised in this way can catch even security-aware users off guard, especially when the CAPTCHA appears on a site they trust.

Payloads and Stealers

The infection chain ultimately delivers various information stealing malware, including:

  • Vidar stealer variants
  • Impure Stealer (a .NET-based infostealer)
  • VodkaStealer (a new C++-based infostealer)

These payloads are capable of harvesting sensitive information, such as credentials, documents, screenshots and activity logs. The malware communicates with attacker infrastructure, much of which is hosted on other compromised WordPress sites, further muddying the waters between legitimate and malicious traffic.

Timeline of the StopAndProtect Campaign

  • July to August 2025: Infrastructure for the campaign, including domains, first appears.
  • 20 August 2025: Israel’s National Digital Agency reports on a large-scale campaign using ClickFix techniques and fake CAPTCHA pages (dubbed ShadowCaptcha).
  • December 2025: Rapid7 establishes that the current campaign form has been active since this time.
  • 10 March 2026: Rapid7 publishes technical details, indicators of compromise and YARA rules for detection.
  • 18 August 2026: Check Point Research exposes the scale and methods of StopAndProtect, quantifying the number of victims and compromised sites.

No single plugin or WordPress version was cited as the root cause, suggesting that attackers are exploiting a range of vulnerabilities or weak points across the WordPress ecosystem.

Current Exploitation Status and Indicators

The StopAndProtect operation remains active in the wild as of August 2026. Over 5,000 infected endpoints and thousands of compromised domains have been identified. Rapid7’s reporting includes detailed indicators of compromise (IOCs) and YARA rules, which are available for defenders to incorporate into their detection and response workflows.

  • The campaign is ongoing, with both new sites being compromised and endpoints infected daily.
  • There is no public attribution to a specific threat actor group.
  • The operation primarily targets Windows endpoints, but any organisation operating a WordPress site could become part of the attacker’s infrastructure if compromised.

Legitimate WordPress websites across multiple sectors and geographies are being abused, making it difficult for users and defenders to distinguish between safe and weaponised sites.

Why StopAndProtect Matters to UK Organisations

UK sites and users are directly affected, with Rapid7 identifying at least 250 infected sites worldwide, including several in the UK. For small and medium businesses (SMBs) running WordPress or relying on WordPress-backed web services, the risks are twofold: their own sites could be weaponised to attack others, and their users could be lured into infection chains on otherwise trusted sites.

The distributed and multi-purpose use of compromised WordPress sites—hosting malware, acting as C2, and storing stolen data—means that a breach can have far-reaching impacts, both reputational and operational. The attack also illustrates the dangers of sophisticated social engineering, where traditional technical controls may not be enough to protect users who are convinced to run commands outside the browser environment.

Immediate Actions for WordPress Site Owners and Users

  • Review and secure WordPress core, plugins and themes. Patch any known vulnerabilities urgently.
  • Audit site content for unexpected JavaScript or evidence of injection.
  • Monitor for signs of compromise using available IOCs and YARA rules from Rapid7’s March 2026 report.
  • Educate staff and users: never copy, paste or run commands from a web page prompt, especially after a CAPTCHA.
  • Consider deploying a web application firewall (WAF) and content security policy (CSP) rules to block connections to known malicious domains.

Organisations should remain vigilant, especially if their sites rely on WordPress or their staff frequently interact with third-party WordPress-backed services. Early detection and swift remediation are key to limiting the campaign’s impact.

Originally reported by Unknown.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call