Executive Summary
The StopAndProtect campaign, identified in May 2026, represents a large-scale cybercrime operation leveraging thousands of vulnerable WordPress websites as command-and-control (C2) and storage infrastructure. The threat actors exploit outdated WordPress versions and plugins to host malicious payloads and exfiltrate victim data, including screenshots and sensitive documents. The campaign primarily impacts users in the United States, Russia, and India, utilizing a 'ClickFix' social engineering technique to trick victims into executing malicious PowerShell commands.
The attack chain involves multiple stages of .NET loaders that ultimately deploy a diverse functional toolkit. This toolkit includes ransomware (SilentEncryptor), data stealers (SilentDataCollector), and lateral movement tools such as SMB/USB worms. Notably, the operation features a custom chat interface for direct communication between attackers and victims. Significant operational security (OPSEC) failures by the attackers, including exposed directory listings on compromised servers, have allowed researchers to recover source code for their management tools and infection logs covering thousands of victims.
This campaign poses a significant risk to organizations due to its dual-threat nature of encryption and silent data exfiltration. The use of legitimate but compromised web infrastructure for hosting and C2 makes detection more challenging for standard reputation-based filters. Organizations should prioritize patching web-facing WordPress instances and monitoring for anomalous PowerShell execution patterns.
Key Details
Threat Name
StopAndProtect
Affects
—
Adversary
StopAndProtect
MITRE Techniques
Malware/Tools
StopAndProtect, SilentEncryptor, SilentDataCollector, NetworkShareScanner, VBS spreader, LockScreen, SimpleChatProxy, Adwind, WannaCry
