Security researchers have uncovered a sprawling cybercrime operation that relied on a network of compromised WordPress websites to distribute malware, harvest data and run ransomware, according to a new investigation.
Scope and method of the operation
Check Point Research identified an operation investigators labeled StopAndProtect that used a combination of hijacked WordPress installations and infected computers to build a distributed criminal infrastructure. The team found roughly 2,000 WordPress domains tied to the scheme and about 5,000 infected machines around the globe.
| Metric | Count |
|---|---|
| Hijacked WordPress domains | 2,000 |
| Infected computers | 5,000 |
| Approx. global WordPress market share (context) | 43% |
WordPress powers a large portion of the internet and is commonly used for everything from single-page sites to complex news platforms and online stores. That prevalence made the CMS an attractive target: attackers exploited outdated core installs and third-party plugins to gain control of victims’ domains.
Malicious uses and investigator findings
According to Check Point Research, StopAndProtect went beyond simple website defacement or hosting of malicious files. The investigators say the operation facilitated:
- malware delivery
- surveillance and data theft
- ransomware distribution
Investigators reported finding internal tools, screenshots and victim logs during their probe, along with files that referenced the compromised domains — evidence that helped map the operation and expose operational mistakes the perpetrators made.
“StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware,”
— Eli Smadja, Check Point Research
Why WordPress sites are vulnerable
WordPress’s open-source nature and wide usage contribute to both its utility and risk. The platform’s popularity — estimated to provide content management for roughly 43% of websites worldwide — and the prevalence of automated installers and third-party plugins produce many targets with weak maintenance practices. According to the report, attackers leveraged outdated software and vulnerable plugins to covertly host malicious payloads and coordinate activity across multiple sites.
Check Point’s investigators initially used the name StopAndProtect for a specific strain of ransomware observed earlier in 2026, but expanded the label after finding the broader criminal ecosystem that used the ransomware alongside other malicious functions.
Implications and response
The operation highlights an ongoing security challenge for administrators and organizations that rely on WordPress. Experts say routine patching, removing unused plugins and monitoring for unusual activity remain critical defenses. The findings also underscore the danger of using poorly maintained sites as part of an attackers’ distributed infrastructure: compromised domains can be repurposed for many types of criminal activity without the owners’ knowledge.
Check Point Research’s disclosure provides a roadmap for defenders and site operators to search for indicators of compromise tied to this campaign. The investigation also raises questions about how smaller organizations and individuals can reliably harden sites against similarly scaled operations.
The StopAndProtect probe serves as a reminder that common web platforms can be weaponized at scale when maintenance lapses and threat actors focus on the weakest links in the internet’s fabric.