Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
The StopAndProtect operation is a multi-component campaign combining ransomware and data theft. It uses a ClickFix social engineering technique to deliver .NET-based loaders, which deploy ransomware, an SMB/USB worm, a lockscreen, a credential stealer, and a chat utility. The actors abuse thousands of compromised WordPress sites as infrastructure for hosting malware, C2 communication, and storing exfiltrated victim data.
- domaindischerniation[.]comCompromised WordPress site used as a base C2 server.
- domainksr-racingparts[.]comCompromised WordPress website used in the StopAndProtect operation.
- domainmaximumrock[.]roCompromised WordPress website used in the StopAndProtect operation.
- domainmectcalcutta[.]comCompromised WordPress site used as a base C2 server.
- domainnorakremer[.]co[.]ukCompromised WordPress website used in the StopAndProtect operation.
- domainpharmart[.]aeCompromised WordPress website used in the StopAndProtect operation.
- domainplatinumcar[.]caCompromised WordPress website used in the StopAndProtect operation.
- domainv-k[.]com[.]uaCompromised WordPress site used as a base C2 server for the StopAndProtect operation.
- domainwww[.]lapellelaser[.]plCompromised WordPress site used as a base C2 server and screenshot exfiltration storage.
- domainwww[.]parsrulman[.]comCompromised WordPress site used as a base C2 server.
- emailstopandprotect[@]gmail[.]comContact email address listed on the StopAndProtect ransom page.
- filenamewp-content/mu-plugins/wp-sec.phpMalicious WordPress must-use (MU) plugin dropped by the backdoor installer for persistence and hidden file upload capabilities.
- filenamewp-content/plugins/verify/proxy.phpScript dropped by verify.php used to fetch remote log files.
- filenamewp-content/plugins/verify/stored_url.txtText file containing the base URL for the fake captcha or the keyword 'off' if disabled.
- filenamewp-content/plugins/verify/store.phpScript dropped by verify.php used to modify the stored_url.txt file to control payload traffic redirects.
- filenamewp-content/plugins/verify/verify.phpMalicious WordPress plugin responsible for displaying the fake CAPTCHA ClickFix prompt to non-Windows visitors.
- sha2560080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40SHA256 hash of the stage 3 encryptor component.
- sha25610babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0SHA256 hash of the stage 3 SMB/USB worm component.
- sha25611a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42eSHA256 hash of the stage 3 lockscreen component.
- sha25623cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70SHA256 hash of the stage 3 credential stealer component.
- sha2562adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68cSHA256 hash of the stage 3 lockscreen component.
- sha25638602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9SHA256 hash of the stage 3 lockscreen component.
- sha2563ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8SHA256 hash of the stage 3 chat utility component.
- sha2563ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9SHA256 hash of the stage 3 chat utility component.
- sha2564dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504SHA256 hash of the stage 1 .NET downloader.
- sha25665550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143SHA256 hash of the stage 3 encryptor component.
- sha2567d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20cSHA256 hash of the stage 2 .NET downloader and loader.
- sha2568337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5SHA256 hash of the stage 1 .NET downloader.
- sha2568d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4SHA256 hash of the stage 3 SMB/USB worm component.
- sha2569765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527SHA256 hash of the stage 2 .NET downloader and loader.
- sha256976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153SHA256 hash of the stage 2 .NET downloader and loader.
- sha25699bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940bSHA256 hash of the stage 1 .NET downloader.
- sha256b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08adSHA256 hash of the stage 3 VBS spreader component.
- sha256b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489SHA256 hash of the stage 3 encryptor component.
- sha256cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0SHA256 hash of the stage 1 PowerShell script.
- sha256cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9SHA256 hash of the stage 2 PowerShell script.
- sha256f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41SHA256 hash of the stage 3 SMB/USB worm component.
- urlhxxps://www[.]lapellelaser[.]pl/display/DESK-PA2NWB75NQ_startup[.]pngURL on a compromised WordPress site storing an exfiltrated victim startup screenshot.
Detection / Hunteropenrouter
What Happened
A criminal operation called StopAndProtect is combining file encryption with data theft. The attackers trick people into running malicious code by showing fake CAPTCHA verification prompts on compromised websites. Once infected, the malware can lock the victim's screen, encrypt files, steal documents and passwords, and spread to other computers via USB drives and network shares. The criminals are using thousands of hacked WordPress websites to manage their operation and store stolen data. Security researchers discovered the operation's scale due to mistakes made by the attackers, who accidentally exposed their own tools and logs. People should be cautious of unexpected verification prompts on websites and ensure their systems and backups are up to date.
Key Takeaways
- The StopAndProtect operation uses a multi-stage infection chain starting with a ClickFix social engineering prompt that delivers .NET-based ransomware, stealers, and worm components.
- Threat actors compromised thousands of WordPress sites to use as C2 infrastructure, malware hosting, and storage for exfiltrated victim data including screenshots and documents.
- Operational security failures by the threat actor exposed source code, internal logs, and a Visual Basic 6 automation tool used for mass-managing compromised WordPress sites.
- The SilentDataCollector stealer component exfiltrates file lists, documents, wallet files, and password files. It also includes keylogging and WhatsApp contact exfiltration capabilities.
- The ransomware component uses per-file passwords and machine names for key derivation, embedding these values in the encrypted file names to enable decryption.
Affected Systems
- Windows operating systems
- WordPress websites with outdated core versions and plugins
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim visits a compromised WordPress site and encounters a fake CAPTCHA ClickFix prompt.
- Execution: The ClickFix prompt tricks the victim into executing a PowerShell command that downloads and runs additional stages.
- Defense Evasion: The .NET stage 1 and stage 2 loaders use reflection to load components into memory and include sandbox checks.
- Discovery: The SilentDataCollector component enumerates all files on fixed, removable, and network drives.
- Lateral Movement: The NetworkShareScanner and VBS spreader components propagate to USB devices and network shares via WMI.
- Impact: The SilentEncryptor ransomware encrypts files and the LockScreen component blocks user input while displaying a ransom message.
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Check Point Research
A YARA rule is provided in the article to detect the StopAndProtect operation based on a specific path string.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR solutions can detect the initial PowerShell execution and subsequent .NET assembly loading in memory. However, the malware's use of sandbox checks and in-memory loading may evade some signature-based detections. |
| Network Visibility | High | The malware communicates with compromised WordPress sites over HTTP/HTTPS for C2, file downloads, and data exfiltration. Network monitoring can detect these connections to known malicious domains and unusual data uploads. |
| Detection Difficulty | Moderate | Detection is feasible due to the malware's reliance on known compromised domains and distinct PowerShell execution patterns. However, the multi-stage .NET loading and use of legitimate WordPress infrastructure for C2 require correlation across network and endpoint telemetry. |
Required Log Sources
- PowerShell Script Block Logging (Event ID 4104)
- Process Creation (Windows Event ID 4688 / Sysmon Event ID 1)
- DNS resolution logs
- Web proxy logs
- WordPress access logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for PowerShell processes initiating network connections to external domains shortly after process creation, particularly those downloading content via Net.WebClient. | PowerShell Script Block Logging, Sysmon Event ID 1 (Process Creation) and Event ID 3 (Network Connection) | Execution | Medium - Legitimate administrative scripts may use similar patterns. |
| If you have web proxy logs, consider hunting for POST requests to /wp-json/wp-sec/v1/upload or similar paths on WordPress sites, which may indicate the malicious MU plugin activity. | Web proxy logs, firewall logs | C2 | Low - The specific REST API endpoint and path are highly indicative of the malicious plugin. |
| Consider hunting for processes interacting with USB removable media or network shares that subsequently execute files or scripts, indicating worm propagation activity. | Sysmon Event ID 1, Event ID 8 (Remote Thread Creation), Event ID 11 (File Creation) | Lateral Movement | Medium - Legitimate software deployment tools may exhibit similar behavior. |
| If you have endpoint visibility, consider hunting for processes taking screenshots at regular intervals (e.g., 30 seconds) and compressing or encrypting the output, which aligns with the SilentDataCollector stealer. | EDR process monitoring, Sysmon Event ID 1, Event ID 11 | Collection | Low - Regular interval screenshot capture is uncommon in legitimate software. |
Control Gaps
- Signature-based antivirus may miss the fileless .NET loaders executed in memory via PowerShell.
- Network controls may not block C2 traffic if it blends with legitimate HTTPS traffic to WordPress domains.
- Endpoint controls may not detect the creation of malicious MU plugins if they do not monitor WordPress-specific file paths.
Key Behavioral Indicators
- PowerShell process executing with '-w hidden -ep bypass' flags and downloading content via Net.WebClient.
- Creation of files in wp-content/mu-plugins/ or wp-content/plugins/verify/ on WordPress servers.
- Network connections to known compromised WordPress domains hosting C2 endpoints like /dwnen.php or /wreport.php.
- Processes creating archives with naming conventions like <computer name>documents<number>.zip or <computer name>screenshot_V<version><yyyymmdd>_<hhmmss>.zip.encrypted.
False Positive Assessment
Medium - The use of PowerShell and legitimate WordPress infrastructure for C2 may generate false positives if not correlated with other indicators. However, specific file paths, REST API endpoints, and archive naming conventions provide high-fidelity detection opportunities.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified compromised WordPress domains and C2 server domains at your firewall or web proxy.
- If your EDR supports it, consider isolating and investigating any endpoints that have communicated with the identified C2 domains or downloaded files with the listed SHA256 hashes.
- Consider reviewing web server logs for the presence of files like wp-sec.php, verify.php, or wp-uploading.php, which may indicate a compromised WordPress site.
Infrastructure Hardening
- Evaluate whether your WordPress sites are running the latest core and plugin versions. Consider implementing automatic updates where supported.
- Consider implementing file integrity monitoring (FIM) on WordPress installations, particularly for the wp-content/mu-plugins/ and wp-content/plugins/ directories.
- If applicable, consider restricting PHP execution in directories where it is not required, such as wp-content/uploads/.
User Protection
- Consider deploying endpoint protection that can detect and block fileless PowerShell execution and in-memory .NET assembly loading.
- If supported by your EDR, consider enabling network containment features to prevent lateral movement via SMB and USB devices.
- Consider blocking the identified Bitcoin address and Telegram handle in communications if your organization monitors for extortion attempts.
Security Awareness
- Consider incorporating warnings about fake CAPTCHA or 'ClickFix' social engineering techniques into existing security awareness programs.
- Remind users to be cautious of websites prompting them to press Windows + R and paste commands into the Run dialog.
- Consider advising users to verify the legitimacy of unexpected verification prompts, especially on sites that do not typically require such checks.
MITRE ATT&CK Mapping
Stealth
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Additional IOCs
- Domains:
maximumrock[.]ro- Compromised WordPress website used in the StopAndProtect operation.platinumcar[.]ca- Compromised WordPress website used in the StopAndProtect operation.norakremer[.]co[.]uk- Compromised WordPress website used in the StopAndProtect operation.pharmart[.]ae- Compromised WordPress website used in the StopAndProtect operation.ksr-racingparts[.]com- Compromised WordPress website used in the StopAndProtect operation.
- Urls:
hxxps://www[.]lapellelaser[.]pl/display/DESK-PA2NWB75NQ_startup.png- URL on a compromised WordPress site storing an exfiltrated victim startup screenshot.
- File Hashes:
99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b(SHA256) - SHA256 hash of the stage 1 .NET downloader.8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5(SHA256) - SHA256 hash of the stage 1 .NET downloader.4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504(SHA256) - SHA256 hash of the stage 1 .NET downloader.9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527(SHA256) - SHA256 hash of the stage 2 .NET downloader and loader.7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c(SHA256) - SHA256 hash of the stage 2 .NET downloader and loader.976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153(SHA256) - SHA256 hash of the stage 2 .NET downloader and loader.b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489(SHA256) - SHA256 hash of the stage 3 encryptor component.65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143(SHA256) - SHA256 hash of the stage 3 encryptor component.0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40(SHA256) - SHA256 hash of the stage 3 encryptor component.8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4(SHA256) - SHA256 hash of the stage 3 SMB/USB worm component.10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0(SHA256) - SHA256 hash of the stage 3 SMB/USB worm component.f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41(SHA256) - SHA256 hash of the stage 3 SMB/USB worm component.11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e(SHA256) - SHA256 hash of the stage 3 lockscreen component.2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c(SHA256) - SHA256 hash of the stage 3 lockscreen component.38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9(SHA256) - SHA256 hash of the stage 3 lockscreen component.b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad(SHA256) - SHA256 hash of the stage 3 VBS spreader component.3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9(SHA256) - SHA256 hash of the stage 3 chat utility component.3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8(SHA256) - SHA256 hash of the stage 3 chat utility component.
- File Paths:
wp-content/mu-plugins/wp-sec.php- Malicious WordPress must-use (MU) plugin dropped by the backdoor installer for persistence and hidden file upload capabilities.wp-content/plugins/verify/verify.php- Malicious WordPress plugin responsible for displaying the fake CAPTCHA ClickFix prompt to non-Windows visitors.wp-content/plugins/verify/store.php- Script dropped by verify.php used to modify the stored_url.txt file to control payload traffic redirects.wp-content/plugins/verify/proxy.php- Script dropped by verify.php used to fetch remote log files.wp-content/plugins/verify/stored_url.txt- Text file containing the base URL for the fake captcha or the keyword 'off' if disabled.
- Command Lines:
- Purpose: Download and execute the second stage PowerShell script from a compromised WordPress site. | Tools:
powershell.exe| Stage: Initial Access / Execution
- Purpose: Download and execute the second stage PowerShell script from a compromised WordPress site. | Tools:
- Other:
wp-sec/v1/upload- Hidden REST API endpoint created by the malicious MU plugin, allowing authenticated file uploads to arbitrary paths under the WordPress root.@StopAndProtect- Telegram contact handle listed on the StopAndProtect ransom page.