Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 6, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 2 hostnames
StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance.
Profile source: Mallory opens in a new tabStopAndProtect
StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance. The operation is notable for abusing large numbers of compromised WordPress websites as distributed infrastructure for malware hosting, command and control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure on hacked WordPress sites that tricks victims into executing a PowerShell command, leading to a staged infection chain involving PowerShell scripts and .NET downloaders and loaders.
The toolkit associated with StopAndProtect includes a ransomware component known as SilentEncryptor, a stealer known as SilentDataCollector, an SMB and USB propagation component, a VBS spreader, a lock-screen ransom module, and a custom chat utility for operator-victim interaction. Reported capabilities include targeted file inventory and exfiltration, credential theft, keylogging, screenshot capture, network share discovery and mapping, scraping of local communication data including WhatsApp-related information, and selective deployment of encryption. Available reporting indicates the operators often prioritize reconnaissance and theft before deciding whether to encrypt systems, and ransomware is not deployed against every victim.
The operation also leveraged malicious WordPress plugins and must-use plugins to maintain access to compromised sites and enable arbitrary file upload, supporting persistent reuse of hacked web infrastructure. Exposed operational data indicated global victimization, with particularly high concentrations observed in the United States, Russia, and India, and showed that the campaign targeted organizations worldwide rather than a single sector. StopAndProtect is best characterized as a modular double-extortion ransomware operation with substantial infostealing, surveillance, lateral movement, and hands-on-keyboard post-exploitation functionality.
Samples
364c90811975d02d9fc340582fe8b56654bb9721b095fae8190a62dd3c5741af 69e9290ffe87e5a9b61dfc40a1918c3600e19616f20554d265b2d3c08d505a3c 2f5812664258558da251ea88b19c00f9bfb59a71f10478e8056a26d0b923b872 6a867d8cec1e6b52c4023642f05b47fd7fb69a442443e578ba8a113303c4063b 8a8fea4d644d6b5e776d65c545c1d8e3bb5c427e74020d458690e6de1c93e256 d27ec23a769e02e66fc3a3fffb66b35fd643e605a05bd9d6155fa03bc976b5e6 MITRE ATT&CK
Reporting
Check Point Research uncovered StopAndProtect, a large-scale cybercrime operation that used compromised WordPress sites to host malware, provide command-and-control, and store stolen data. The campaign began with a ClickFix fake CAPTCHA lure that tricked victims into launching PowerShell, then deployed multiple .NET loader stages that installed a broad toolset including SilentEncryptor ransomware, the SilentDataCollector stealer, an SMB/USB worm, a VBS spreader, a lock-screen module, a credential stealer, and a custom chat utility for interacting with victims. Researchers said the operators made significant OPSEC mistakes that exposed their infrastructure, including open PHP directory listings, accessible log and screenshot folders, and archived files that appeared to show the actors had infected themselves. Those leaks revealed source code and operational files used to mass-manage compromised WordPress domains. Monitoring from mid-May through late July 2026 found more than 700 stolen-data archives and about 31,000 victim screenshots, while internal logs and exposed systems indicated the campaign hit thousands of IP addresses worldwide, with the highest concentrations in the United States, Russia, and India.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.