Last seven days
- First activity
- Sep 30, 2026
- Last activity
- Sep 30, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance.
Profile source: Mallory opens in a new tabStopAndProtect
StopAndProtect is a multi-component cybercrime malware operation first identified in May 2026 that combines ransomware with covert data theft and post-compromise surveillance. The operation is notable for abusing large numbers of compromised WordPress websites as distributed infrastructure for malware hosting, command and control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure on hacked WordPress sites that tricks victims into executing a PowerShell command, leading to a staged infection chain involving PowerShell scripts and .NET downloaders and loaders.
The toolkit associated with StopAndProtect includes a ransomware component known as SilentEncryptor, a stealer known as SilentDataCollector, an SMB and USB propagation component, a VBS spreader, a lock-screen ransom module, and a custom chat utility for operator-victim interaction. Reported capabilities include targeted file inventory and exfiltration, credential theft, keylogging, screenshot capture, network share discovery and mapping, scraping of local communication data including WhatsApp-related information, and selective deployment of encryption. Available reporting indicates the operators often prioritize reconnaissance and theft before deciding whether to encrypt systems, and ransomware is not deployed against every victim.
The operation also leveraged malicious WordPress plugins and must-use plugins to maintain access to compromised sites and enable arbitrary file upload, supporting persistent reuse of hacked web infrastructure. Exposed operational data indicated global victimization, with particularly high concentrations observed in the United States, Russia, and India, and showed that the campaign targeted organizations worldwide rather than a single sector. StopAndProtect is best characterized as a modular double-extortion ransomware operation with substantial infostealing, surveillance, lateral movement, and hands-on-keyboard post-exploitation functionality.
Samples
MITRE ATT&CK
Reporting
Check Point Research uncovered StopAndProtect, a large-scale cybercrime operation that used compromised WordPress sites to host malware, provide command-and-control, and store stolen data. The campaign began with a ClickFix fake CAPTCHA lure that tricked victims into launching PowerShell, then deployed multiple .NET loader stages that installed a broad toolset including SilentEncryptor ransomware, the SilentDataCollector stealer, an SMB/USB worm, a VBS spreader, a lock-screen module, a credential stealer, and a custom chat utility for interacting with victims. Researchers said the operators made significant OPSEC mistakes that exposed their infrastructure, including open PHP directory listings, accessible log and screenshot folders, and archived files that appeared to show the actors had infected themselves. Those leaks revealed source code and operational files used to mass-manage compromised WordPress domains. Monitoring from mid-May through late July 2026 found more than 700 stolen-data archives and about 31,000 victim screenshots, while internal logs and exposed systems indicated the campaign hit thousands of IP addresses worldwide, with the highest concentrations in the United States, Russia, and India.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.