
A criminal group used nearly 2,000 WordPress sites to distribute malware that steals crypto wallet seeds. Check Point researchers traced the campaign back to mid-May.
Alpha Score of 58 reflects moderate overall profile with strong momentum, strong value, moderate quality, poor sentiment.
A criminal group tracked by Check Point Research as StopAndProtect used nearly 2,000 poorly maintained WordPress sites to distribute malware that steals crypto wallet seed phrases, passwords, and files from Windows computers. Check Point published the findings Aug. 18, after a ransomware sample detected in mid-May led researchers to a broader extortion and surveillance operation.
What sets this campaign apart, Check Point researcher Jaromír Hořejší said, is the infrastructure. Instead of renting or compromising their own servers, the attackers turned legitimate WordPress domains into platforms that hosted payloads and relayed instructions to infected devices. A single server could handle all those functions without the criminals spending anything on hosting, Hořejší said.
The malware spreads through fake CAPTCHA pages. Visitors believe they must verify they are human to access a site. Instead the page instructs them to copy and paste a PowerShell command into their terminal. That command downloads .NET payloads that extract saved passwords, wallet seeds, and other sensitive data from the compromised machine.
Newer versions of the malware log keystrokes, capture screenshots every 30 seconds, copy files from shared folders and USB drives, and encrypt the device to demand a ransom. Check Point advised users to immediately leave any site that asks them to paste or type commands into their system.
The most valuable intelligence came from the attackers' own servers. Directories and log files were left exposed on the web because of poor security practices. Check Point suspects one of the criminals' devices was compromised, leaking internal files accidentally.
Among those files, Hořejší found the source code of an automation tool written in Visual Basic 6 that let attackers remotely control the hacked sites. As of July 24, the malware had infected more than 6,000 unique IP addresses. The United States accounted for 1,852 victims. Russia and India each had 630. More than 20,000 screenshots from compromised devices were found in one of the open directories.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.