LIVEAI market intelligence
StarLive
StarNews › StarFlash
⚡ StarFlash

Nearly 2,000 WordPress-built websites hacked to steal crypto wallets and deploy ransomware

近2,000个WordPress网站遭入侵,被用于窃取加密钱包并投放勒索软件
✓ Key facts
  • Check Point Research said hackers compromised nearly 2,000 WordPress-built websites and used them to spread malware, steal crypto wallet files, and deploy ransomware.
  • The campaign, called StopAndProtect, was first identified in mid-May.
  • Attackers tricked Windows users into running PowerShell commands through fake CAPTCHAs on the compromised sites.
  • The malware could steal credentials and crypto wallet mnemonic phrases, spread across networks and USB devices, lock screens, and deploy ransomware.
  • Researchers said the attackers exposed internal files, including infection logs, victim screenshots, and source code for managing the compromised sites.
  • By July 24, more than 6,000 unique IP addresses had been affected, including 1,852 in the United States and 630 each in Russia and India.

Cybersecurity firm Check Point Research said hackers compromised nearly 2,000 WordPress-built websites and used them to distribute malware, steal crypto wallet files, and deploy ransomware. The operation was identified in mid-May and was referred to as StopAndProtect.

According to the report, the attackers used fake CAPTCHAs on the compromised sites to get Windows users to run PowerShell commands. The resulting malware could steal credentials and crypto wallet mnemonic phrases, spread through networks and USB devices, lock screens, and trigger ransomware.

Researchers said the campaign also exposed internal files, including infection logs, screenshots from victims’ computers, and source code used to manage the hacked websites. That gave security teams a detailed look at how the operation functioned.

As of July 24, more than 6,000 unique IP addresses had been affected, with the largest concentrations in the United States, Russia, and India. For markets, the direct effect is mainly negative for crypto sentiment because the activity targets wallet files and credentials, while the impact on stocks, gold, and foreign exchange is likely limited and indirect.

中文版

近2,000个WordPress网站遭入侵,被用于窃取加密钱包并投放勒索软件

网络安全公司Check Point Research表示,黑客入侵了近2,000个基于WordPress搭建的网站,并利用这些网站传播恶意软件、窃取加密钱包文件并投放勒索软件。这一行动在5月中旬被发现,研究人员将其称为StopAndProtect。

报告称,攻击者在被入侵网站上放置虚假CAPTCHA,诱使Windows用户运行PowerShell命令。相关恶意程序可以窃取凭证和加密钱包助记词,还能在网络和USB设备之间传播、锁定屏幕并触发勒索软件。

研究人员表示,这一行动还暴露了内部文件,包括感染日志、受害者电脑截图,以及用于管理被入侵网站的源代码,使安全团队得以更深入了解其运作方式。

截至7月24日,已有超过6,000个独立IP地址受到影响,其中美国最多,俄罗斯和印度各有630个。就市场影响看,这类事件对加密货币情绪偏利空,因为涉及钱包文件和凭证;对股票、黄金和外汇市场的直接影响则较有限,更多是间接影响。

Original reporting: panewslab.com. StarLive rewrote this story in its own words, preserving the facts; the full third-party article is not reproduced. AI-generated · market intelligence, not financial advice.
🔍 Analyze any asset with StarLive's 7-layer AI →