StopAndProtect Hijacks Nearly 2,000 WordPress Sites for Crypto Theft
WordPress powers a large share of the web, but its broad ecosystem of plugins and themes can leave poorly maintained sites exposed to known flaws. The campaign dubbed StopAndProtect is significant because it turns legitimate websites into distributed criminal infrastructure, giving attackers trusted domains from which to deliver malware and pursue cryptocurrency assets while making malicious activity harder for users and security filters to identify.
Investigators found that StopAndProtect compromised nearly 2,000 WordPress sites and repurposed them to distribute malware, deploy ransomware and steal cryptocurrency wallet files from victims. The operation extends the impact beyond the original website owners: each breached site can serve as a launch point for additional attacks against visitors, widening the potential pool of victims and raising the risk of both data loss and irreversible theft of digital assets.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →