Nearly 2,000 Hacked WordPress Sites Weaponized to Steal Cryptocurrency Wallets and Deploy Ransomware
Check Point Research discovers massive criminal operation using compromised WordPress infrastructure to target crypto users, stealing wallet seeds and credentials across 6,000+ infected systems.
A Sophisticated Multi-Component Malware Ecosystem
Thousands of WordPress websites have been compromised and repurposed as criminal infrastructure designed specifically to target cryptocurrency users, according to research published Tuesday by cybersecurity firm Check Point Research. The investigation uncovered that nearly 2,000 hacked WordPress sites formed the backbone of a coordinated malware distribution and data theft operation that compromised over 6,000 unique IP addresses and exposed sensitive cryptocurrency wallet information.
The criminal operation, linked to the StopAndProtect ransomware family, was first identified in mid-May and uses an integrated toolkit of specialized malware components rather than a single program. These components work in coordination to achieve different attack objectives. The compromised WordPress sites serve as central infrastructure for the operation, hosting malware payloads, relaying commands to infected machines, and maintaining repositories of stolen data including documents, screenshots, and victim activity logs.
The attack begins when a victim encounters a compromised website displaying a fake CAPTCHA verification—a social engineering technique called ClickFix. This prompt tricks users into executing PowerShell commands on their Windows machines, which download and install the malware. Once active, the malicious software performs multiple destructive functions: harvesting stored credentials and passwords, extracting cryptocurrency wallet seed phrases, spreading through network shares and removable drives, locking screens to facilitate ransom demands, and eventually deploying file-encrypting ransomware. The malware primarily targets Windows users, though the research did not confirm whether macOS or Linux systems are affected.
A Campaign of Staggering Scale
The breadth of this operation underscores its industrialized nature. By July 24, more than 6,000 unique IP addresses had been compromised globally, with significant concentration in the United States where 1,852 systems were infected. An additional 630 victims each were identified in Russia and India. Between mid-May and the end of July—approximately ten weeks—researchers recovered over 31,000 screenshots extracted from victims’ infected computers and collected more than 700 archives of stolen data. These archives included documents, passwords, and cryptocurrency wallet files, indicating systematic targeting of digital assets.
Operational Failures Expose the Criminal Infrastructure
A major breakthrough for researchers came through the attackers’ own security failures. Exposed directories revealed detailed infection logs from victims’ machines, screenshots from compromised computers, and source code for the tools the criminals use to manage their WordPress infrastructure at scale. Evidence suggests the threat actors accidentally infected themselves at one point, allowing researchers to examine unusual internal files that illuminate how the operation functions and estimate the likely number of domains under attacker control.
The explicit targeting of cryptocurrency wallet seed phrases demonstrates this operation’s intentional focus on stealing digital assets from crypto users. This incident underscores the persistent security threats facing the cryptocurrency ecosystem and reinforces why vigilant security practices remain essential for participants protecting their digital assets.
Source: Check Point Research, via Decrypt. Not financial advice.