Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit

A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge overhead photoreal shot of a sleek modern desk with a glowing dark monitor showing abstract code patterns and a subtle subscription-styl
Share

Key points

  • Researchers have linked nearly 2,000 hacked WordPress sites to a single criminal operation dubbed StopAndProtect.
  • The hijacked sites are being used to deliver malware, take over victim computers and store stolen files.
  • The operation runs a whole toolkit of criminal software, not one single virus, making it harder to shut down.
  • Ordinary web users can land on these sites through normal search results or malicious ads.
  • Site owners running WordPress should update plugins and check for unfamiliar admin accounts.

A global cybercrime crew has quietly turned nearly 2,000 hacked WordPress websites into its own delivery service, according to research first flagged by The Hacker News. The operation, tracked as StopAndProtect, uses those hijacked sites to push malware, which is software designed to damage or spy on a computer, onto anyone unlucky enough to visit.

Think of it like criminals hiding drugs in the back rooms of shops that don't know they've been broken into. The shopfront still looks normal. The customer walks in, and the trap is set.

What is StopAndProtect actually doing?

It is running a whole toolkit of criminal software through websites it does not own. Instead of relying on one virus, the group cycles through many, and uses the hacked sites to store stolen documents, screenshots taken from victims, and logs that track which infections are still working.

That last part matters. The hackers are treating these sites the way a legitimate company treats a filing cabinet. Stolen material goes in. Notes on which victims are still producing useful data go alongside it.

How did the hackers get into the sites?

Researchers have not published a single point of entry, but the pattern fits familiar WordPress problems: outdated plugins, weak admin passwords, and site owners who never notice a break-in. WordPress powers a huge slice of the web, and small business sites often go months without updates.

Once inside, the criminals plant their own files. The genuine owner sees nothing unusual. Visitors get redirected, or served a fake download, or hit with a script that quietly installs something nasty.

Who gets hurt by this?

Two groups. First, the site owners, whose reputations and search rankings take a hit when Google flags their pages as dangerous. Second, ordinary visitors, whose machines get infected and whose files may be stolen and stashed on those same hijacked sites.

Detail What we know
Operation name StopAndProtect
Hijacked sites Nearly 2,000
Platform abused WordPress
Stolen data held on sites Documents, screenshots, activity logs
Delivery method Malware served to site visitors

What should ordinary people watch for?

Be wary of downloads that appear after clicking a search result, especially installers for software you didn't go looking for. If a familiar-looking site suddenly asks you to update your browser or run a file to view content, close the tab. Real websites do not work that way.

If you run a WordPress site, log in and check the list of admin users. An account you don't recognise is a red flag. Update every plugin, and remove any you no longer use. Old plugins are the single most common way these break-ins start.

Why this matters beyond one campaign

StopAndProtect is not a clever new attack. It is old-fashioned website hijacking at industrial scale, dressed up with a filing system. The interesting part is the discipline: the group is running its criminal business the way a small software company runs its operations, with logs, storage and inventory.

That is the pattern worth watching. Not the malware itself, but the infrastructure behind it, built for free on other people's servers.

© 2026 Threat Vectr