TL;DR:
- The criminal group StopAndProtect used nearly 2,000 compromised WordPress blogs to distribute malware that steals crypto wallet seeds.
- The attack tricks Windows users with fake CAPTCHA pages that prompt them to run malicious PowerShell commands on their devices.
- Between May and July, the campaign infected more than 6,000 unique IP addresses and collected over 700 stolen data files from victims.
A criminal group identified by Check Point Research as StopAndProtect used nearly 2,000 poorly maintained WordPress sites to distribute Malware capable of stealing seeds from wallets, passwords and files from Windows computers. The details were published on August 18, after linking a ransomware sample detected in mid-May to an extortion and surveillance campaign.
What sets this operation apart from similar ones is the infrastructure used. Rather than renting or compromising their own servers, the attackers turned legitimate WordPress domains into platforms to host payloads, redirect instructions to malware-infected devices and store stolen files. Researcher JaromÃr HoÅ™ejšànoted that a single server can fulfill all those functions simultaneously, without the criminals spending a single cent.
How the Malware Operates on WordPress
The malware’s propagation tactic relies on fake CAPTCHA pages. Users believe they must complete a verification to access a site, but are actually instructed to copy and paste a PowerShell command into their terminal. That command downloads .NET payloads that allow attackers to extract saved passwords, wallet seeds and other sensitive data from the compromised device.
The most recent versions of the malware go further: they log keystrokes, capture screenshots every 30 seconds, copy files from shared folders and USB drives, and even encrypt the device to demand payment as ransomware. Users should immediately leave any site that asks them to paste or type commands into their system.
The Attackers’ Own Mistakes
The most valuable intelligence about the campaign came from the attackers’ own servers. Directories and log files were left exposed on the web due to poor security practices, and Check Point suspects that one of the criminals’ devices was compromised, leading to the accidental leak of internal files.
Among those files, Hořejšà found the source code of an automation tool written in Visual Basic 6 that allowed attackers to remotely control the hacked sites. As of July 24, the malware had already infected more than 6,000 unique IP addresses, with 1,852 victims in the United States and 630 in Russia and India respectively. More than 20,000 screenshots from compromised devices were found in one of the open directories.






