Search the site
Press ESC to close
LIVE
Loading...
Updating...

WordPress Hack Targets 2,000 Sites to Steal Crypto Wallets and Data

Fact-checked
3 min read
402 words
Share

Cybersecurity researchers have uncovered a large-scale malicious operation targeting the WordPress ecosystem, resulting in the compromise of nearly 2,000 websites. According to a report from Check Point Research, the campaign, dubbed “StopAndProtect,” aims to infiltrate Windows-based systems to exfiltrate sensitive data, specifically targeting cryptocurrency wallet mnemonic phrases and credentials. The attack represents a significant threat to decentralized finance (DeFi) participants who interact with web-based platforms.

Mechanism of the StopAndProtect Attack

The threat actors behind this campaign utilize a sophisticated social engineering tactic to bypass standard security perceptions. By deploying fake CAPTCHAs on legitimate but compromised WordPress sites, they trick visitors into executing PowerShell commands. Once a user follows the prompts, the malware installs itself on the host machine, initiating a series of malicious activities designed to compromise the user's digital assets and privacy.

  • Wallet Theft: The malware scans local files for private keys and recovery seeds associated with various crypto wallets.
  • Lateral Movement: The infection spreads through local networks and connected USB devices to maximize its reach.
  • Ransomware Deployment: In addition to data theft, the malware can lock screens and encrypt files, demanding payment for decryption.
  • Credential Harvesting: The software extracts saved passwords and login information from web browsers.

Operational Errors Lead to Discovery

Despite the scale of the operation, which was first detected in mid-May 2024, the hackers made critical technical errors that allowed security experts to analyze their infrastructure. The researchers noted that the attackers inadvertently exposed internal files, providing a rare glimpse into the backend of a cybercriminal enterprise.

The hackers made a low-level mistake in their operation – exposing internal files, including infection logs, screenshots of victim computers, and source code for managing the hacked websites, allowing security teams to gain a deep understanding of their operations.

This exposure has provided cybersecurity firms with the necessary data to track the progression of the malware and develop more effective countermeasures for WordPress site administrators and end-users.

The discovery of the StopAndProtect campaign highlights the ongoing vulnerabilities within content management systems (CMS) and the persistent interest of cybercriminals in the cryptocurrency sector. Users are advised to exercise extreme caution when prompted to run scripts or commands by web interfaces and to utilize hardware wallets for storing significant quantities of digital assets. As the investigation continues, WordPress site owners are encouraged to update their security plugins and audit their site directories for unauthorized scripts.

Frequently Asked Questions

Quick answers to the most common questions about this topic.