Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

    Date: 08/20/2026

    Severity: High

    Summary

    The StopAndProtect campaign is a multi-stage malware operation that begins with ClickFix social engineering, leading to PowerShell, .NET payloads and the deployment of ransomware, SMB/USB worm, credential stealer, VBS spreader, and LockScreen components. The operators exploited nearly 2,000 vulnerable WordPress sites for malware hosting, C2 infrastructure, and victim log exfiltration, while exposed directories revealed extensive campaign infrastructure. The operation also performs telemetry collection, file exfiltration, and large-scale WordPress abuse, highlighting the risks of unpatched CMS environments.

    Indicators of Compromise (IOC) List

    Domains/Urls

    maximumrock.ro

    platinumcar.ca

    norakremer.co.uk

    pharmart.ae

    ksr-racingparts.com

    v-k.com.ua

    www.lapellelaser.pl

    www.parsrulman.com

    mectcalcutta.com

    discherniation.com

    Hash

    cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0

    cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9

    99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b

    8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5

    4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504

    9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527

    7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c

    976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153

    b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489

    65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143

    0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40

    8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4

    10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0

    f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41

    11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e

    2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c

    38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9

    23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70

    b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad

    3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9

    3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "norakremer.co.uk" or url like "norakremer.co.uk" or siteurl like "norakremer.co.uk" or domainname like "platinumcar.ca" or url like "platinumcar.ca" or siteurl like "platinumcar.ca" or domainname like "ksr-racingparts.com" or url like "ksr-racingparts.com" or siteurl like "ksr-racingparts.com" or domainname like "www.parsrulman.com" or url like "www.parsrulman.com" or siteurl like "www.parsrulman.com" or domainname like "pharmart.ae" or url like "pharmart.ae" or siteurl like "pharmart.ae" or domainname like "discherniation.com" or url like "discherniation.com" or siteurl like "discherniation.com" or domainname like "v-k.com.ua" or url like "v-k.com.ua" or siteurl like "v-k.com.ua" or domainname like "mectcalcutta.com" or url like "mectcalcutta.com" or siteurl like "mectcalcutta.com" or domainname like "www.lapellelaser.pl" or url like "www.lapellelaser.pl" or siteurl like "www.lapellelaser.pl" or domainname like "maximumrock.ro" or url like "maximumrock.ro" or siteurl like "maximumrock.ro"

    Detection Query 2 :

    sha256hash IN ("38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9","99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b","3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9","2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c","cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0","3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8","23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70","65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143","976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153","f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41","9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527","11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e","b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad","8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4","8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5","0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40","4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504","cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9","10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0","b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489","7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c")

    Reference: 

    https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/         


    Tags

    MalwareVulnerabilityExploitClickFixRansomwareStealerCredential HarvestingSocial EngineeringPowerShell Attack.NET PayloadsWormExfiltrationWordPress

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags