2026-08-19NOTABLERoughly 2,000 hijacked sites are the infrastructure, not the victims, and the persistence lives where nobody looks
StopAndProtect
campaign · campaign:stopandprotect single-source
Criminal toolkit operation first observed by Check Point Research in mid-May 2026 that hosts its payload delivery, command-and-control and stolen-data collection on compromised WordPress sites rather than on dedicated infrastructure, with close to 2,000 hijacked domains listed in the operators' own tracking files. Persistence on each site is a must-use plugin written to wp-content/mu-plugins/wp-sec.php (auto-loaded on every request and absent from the standard plugin list) registering a hidden REST route authenticated by hardcoded credentials that writes files, including PHP, almost anywhere under the site root, after which the installer deactivates and self-deletes. Delivery is a fake-CAPTCHA paste-and-run lure leading through two PowerShell and two .NET in-memory loader stages to a component set covering file encryption, an SMB/USB worm, a script spreader, a lock screen, a credential and screenshot collector and an operator chat utility. Check Point states no initial WordPress compromise vector, names no actor, and asserts no lineage to any previously tracked operation (Check Point Research, 2026-08-18).
Coverage
1
first 2026-08-19 → last 2026-08-19
Latest activity
2026-08-19
Roughly 2,000 hijacked sites are the infrastructure, not the victims, and the persistence lives where nobody…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, education, technology · regions: europe
Sources cited
1
1 hosts
Action items (2)
Do-now tasks recorded on the entries about StopAndProtect, newest first. Check the date before acting on an older one.
- On every WordPress site you own, list the contents of wp-content/mu-plugins (files there load on every request and do not appear in the admin plugin list, so a hostile one is invisible to the usual review) and treat any unrecognised file, wp-sec.php in particular, as a live backdoor rather than a stale artifact.2026-08-19Roughly 2,000 hijacked sites are the…
- Enumerate the REST routes each WordPress site actually exposes and compare against the routes its installed plugins should register; a route that no known plugin accounts for is the finding.2026-08-19Roughly 2,000 hijacked sites are the…
Defender insights
What each entry about StopAndProtect tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- SilentEncryptorCheck Point names SilentEncryptor as the operation's file-encryption component, unpacked by its third-stage .NET loader
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (13 across 10 tactics)
13 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessReplication Through Removable Media
- ExecutionWindows Management Instrumentation · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Visual Basic · User Execution: Malicious Copy and Paste
- PersistenceServer Software Component: Web Shell
- StealthReflective Code Loading
- Credential AccessInput Capture: Keylogging
- DiscoveryNetwork Share Discovery
- Lateral MovementReplication Through Removable Media
- CollectionInput Capture: Keylogging · Screen Capture
- Command and ControlIngress Tool Transfer
- ImpactData Encrypted for Impact · Financial Theft
Initial Access TA0001
T1091Replication Through Removable Media×1
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Execution TA0002
T1047Windows Management Instrumentation×1
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
T1059.005Command and Scripting Interpreter: Visual Basic×1
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Stealth TA0005
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Credential Access TA0006
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Discovery TA0007
T1135Network Share Discovery×1
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Lateral Movement TA0008
T1091Replication Through Removable Media×1
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Collection TA0009
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin · ATT&CK page ↗
Entries about StopAndProtect (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- research.checkpoint.com1 (100%)