A sprawling criminal operation hijacked nearly 2,000 WordPress sites and turned them into a malware distribution and data-theft pipeline that put crypto users squarely in the crosshairs, cybersecurity firm Check Point Research said in a report released Tuesday. What researchers found - The campaign centers on a ransomware family dubbed StopAndProtect, first identified in mid‑May, but Check Point’s analysis shows it’s part of a much larger toolkit of malicious software. Rather than a single strain, the operation uses multiple components that together steal data, monitor victims, encrypt files, and enable live interaction between attackers and targets. - Compromised WordPress sites hosted the malicious payloads, relayed commands to infected machines, and stored exfiltrated material — including documents, activity logs and screenshots. How the infection works - The infection chain begins on a compromised website with a fake CAPTCHA (branded “ClickFix”) that instructs visitors to run a PowerShell command. Executing that command installs malware that: - steals credentials and cryptocurrency wallet seed phrases and files, - spreads across networks and removable drives, - locks screens and deploys ransomware, - and acts as a backchannel for attackers to interact with victims. - Check Point says the malware targets Windows users; the report did not confirm macOS or Linux infection vectors for this campaign. (However, ClickFix-style social engineering has previously been used to trick macOS users into pasting malicious Terminal commands.) Scale and data exposed - Due to operational security lapses by the criminals, researchers were able to access source code, infection logs and hundreds of screenshots from victims’ machines. - By July 24 the campaign had touched more than 6,000 unique IP addresses worldwide — including 1,852 in the United States and 630 each in Russia and India. - Between mid‑May and the end of July, Check Point collected over 31,000 screenshots and more than 700 archives of stolen data containing documents, passwords and cryptocurrency wallet files. - In at least one instance the attackers appear to have infected themselves, producing unusual files that gave researchers extra visibility into the operation and its breadth. Context: ClickFix is not new - Variants of the ClickFix trick have popped up repeatedly this year: - In May, visitors to an apparel site tied to a public figure were reportedly prompted to paste a macOS Terminal command that installed an infostealer targeting browser data, session tokens and crypto wallets. - In July, Jamf Threat Labs observed a sponsored ad on X redirecting users to a page that pushed a ClickFix-style prompt and installed an Atomic infostealer variant. - In August, Microsoft warned of compromised sites and even BNB Chain smart contracts being used to serve fake CAPTCHAs that distribute malware. Why crypto users should care - The campaign explicitly targets wallet seed phrases, wallet files and other browser-stored credentials — assets that, once exfiltrated, are highly actionable for thieves. Because attackers used a mix of credential-stealing, lateral-spreading and ransomware components, victims face both immediate theft and broader network compromise. Takeaways - Be skeptical of prompts that ask you to run commands or paste code from websites. - Keep systems and browsers patched, and avoid downloading or executing code from untrusted pages. - Use hardware wallets or well-protected cold storage for large cryptocurrency holdings, and maintain offline backups of critical data. Check Point’s report sheds light on an operation that combined large-scale web compromise with social-engineering tricks to harvest highly sensitive data — underscoring that compromised websites and clever UX tricks remain potent vectors for crypto-targeting malware. Read more AI-generated news on: undefined/news