Summary
- Check Point says StopAndProtect abused thousands of hacked WordPress websites as malware-distribution, command-and-control, and stolen-data infrastructure.
- Operational-security failures exposed internal logs and tools, with more than 6,000 unique victim IP addresses appearing in the material.
- The campaign shows how ordinary business websites can become criminal infrastructure even when the website owner is not the malware operation’s primary victim.
Thousands of compromised WordPress websites have been repurposed as infrastructure for a malware operation that combines file encryption with data theft, according to new research from Check Point.
The operation, which researchers call StopAndProtect, uses hacked websites to distribute malware, communicate with infected machines, and store stolen documents, screenshots, and activity logs. That turns otherwise ordinary web hosting into a distributed layer of criminal infrastructure.
Check Point said operational-security failures by the malware developer exposed internal material including infection logs, screenshots from compromised systems, and source code for tools used to mass-manage hacked websites.
The exposed logs contained more than 6,000 unique victim IP addresses, indicating a campaign operating across multiple regions and networks rather than a small number of targeted intrusions. The largest concentrations identified by the researchers were in the United States, Russia, and India.
The operation’s use of WordPress sites is significant because the websites themselves may belong to businesses with no connection to the malware victims. Once compromised, their hosting resources can become part of a command-and-control, distribution, or storage network without the legitimate owner understanding how the infrastructure is being used.
Websites become an infrastructure dependency
Business websites are often treated as lower-risk digital assets than internal systems because they may contain limited sensitive information and sit outside core operational networks. StopAndProtect demonstrates a different exposure: even a relatively modest public website can provide attackers with trusted hosting, bandwidth, a legitimate domain, and a geographically distributed foothold.
That can create consequences for several parties at once. Malware victims face data theft and encryption, while owners of the hijacked websites may suffer reputational damage, provider suspension, blacklisting, incident-response costs, or further compromise if the same access extends beyond the web application.
Distributed use of legitimate websites also complicates disruption. Taking down a conventional malicious server can remove a clear piece of attacker infrastructure. A network built from thousands of unrelated compromised sites is more fragmented and can be replenished as new sites are breached.
The campaign emerges against a period of unusually intense WordPress exploitation. Critical WordPress core vulnerabilities disclosed in July 2026 were followed by large volumes of exploit attempts against unpatched installations, while separate plugin and supply-chain incidents have reinforced how widely exposed the ecosystem can become when vulnerable components are deployed at scale.
Check Point’s research does not establish that all StopAndProtect sites were compromised through the same vulnerability or mechanism. WordPress compromises can result from vulnerable core versions, plugins and themes, weak credentials, stolen administrator sessions, or compromised hosting accounts.
The infrastructure model nevertheless shows why website security cannot be assessed only by asking what information a site stores. A compromised site can have value as a platform from which attackers reach entirely different victims.
For businesses relying on agencies, managed hosts, or third parties to maintain public websites, that also raises an accountability issue. Responsibility for patching, credential management, monitoring, and incident response needs to be explicit because the operational consequences of a neglected website can extend beyond defacement or downtime.
Check Point’s exposure of the operation gives defenders and hosting providers an opportunity to identify and remove part of the compromised infrastructure. The wider pattern is likely to persist, however, because legitimate web estates remain plentiful, distributed, and difficult to distinguish from attacker-controlled infrastructure until abuse is detected.



