StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

CyberNews.work Exclusive: Malware Campaign Utilizes Compromised WordPress Sites to Spread Malware and Steal Data

A sophisticated malware campaign has been discovered using nearly 2,000 hacked WordPress sites to spread malicious code and steal sensitive data from unsuspecting users. Dubbed “StopAndProtect,” this operation demonstrates the ongoing threat of compromised web applications serving as a conduit for cyberattacks.

The StopAndProtect campaign leverages the power of cross-domain privilege escalation, which allows attackers to bypass security measures by exploiting vulnerabilities in web application architecture. By creating a network of hacked WordPress sites, the attackers can establish a chain of command over these compromised domains, enabling them to spread malware and access sensitive data across different websites.

The compromised WordPress sites are being used as a springboard for various types of attacks, including drive-by downloads and phishing campaigns. These malicious activities allow the attackers to inject malware into victims’ systems, thereby compromising their security and creating an entry point for further exploitation. Furthermore, the campaign is also involved in stealing sensitive information from users, which can be sold on the dark web or used for identity theft.

What’s particularly concerning about this campaign is its ability to adapt and evolve. The attackers are continually updating their tactics to stay ahead of security measures, making it challenging for defenders to keep pace. This highlights the need for robust cybersecurity strategies that can detect and respond to emerging threats in a timely manner.

The impact of StopAndProtect extends beyond individual users; compromised WordPress sites can also have far-reaching consequences for businesses and organizations with online presence. As attackers continue to exploit vulnerabilities in web applications, it’s essential for website owners to prioritize security measures, such as regular updates, secure login mechanisms, and robust firewall configurations.

To mitigate the risks associated with StopAndProtect, it’s crucial for users to remain vigilant when interacting with compromised websites. One practical takeaway is to always verify the authenticity of a site before sharing sensitive information or downloading files. Furthermore, website owners should prioritize security best practices, including regular software updates, secure passwords, and robust access controls.

Ultimately, the StopAndProtect campaign serves as a reminder of the ongoing threat posed by compromised web applications. By staying informed about emerging threats and prioritizing cybersecurity measures, individuals and organizations can reduce their exposure to these types of attacks and maintain a more secure online presence.


Source: The Hacker News — 2026-08-19