Interestana
Home/News/Nearly 2,000 Hacked WordPress Sites Used for Criminal Infrastructure
Decrypt3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Nearly 2,000 Hacked WordPress Sites Used for Criminal Infrastructure

Nearly 2,000 Hacked WordPress Sites Used for Criminal Infrastructure

The StopAndProtect operation, identified by security researchers, has revealed a significant cybercrime campaign that repurposed nearly 2,000 compromised WordPress websites into a distributed criminal infrastructure. These hacked sites were not merely defaced but actively utilized to facilitate a range of malicious activities, including the distribution of malware, the theft of cryptocurrency wallet files, and the deployment of ransomware attacks. The operation highlights a sophisticated method of leveraging widely used content management systems for illicit purposes, underscoring the persistent vulnerabilities within web infrastructure.

Researchers from the cybersecurity firm StopAndProtect detailed in a recent analysis that the compromised WordPress installations served as command-and-control servers and distribution points for various malware strains. Attackers exploited these sites to host malicious code, which was then delivered to unsuspecting users who visited the compromised websites. This technique allowed the cybercriminals to maintain a persistent presence and control over their malicious operations, making them harder to track and dismantle. The scale of the operation, affecting close to 2,000 distinct websites, suggests a well-organized and resourced threat actor group.

One of the primary objectives of the StopAndProtect operation was the exfiltration of sensitive data, particularly cryptocurrency wallet files. These files often contain the private keys necessary to access and control digital assets, making them a high-value target for cybercriminals. By compromising WordPress sites that may have been linked to e-commerce or other online services, attackers could potentially gain access to user data or direct users to phishing pages designed to steal credentials. The deployment of ransomware was another key component, where encrypted files on victim systems were held hostage until a ransom payment was made, typically in cryptocurrency to obscure the transaction trail.

The widespread use of WordPress, which powers a substantial portion of the internet's websites, makes it an attractive target for cybercriminals. Its vast ecosystem of plugins and themes, while offering flexibility, can also introduce security vulnerabilities if not properly managed and updated. The StopAndProtect operation serves as a stark reminder of the ongoing threats posed by sophisticated cyberattacks and the critical importance of robust cybersecurity measures for website owners, including regular software updates, strong password policies, and the use of reputable security plugins. The impact of such operations extends beyond the immediate victims, potentially eroding trust in online platforms and services.

Original source — read the full reporting at the publisher:

Read on Decrypt

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next