Nearly 2,000 Hacked WordPress Websites Used to Spread Malware
Cybersecurity researchers have uncovered a large malware campaign that has turned nearly 2,000 hacked WordPress websites into tools for cybercriminals. The campaign, which researchers have called StopAndProtect, uses legitimate websites that have been compromised to help distribute malicious software, communicate with infected computers, and collect information from victims.
The campaign is particularly concerning because the websites being used by the attackers are not necessarily created for malicious purposes. Instead, criminals appear to be breaking into existing WordPress sites and secretly using them as part of their operation. This allows the attackers to hide their activities behind websites that may appear completely normal to visitors.
Researchers observed more than 6,000 unique IP addresses connected to the campaign. An IP address is essentially an identifying number associated with a device or internet connection. Seeing thousands of addresses involved in the activity suggests that the campaign has reached a significant number of potential victims and devices.
One of the main purposes of the compromised websites is to help deliver malware to unsuspecting users. Someone visiting one of the hacked sites may have no idea that the website has been compromised. Depending on the attacker’s setup and the victim’s device, the website can be used to redirect visitors, load malicious content, or help convince them to download software that contains malware.
Using hacked websites provides criminals with several advantages. Instead of purchasing and maintaining thousands of websites themselves, attackers can take advantage of websites that already have established domain names, hosting accounts, and normal-looking content. This can also make their infrastructure more difficult to identify because security teams may initially see traffic going to a legitimate website rather than an obviously malicious domain.
The compromised WordPress sites also appear to play a role in the attackers’ command-and-control infrastructure. Command-and-control, often shortened to C2, is the system criminals use to communicate with malware after it has infected a device. Through these connections, attackers can potentially send instructions to infected computers and receive information back from them.
This type of infrastructure is an important part of modern malware campaigns. Once malicious software gets onto a computer, it often needs a way to communicate with its operators. By hiding that communication inside compromised websites, attackers can make it harder for defenders to determine where the operation is actually being controlled from.
WordPress is an especially attractive target for criminals because it powers a huge number of websites around the world. Websites can become vulnerable when WordPress itself, plugins, or themes are not kept up to date. Weak passwords, stolen administrator credentials, and poorly secured hosting environments can also give attackers an opportunity to take control of a site.
Once a website has been compromised, the owner may not immediately notice anything wrong. The site’s normal pages may continue to work, while malicious code operates quietly in the background. In some cases, attackers deliberately try to avoid affecting normal visitors so that the website owner does not discover the intrusion.
The StopAndProtect campaign demonstrates why website owners need to take security seriously even if their websites do not contain particularly sensitive information. A small business website or personal blog might not seem like an attractive target, but attackers can use thousands of compromised sites as building blocks for much larger criminal operations.
Website administrators should make sure WordPress, plugins, and themes are regularly updated and should remove software that is no longer being used. Strong, unique administrator passwords and multi-factor authentication can also make it significantly harder for criminals to take over accounts. Website owners should additionally monitor their sites for unexpected changes, unfamiliar administrator accounts, suspicious files, and unusual traffic.
Visitors should also be cautious when browsing websites that suddenly redirect them to unfamiliar pages or unexpectedly ask them to download software. Legitimate websites can be compromised, so simply recognizing a familiar website name does not guarantee that everything being delivered through it is safe.
The StopAndProtect campaign is another example of how cybercriminals can turn everyday internet infrastructure against its users. Rather than building an obvious network of malicious websites, attackers can compromise legitimate sites and quietly turn them into pieces of a much larger operation. With nearly 2,000 WordPress websites reportedly involved and thousands of IP addresses associated with the campaign, the incident shows how quickly compromised websites can become part of a widespread malware distribution network.






