LIVE · cybersecurity feed
Live wire
malware

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

zeroday.news ·

Cybersecurity researchers have uncovered a global cybercrime operation, dubbed "StopAndProtect," that leverages nearly 2,000 compromised WordPress websites to facilitate its malicious activities. The operation reportedly uses these hacked sites as a distributed infrastructure to spread various malware strains, maintain control over infected systems, and exfiltrate sensitive data, including documents, screenshots, and activity logs.

The core mechanism of the StopAndProtect operation involves the initial compromise of a large number of WordPress sites. Once compromised, these websites are then repurposed by the attackers to host and distribute their malicious toolkit. This strategy allows the threat actors to diversify their distribution channels, making it more challenging for defenders to block all sources of the malware. The use of legitimate, albeit compromised, websites can also help the malware evade detection by appearing to originate from trusted domains.

The researchers noted that StopAndProtect does not rely on a singular malware payload but rather employs a comprehensive suite of criminal software. This toolkit approach suggests a sophisticated operation capable of adapting its attacks and achieving multiple objectives. Such toolkits typically include various components for initial access, privilege escalation, persistence, data exfiltration, and command and control (C2) communications. The specific types of malware within the toolkit were not detailed, but they are designed to commandeer infected hosts and steal data.

The compromised WordPress sites serve multiple roles within the operation. Beyond malware distribution, they are also used as command-and-control servers, enabling the attackers to issue commands to infected machines and receive data back. Furthermore, these sites are utilized as storage repositories for exfiltrated information. This includes stolen documents, screenshots of compromised systems, and activity logs that track the status and progress of the malicious activities. Storing exfiltrated data on a network of compromised sites can make it harder for law enforcement and security teams to trace the ultimate destination of the stolen information.

The global scale of the operation, involving nearly 2,000 hacked WordPress sites, indicates a significant and widespread threat. WordPress, being the most popular content management system globally, is a frequent target for attackers due to its extensive user base and the potential for vulnerabilities in its core software, themes, or plugins. Regular patching, strong authentication, and robust security configurations are critical mitigations for website administrators to prevent their sites from being co-opted into such malicious infrastructures.

For organizations and individuals, the primary concern is the potential for malware infection and subsequent data theft. Typical mitigation strategies against such threats include maintaining up-to-date antivirus and anti-malware software, employing network intrusion detection and prevention systems, regularly backing up critical data, and educating users about phishing and social engineering tactics that often lead to initial compromises. Monitoring network traffic for unusual patterns and connections to known malicious indicators is also crucial.

This operation underscores the persistent challenge posed by cybercriminals who exploit widely used platforms for their illicit activities. The distributed nature of StopAndProtect, leveraging a vast network of compromised legitimate websites, exemplifies a common tactic to enhance resilience and evade detection. It highlights the need for continuous vigilance and proactive security measures across the digital ecosystem, from individual website administrators to enterprise security teams, to counter evolving cyber threats.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

US charges Iranians for sprawling hacking campaign on government agencies, universities

The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

ai

OpenAI Tightens AI Safeguards Following Hugging Face Incident

OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities

ai

Prevalent AI Raises $22 Million to Expand Data Fabric Platform

The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek.

security

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek.

vulnerability

Microsoft fixes known issue causing Windows Defender crashes

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.