Interestana
Home/News/StopAndProtect Abuses 2,000 Hacked WordPress Sites for Malware
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

StopAndProtect Abuses 2,000 Hacked WordPress Sites for Malware

StopAndProtect Abuses 2,000 Hacked WordPress Sites for Malware

Cybersecurity researchers have identified a large-scale global cybercrime operation, dubbed StopAndProtect, that is leveraging nearly 2,000 compromised WordPress websites as its primary infrastructure. This operation is designed to disseminate malware, commandeer infected hosts, and serve as a repository for stolen sensitive information, including documents, screenshots, and activity logs. The researchers detailed their findings in a report published on March 19, 2024, highlighting the sophisticated and multi-faceted nature of the attack.

StopAndProtect's modus operandi involves a diverse toolkit of criminal software rather than a single malware strain. This approach allows the attackers to adapt their methods and evade detection more effectively. The compromised WordPress sites are not merely used for distribution; they also play a crucial role in hosting the stolen data. This includes sensitive documents, visual evidence in the form of screenshots, and detailed logs that track the progress and status of the operation. The sheer scale of compromised sites, numbering close to 2,000 globally, underscores the significant reach and potential impact of this cybercrime network.

The operation's infrastructure is built upon a foundation of exploited vulnerabilities within WordPress websites. These sites, once secured by their legitimate owners, have been taken over by the attackers. The researchers have not yet disclosed the specific vulnerabilities exploited or the exact methods used to gain initial access to these sites. However, the widespread use of WordPress, a popular content management system powering a significant portion of the internet, makes it a prime target for such large-scale abuse. The attackers are effectively turning legitimate online presences into tools for malicious activities, posing a substantial threat to both the website owners and their visitors.

The implications of StopAndProtect are far-reaching. For website owners, the compromise means a loss of control over their digital assets, potential damage to their reputation, and the risk of being associated with criminal activities. For users who may interact with these compromised sites, there is a risk of malware infection, data theft, and other forms of cyber exploitation. The operation's reliance on a broad spectrum of criminal software suggests a well-resourced and organized cybercriminal entity. The ongoing investigation aims to further understand the full scope of the operation, identify the perpetrators, and develop effective countermeasures to dismantle this network and prevent future attacks of this nature. The researchers are urging website administrators to ensure their WordPress installations and all associated plugins and themes are kept up-to-date to mitigate the risk of similar compromises.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next