
Check Point Research uncovered a campaign using nearly 2,000 compromised sites to trick crypto holders into running malware that steals wallet seeds and credentials. Over 6,000 IPs infected.
Alpha Score of 58 reflects moderate overall profile with strong momentum, strong value, moderate quality, poor sentiment.
A criminal group identified by Check Point Research has hijacked nearly 2,000 poorly maintained WordPress websites to host malware that steals cryptocurrency wallet seeds, passwords, and files from Windows computers. The campaign, which the researchers named StopAndProtect, targets crypto users through fake CAPTCHA prompts that trick victims into running PowerShell commands.
The attackers do not rent their own servers. They operate entirely from compromised blogs that appear as legitimate business sites. Jaromír Hořejší, the Check Point researcher who traced the campaign, said this choice is the campaign's most interesting feature. One hacked WordPress instance can host the ransomware payload, relay instructions to infected machines, and store stolen files.
Check Point published its findings on August 18 after connecting a ransomware sample spotted in mid-May to a larger extortion and surveillance operation. By July 24, according to the researchers, the campaign had infected more than 6,000 unique IP addresses. Of those, 1,852 were in the United States, with 630 each in Russia and India.
Hundreds of compromised sites run outdated WordPress software. Hořejší's team found nearly 40 separate vulnerabilities dating back to 2021 on a single infected domain.
The phishing sequence begins when a Windows user visits a hacked site. The page shows a fake CAPTCHA that instructs the visitor to copy and paste a PowerShell command into the terminal. That command downloads .NET-based malware capable of extracting saved passwords, cryptocurrency wallet seed phrases, and other sensitive files.
Later versions of the malware add keystroke logging, take screenshots every 30 seconds, and can even use WhatsApp to pull photos from a victim's contact list, the researchers said. The malware also copies files from shared network folders and USB drives, and can encrypt the entire machine and demand a ransom.
Between mid-May and the end of July, Check Point found more than 700 archives of stolen data. One open directory contained over 20,000 screenshots of victims' computers. The researchers said the threat actors scanned files on infected machines to select the most valuable ones for exfiltration.
The most revealing information came from the attackers' own security failures. The criminals left directories and log files exposed to the web, possibly because one of their own computers had been compromised. Hořejší found the source code for an automation tool the group used to control the hacked websites.
That tool, written in legacy Visual Basic 6, lets the criminals remotely toggle the fake CAPTCHA page, redirect site visitors, and update malware on the compromised domains. A text file attached to the tool listed all the domains the group had taken over.
For the crypto sector, the campaign represents a direct threat to anyone who saves wallet seeds or private keys on a Windows machine. The infection method does not require any software vulnerability on the victim's side, only a moment of user error. Exchanges and wallet providers may need to warn customers about the specific CAPTCHA approach.
Researchers caution crypto users to be wary of any website that asks them to copy and paste commands into a terminal. The safest response is to leave the page immediately, Hořejší said.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.