Skip to content

StopAndProtect

StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction.

Profile source: Mallory opens in a new tab

StopAndProtect

Family profile

StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction. The operation relies heavily on large numbers of compromised WordPress websites, which are repurposed as distributed infrastructure for malware delivery, command-and-control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure that tricks users into executing a PowerShell command, after which staged PowerShell and .NET downloader/loader components deploy the main payloads.

Observed payloads include SilentEncryptor, the ransomware component; SilentDataCollector, a stealer focused on file inventorying and selective exfiltration; NetworkShareScanner, which propagates via SMB shares and removable media; a VBS-based spreader that also supports WMI-driven lateral movement; a lock-screen module; and a custom chat utility used for operator-victim communication. Newer stealer variants have been observed with keylogging, screenshot capture, network-share mapping, and WhatsApp-focused collection features. The operation does not always culminate in encryption; in many cases it appears to prioritize reconnaissance and theft of file listings and selected files before, or instead of, ransomware deployment.

The campaign targets Windows systems and has affected victims globally, with notable concentrations observed in the United States, Russia, and India. Operational security failures exposed internal logs, screenshots, stolen-data archives, and tooling used to manage the compromised WordPress infrastructure, indicating a broad, actively managed criminal ecosystem rather than isolated ransomware incidents. The abuse of outdated and vulnerable WordPress installations, along with malicious plugins and must-use plugins for persistence and arbitrary file upload, is a defining feature of the operationโ€™s infrastructure strategy.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Observed infrastructure

Last seven days

First activity
Aug 19, 2026
Last activity
Aug 20, 2026
Feed role
Distribution
Host form
0 IP / 17 hostnames

Leading locations

  • TR4
  • FR2
  • US2
  • BD1
  • DE1
  • ES1
  • FI1
  • ID1
  • IR1
  • SG1
  • SK1
  • VN1

Leading providers

  • OVH SAS3
  • Hetzner Online GmbH2
  • Cloudflare, Inc.1
  • DinaHosting S.L.1
  • DLITS1
  • FranTech Solutions1

Infrastructure traits

  • Hosting 16
  • Anycast 1

MITRE ATT&CK

StopAndProtect in ATT&CK

30 distinct techniques

Reporting

Research mentioning StopAndProtect

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.