Operation StopAndProtect is one of the most extensive cybercrime campaigns detected in 2026, leveraging nearly 2,000 compromised WordPress sites as infrastructure for malware distribution, data theft, and control of infected systems . Check Point Research researchers have revealed the detailed architecture of the operation, which is not based on a single malicious tool, but on an entire arsenal of specialized components that work together harmoniously to achieve the attackers’ goals.

The campaign was first detected in mid- May 2026 , when researchers discovered a ransomware family called StopAndProtect . However, it quickly became clear that the ransomware was just one of many tools used by the attackers. The infection chain begins with a ClickFix- style social engineering attack , in which the victim visits a compromised website and sees a fake CAPTCHA prompt. They are then tricked into copying and executing a PowerShell command , which sets in motion a multi-layered infection process.
According to Jaromír Hořejší, at Check Point Research, the enterprise does not always aim to deploy ransomware. In most cases, attackers prefer to silently steal lists of files and then specific documents from infected systems. This makes detection particularly difficult, as defenders cannot focus solely on file encryption, but must also monitor for credential theft, remote command execution, and suspicious PowerShell activity.
See also: WordPress sites hacked: Fake plugins promote info-stealer malware
StopAndProtect: How the chain of infection works
The technical infrastructure of StopAndProtect is impressively complex. Executing the PowerShell command triggers a three-stage chain. In Stage 1, a .NET downloader reports statistics to the C2 and loads the next stage. In Stage 2, a second .NET downloader and loader incorporates sandbox checks and additional logging mechanisms before launching the main components. Finally, Stage 3 includes six specialized tools that form the core of the attack.

The six components of Stage 3 are: SilentEncryptor, which encrypts files on infected systems or on specific hostnames; NetworkShareScanner, which acts as an SMB/USB worm to spread to other devices; VBS spreader, which spreads malware to hard drives and removable media via WMI; LockScreen, which blocks user login and displays a ransom message with a QR code for payment; SimpleChatProxy, a custom chat application for communication between the victim and the attacker; and finally SilentDataCollector, which creates a list of all drives, encrypts it and exports it to the C2 server, while it can receive commands to collect specific files.
The compromised WordPress sites perform multiple functions in the enterprise infrastructure: they act as command-and-control (C2) servers for sending commands, host malicious payloads , and store stolen logs, screenshots, and documents. Check Point Research estimates that nearly 2,000 WordPress sites have been compromised in this campaign, with most running outdated versions of WordPress and installed plugins. One of the compromised sites, for example, was running a version of WordPress from 2021, which made it vulnerable to about 40 different vulnerabilities.
StopAndProtect: The OPSEC mistakes that revealed the scale of the attack
One of the most notable elements of the case is that Check Point Research was able to obtain detailed information about the campaign thanks to serious OPSEC (operational security) errors by the attackers. These errors exposed detailed infection logs, screenshots from victim machines, source code, and lists of compromised domains. The data revealed more than 6,000 victim IP addresses, approximately 31,000 screenshots , and over 700 data files, indicating an operation of enormous scale.
See also: Gravity SMTP: Critical vulnerability in 100,000 WordPress sites
Operation StopAndProtect is not an isolated incident. In July 2026, another campaign attributed to the TA2726 compromised 1,509 WordPress sites to distribute SocGholish, demonstrating that abusing compromised CMS sites remains a popular and effective method for cybercriminals. Meanwhile, reports of exploits in WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 — including CVE-2026-60137 and CVE-2026-63030 — indicate that WordPress exploitation continued throughout the same period.
The attackers’ strategy of using multiple compromised sites as infrastructure reflects a deliberate choice for resilience: if one node is taken down, the others continue to operate. This distributed architecture makes it particularly difficult for authorities and security researchers to combat the threat. According to The Hacker News, the operation combines ransomware, data theft , and manual auditing, making it particularly dangerous.

How to protect yourself from StopAndProtect and similar threats
For WordPress site owners , the first line of defense is to regularly update your core, plugins, and themes . The compromised sites in the StopAndProtect campaign were running old, outdated versions, making them easy targets. Additionally, it is recommended to remove unused plugins and themes , use strong passwords for administrator accounts, and enable MFA (Multi-Factor Authentication) for all privileged accounts.
Site owners should also watch for unauthorized file changes, suspicious creation of administrator accounts, unexpected CAPTCHA prompts or copy-and-paste prompts , and outbound traffic to unknown hosts . For end users, the golden rule is to never execute commands copied from web pages , especially PowerShell commands that present themselves as CAPTCHA verification.
See also: Forminator Forms: Critical vulnerability affects WordPress sites
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the endpoint security level, organizations should configure controls that block or alert for suspicious PowerShell execution, coded commands, unusual .NET processes, and script-based loaders. If a breach is suspected, the safest response is to isolate the system, maintain logs, change credentials, and restore from clean sources. For WordPress owners, this means verifying the integrity of core files, reinstalling plugins and themes from trusted sources, and restoring only from backups that predate the breach.
Operation StopAndProtect is a striking example of the evolution of modern cyberattacks: they are no longer simple ransomware attacks, but complex, multi-layered operations that combine social engineering, data theft, network propagation, and manual control. Understanding this complexity is the first step to effectively countering it.
