Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Uses Compromised WordPress Sites for C2 Operations

Malware Uses Compromised WordPress Sites for C2 Operations

Posted on August 18, 2026 By CWS

A recent cybersecurity investigation has revealed a malicious operation named StopAndProtect, which is exploiting thousands of compromised WordPress websites to build an extensive command-and-control (C2) network. This campaign combines ransomware and stealthy data exfiltration, targeting sensitive information from affected systems globally.

According to internal logs, the campaign has impacted over 6,000 unique IP addresses, with the United States, Russia, and India showing the highest infection rates. The threat actors manipulate nearly 2,000 compromised WordPress domains, establishing a robust infrastructure to distribute malware and manage stolen data.

WordPress Sites as C2 Servers

The attack begins with deceptive CAPTCHA prompts on vulnerable WordPress sites, where visitors are misled into executing a harmful PowerShell command. This command triggers a multi-stage infection process using PowerShell scripts and .NET loaders, deploying a suite of malicious tools.

These tools include ransomware, credential stealers, screen lockers, and network worms. The operation, as detailed by Check Point Research, focuses on intelligence gathering and selective targets, deviating from typical smash-and-grab tactics.

Analyzing the Threat

Security researchers gained insight into the operation through exposed PHP endpoints and open directories on compromised servers. Notably, the attackers mistakenly uploaded internal development files, shedding light on their tactics, including a Visual Basic tool for managing hijacked sites and deploying malware.

This case underscores the dangers of outdated Content Management Systems (CMS). One site had been unpatched since 2021, leaving it vulnerable to numerous exploits. Unpatched WordPress sites offer persistent entry points for attackers to convert legitimate domains into malicious hubs.

Securing Your WordPress Site

To counter these threats, website administrators must rigorously update WordPress core files, themes, and plugins. Regular scans for unauthorized scripts and suspicious account activity are essential. End users should regard any terminal command prompts as potential security threats.

By maintaining a vigilant approach to security updates and monitoring network activity, organizations can mitigate the risks posed by such malware campaigns. Proactive measures are vital to prevent adversaries from exploiting vulnerabilities and expanding their reach within networks.

In conclusion, the StopAndProtect operation highlights the evolving threats to web security and the importance of regular maintenance and monitoring of digital assets. As attackers continuously refine their methods, robust defense strategies are crucial in safeguarding sensitive information and maintaining secure online environments.

Cyber Security News Tags:C2 servers, compromised sites, cyber crime, Cybersecurity, data theft, Hacking, Malware, network security, Ransomware, Security, security updates, threat detection, Websites, WordPress

Post navigation

Previous Post: Ransom Busters’ Ransomware Deletion Claims Under Scrutiny
Next Post: Microsoft 365 Search Issue Affects Global Users

Related Posts

CISA Releases 3 ICS Advisories Covering Vulnerabilities and Exploits CISA Releases 3 ICS Advisories Covering Vulnerabilities and Exploits Cyber Security News
Mindgard Secures  Million to Enhance AI Security Mindgard Secures $30 Million to Enhance AI Security Cyber Security News
20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly 20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly Cyber Security News
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Cyber Security News
First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology Cyber Security News
Azure Data Breach Exposes Millions from Major Firms Azure Data Breach Exposes Millions from Major Firms Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft 365 Search Issue Affects Global Users
  • Malware Uses Compromised WordPress Sites for C2 Operations
  • Ransom Busters’ Ransomware Deletion Claims Under Scrutiny
  • CISA Issues Warning on Medusa Ransomware Tactics
  • Critical MLflow and FUXA Vulnerabilities Exploited by Attackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft 365 Search Issue Affects Global Users
  • Malware Uses Compromised WordPress Sites for C2 Operations
  • Ransom Busters’ Ransomware Deletion Claims Under Scrutiny
  • CISA Issues Warning on Medusa Ransomware Tactics
  • Critical MLflow and FUXA Vulnerabilities Exploited by Attackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark