Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit

A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A WordPress dashboard interface overlaid with malware distribution nodes and command-and-control infrastructure visualization, showing how compromised sites for
Share

Key points

  • Researchers have linked nearly 2,000 hacked WordPress sites to a single criminal operation dubbed StopAndProtect.
  • The hijacked sites deliver malware and store stolen documents, screenshots and activity logs.
  • The operation runs a toolkit of criminal software rather than a single virus, making it harder to shut down.
  • Ordinary web users can reach these sites through normal search results or malicious ads.
  • WordPress site owners should check for unfamiliar admin accounts and update every plugin.

A global cybercrime crew has quietly turned nearly 2,000 hacked WordPress websites into its own delivery service, according to research first flagged by The Hacker News. The operation, tracked as StopAndProtect, uses those hijacked sites to push malware onto anyone unlucky enough to visit. Malware is software designed to damage or spy on a computer.

Think of it like criminals hiding contraband in the back rooms of shops that don't know they've been broken into. The storefront looks normal. Customers walk in, and the trap is already set.

What is StopAndProtect actually doing?

It runs a toolkit of criminal software through websites it doesn't own. The group cycles through many pieces of malware and uses the hacked sites to store stolen documents, screenshots from victims, and logs tracking which infections are still active.

The hackers are treating these sites the way a legitimate company treats a filing cabinet: stolen material goes in, notes on productive victims go alongside it. That discipline is what sets this apart from a smash-and-grab.

How did the hackers get into the sites?

Researchers haven't published a single point of entry. WordPress powers a huge slice of the web, and small business sites often go months without updates. Our 17 August story on a critical flaw in the Forminator plugin, rated 9.8 out of 10, showed exactly how badly unpatched plugins can go wrong.

Once inside, the criminals plant their own files. The genuine owner sees nothing unusual. Visitors get redirected, served a fake download, or hit with a script that quietly installs something malicious.

Who gets hurt by this?

Site owners take a reputational hit when Google flags their pages as dangerous, and their search rankings suffer alongside it. Visitors get infected machines and may find their files stashed on those same hijacked sites.

Detail What we know
Operation name StopAndProtect
Hijacked sites Nearly 2,000
Platform abused WordPress
Stolen data held on sites Documents, screenshots, activity logs
Delivery method Malware served to site visitors

What should ordinary people watch for?

Be wary of downloads that appear after clicking a search result, especially installers for software you didn't go looking for. If a familiar-looking site suddenly asks you to update your browser or run a file to view content, close the tab. Real websites don't work that way.

If you run a WordPress site, log into the admin panel and review the list of users. An account you don't recognise is a red flag. Remove every plugin you no longer use and update the rest immediately.

Should you worry about the wider pattern?

StopAndProtect isn't a clever new attack. It's old-fashioned website hijacking at industrial scale, dressed up with a filing system. The group is running its criminal business like a small software company: logs, storage, inventory, all built for free on other people's servers.

That infrastructure discipline is the detail worth watching next, not the malware payload itself.

© 2026 Threat Vectr