Attackers’ OPSEC mistakes expose infrastructure behind cybercrime campaign
https://etimg.etb2bimg.com/thumb/msid-133397488,imgsize-1130640,width-1200,height=627,overlay-etciso,resizemode-75/cybercrime-fraud/attackers-opsec-mistakes-expose-infrastructure-behind-cybercrime-campaign.jpg
Researchers investigating a cybercrime operation called StopAndProtect uncovered operational security (OPSEC) mistakes that exposed parts of the attackers’ infrastructure, including victim logs, screenshots, source code, internal management tools and evidence of a campaign affecting more than 5,000 computers worldwide.
The investigation also identified files referencing nearly 2,000 compromised WordPress domains, providing insight into how the operation was built and managed.
Compromised WordPress sites used as criminal infrastructure
The exposed files showed that the attackers used compromised WordPress websites instead of dedicated command-and-control servers. The sites were used to host malware, deliver additional payloads, communicate with infected devices and store stolen documents, screenshots and activity logs.
WordPress accounted for more than 43% of the global website builder market in 2026, according to Statista, making compromised sites a potential source of distributed infrastructure.
Researchers also found evidence of outdated and vulnerable WordPress installations being incorporated into the operation. In one case, a compromised website was running a 2021 version of WordPress with nearly 40 known vulnerabilities.
Attackers’ infrastructure exposed
During the investigation, researchers found publicly accessible directories containing malware logs, victim screenshots, stolen files and internal tools used to manage the campaign. They also recovered source code for automation tools used to manage compromised WordPress websites and files referencing nearly 2,000 compromised domains.
Researchers suspect that one of the operators may have accidentally infected their own computer, resulting in internal development files being uploaded to infrastructure also used to collect victim data. The archive was removed several days later, but its temporary exposure provided information about the organisation of the campaign.
Fake CAPTCHA used in ClickFix attacks
The campaign uses fake CAPTCHA pages associated with the ClickFix social engineering technique. Victims are instructed to copy, paste and execute commands on their computers, which can initiate a multi-stage infection chain that downloads additional malware from compromised WordPress websites.
The campaign combines social engineering, compromised legitimate infrastructure and modular malware. Depending on the attackers’ objectives, the malware can be used for ransomware, document theft, credential harvesting or data exfiltration.
Eli Smadja, Head of Research at Check Point Research, said, “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware. Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser.”
The investigation highlights the risks associated with outdated WordPress installations and social engineering techniques. Recommended measures include keeping WordPress and its plugins updated, educating users about ClickFix-style attacks, monitoring for suspicious PowerShell activity and avoiding CAPTCHA prompts that require users to execute commands outside the browser.
Firewall Support Company in India All type of Firewalls Support Provider Company in India












