
A campaign using fake CAPTCHAs on 2,000 hacked WordPress sites has stolen crypto wallet files and infected over 6,000 IPs across the US, Russia, and India, Check Point Research said.
Check Point Research uncovered a sprawling cybercrime campaign that turns outdated WordPress installations into malware launchpads, targeting crypto holders across three continents.
The operation, called StopAndProtect, has weaponized nearly 2,000 compromised WordPress websites to distribute malware, siphon cryptocurrency wallet files, and deploy ransomware against victims in the US, Russia, and India. Check Point published its findings on August 18, detailing a campaign first spotted in mid-May 2026 that has since ballooned into one of the more brazen web-infrastructure hijacking schemes in recent memory.
The infection spread to more than 6,000 unique IP addresses through a deceptively simple trick: fake CAPTCHA prompts that convince visitors to run malicious PowerShell commands on their own machines.
StopAndProtect relies on a social-engineering technique called ClickFix. When an unsuspecting user lands on one of the compromised WordPress sites, they encounter what looks like a standard CAPTCHA verification page. Instead of clicking squares with traffic lights, victims are prompted to execute a PowerShell command, which kicks off a multi-stage infection process.
That initial command downloads a .NET loader, which then pulls in a suite of malware components. These include credential stealers, obfuscation tools designed to dodge antivirus detection, and modules specifically built to locate and exfiltrate crypto wallet files. The compromised WordPress sites don't just serve as the initial bait. They also function as command-and-control servers and data storage repositories for stolen information.
Many of the hijacked sites were running WordPress versions released as far back as 2021.
The geographic spread of the campaign is wide. Of the 6,000-plus unique IP addresses flagged as of July 24, the US accounted for the largest share at 1,852 addresses, followed by Russia and India at 630 each.
Check Point researchers accessed more than 31,000 screenshots captured from victims' machines, along with directories containing up to 700 stolen data archives. Those screenshots and logs gave researchers a detailed map of the attackers' targeting methods and the scope of data they had already harvested.
What makes StopAndProtect different from garden-variety ransomware is its hybrid approach. Rather than simply encrypting files and demanding payment, the operation combines selective file encryption with extensive data theft and ongoing user surveillance. The ransomware component encrypts enough to cause pain, but the real value for the attackers appears to be the steady stream of stolen credentials, wallet files, and screenshots flowing back to their infrastructure.
The deliberate targeting of cryptocurrency wallet files elevates this from a generic malware campaign to a direct threat against digital asset holders. The malware's data exfiltration modules are specifically designed to hunt for wallet files on infected machines, meaning anyone who stores private keys or seed phrases on a device that visits a compromised site is a potential target.
WordPress site administrators have a role to play in shrinking the attack surface. The fact that so many of the compromised sites were running software with known vulnerabilities from half a decade ago suggests that basic patch management would have prevented a significant portion of this campaign's infrastructure from ever being established.
Check Point's ability to access the attackers' own stolen data troves may accelerate law enforcement response and victim notification efforts. Researchers accessed more than 31,000 screenshots from infected machines, along with up to 700 stolen data archives, they said.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.