Skip to content

StopAndProtect

StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance.

Profile source: Mallory opens in a new tab

StopAndProtect

Family profile

StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance. The operation is notable for abusing large numbers of compromised WordPress websites as distributed infrastructure for malware hosting, command and control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure on hacked WordPress sites that tricks victims into executing a PowerShell command, leading to a staged infection chain involving PowerShell scripts and .NET downloaders and loaders.

The toolkit associated with StopAndProtect includes a ransomware component known as SilentEncryptor, a stealer known as SilentDataCollector, an SMB and USB propagation component, a VBS spreader, a lock-screen ransom module, and a custom chat utility for operator-victim interaction. Reported capabilities include targeted file inventory and exfiltration, credential theft, keylogging, screenshot capture, network share discovery and mapping, scraping of local communication data including WhatsApp-related information, and selective deployment of encryption. Available reporting indicates the operators often prioritize reconnaissance and theft before deciding whether to encrypt systems, and ransomware is not deployed against every victim.

The operation also leveraged malicious WordPress plugins and must-use plugins to maintain access to compromised sites and enable arbitrary file upload, supporting persistent reuse of hacked web infrastructure. Exposed operational data indicated global victimization, with particularly high concentrations observed in the United States, Russia, and India, and showed that the campaign targeted organizations worldwide rather than a single sector. StopAndProtect is best characterized as a modular double-extortion ransomware operation with substantial infostealing, surveillance, lateral movement, and hands-on-keyboard post-exploitation functionality.

Capabilities

  • Credential Theft
  • Exfiltration
  • Extortion
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 6, 2026
Feed role
Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • FR1
  • ZA1

Leading providers

  • Host Africa (Pty) Ltd1
  • Host Europe GmbH1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

StopAndProtect in ATT&CK

38 distinct techniques

Reporting

Research mentioning StopAndProtect

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.