Last seven days
- First activity
- Aug 19, 2026
- Last activity
- Aug 20, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 17 hostnames
StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction.
Profile source: Mallory opens in a new tabStopAndProtect
StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction. The operation relies heavily on large numbers of compromised WordPress websites, which are repurposed as distributed infrastructure for malware delivery, command-and-control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure that tricks users into executing a PowerShell command, after which staged PowerShell and .NET downloader/loader components deploy the main payloads.
Observed payloads include SilentEncryptor, the ransomware component; SilentDataCollector, a stealer focused on file inventorying and selective exfiltration; NetworkShareScanner, which propagates via SMB shares and removable media; a VBS-based spreader that also supports WMI-driven lateral movement; a lock-screen module; and a custom chat utility used for operator-victim communication. Newer stealer variants have been observed with keylogging, screenshot capture, network-share mapping, and WhatsApp-focused collection features. The operation does not always culminate in encryption; in many cases it appears to prioritize reconnaissance and theft of file listings and selected files before, or instead of, ransomware deployment.
The campaign targets Windows systems and has affected victims globally, with notable concentrations observed in the United States, Russia, and India. Operational security failures exposed internal logs, screenshots, stolen-data archives, and tooling used to manage the compromised WordPress infrastructure, indicating a broad, actively managed criminal ecosystem rather than isolated ransomware incidents. The abuse of outdated and vulnerable WordPress installations, along with malicious plugins and must-use plugins for persistence and arbitrary file upload, is a defining feature of the operationโs infrastructure strategy.
MITRE ATT&CK
Reporting
Check Point Research uncovered StopAndProtect, a large-scale cybercrime operation that used compromised WordPress sites to host malware, provide command-and-control, and store stolen data. The campaign began with a ClickFix fake CAPTCHA lure that tricked victims into launching PowerShell, then deployed multiple .NET loader stages that installed a broad toolset including SilentEncryptor ransomware, the SilentDataCollector stealer, an SMB/USB worm, a VBS spreader, a lock-screen module, a credential stealer, and a custom chat utility for interacting with victims. Researchers said the operators made significant OPSEC mistakes that exposed their infrastructure, including open PHP directory listings, accessible log and screenshot folders, and archived files that appeared to show the actors had infected themselves. Those leaks revealed source code and operational files used to mass-manage compromised WordPress domains. Monitoring from mid-May through late July 2026 found more than 700 stolen-data archives and about 31,000 victim screenshots, while internal logs and exposed systems indicated the campaign hit thousands of IP addresses worldwide, with the highest concentrations in the United States, Russia, and India.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.