Unveiling StopAndProtect: Massive cybercriminal blunder exposes internal network | #cybercrime | #infosec


The StopAndProtect operation was exposed after a series of operational security errors committed by the attackers themselves, allowing investigators access to victim records, screenshots, source code, internal tools, and confidential documentation. Researchers from the cybersecurity company Check Point Software Technologies Ltd. have published their findings on the internal workings of this cybercrime organization.

This analysis reconstructs how a modern criminal infrastructure is organized from the inside, not from the victims’ perspective. The campaign, which affected more than 5,000 infected computers worldwide, employed nearly 2,000 compromised WordPress domains as a means to distribute malware and manage the operation.

The vulnerabilities of WordPress

It is particularly noteworthy that StopAndProtect avoided using traditional command and control servers. Instead, the operators enabled a distributed infrastructure by leveraging thousands of vulnerable WordPress websites to conceal their activity among legitimate internet traffic and make detection more difficult.

The compromised sites performed different functions throughout the attack cycle: hosting and distributing malware, delivering additional malicious payloads, communicating with infected systems, and storing stolen documents, screenshots, and activity logs. This strategy turns seemingly innocuous web pages into fundamental pieces of a resilient and scalable criminal network.

WordPress represents more than 43% of the global content management market in 2026, a popularity that makes it an especially attractive target for cybercriminals looking to operate on a large scale without deploying their own infrastructure.

The entry point

The investigation also highlights a persistent problem for companies and web administrators: the lack of updates for applications and plugins. During the analysis, Check Point Research found a compromised site that was still running a version of WordPress released in 2021, accumulating nearly 40 known vulnerabilities. The case illustrates how a single neglected page can end up being part of an international criminal operation without its owner being aware of it.

The researchers warn that thousands of installations continue to operate with outdated software, expanding the attack surface available to groups specializing in compromising legitimate websites.

The cybercriminals’ weak points

The partial downfall of StopAndProtect was not due to a technical vulnerability but rather a chain of human errors. The operators exposed internal files containing critical information about their infrastructure, including administrative tools, operational logs, and evidence of compromised victims.

Analysts estimate that such failures demonstrate that even the most sophisticated criminal organizations depend on the correct management of their own operational security. A single oversight can provide investigators with exceptional visibility into their operations and accelerate the identification of their methods and resources.

The StopAndProtect operation was exposed after a series of operational security errors committed by the attackers themselves, allowing investigators access to victim records, screenshots, source code, internal tools, and confidential documentation. Researchers from the cybersecurity company Check Point Software Technologies Ltd. have published their findings on the internal workings of this cybercrime organization.

This analysis reconstructs how a modern criminal infrastructure is organized from the inside, not from the victims’ perspective. The campaign, which affected more than 5,000 infected computers worldwide, employed nearly 2,000 compromised WordPress domains as a means to distribute malware and manage the operation.

The vulnerabilities of WordPress

It is particularly noteworthy that StopAndProtect avoided using traditional command and control servers. Instead, the operators enabled a distributed infrastructure by leveraging thousands of vulnerable WordPress websites to conceal their activity among legitimate internet traffic and make detection more difficult.

The compromised sites performed different functions throughout the attack cycle: hosting and distributing malware, delivering additional malicious payloads, communicating with infected systems, and storing stolen documents, screenshots, and activity logs. This strategy turns seemingly innocuous web pages into fundamental pieces of a resilient and scalable criminal network.

WordPress represents more than 43% of the global content management market in 2026, a popularity that makes it an especially attractive target for cybercriminals looking to operate on a large scale without deploying their own infrastructure.

The entry point

The investigation also highlights a persistent problem for companies and web administrators: the lack of updates for applications and plugins. During the analysis, Check Point Research found a compromised site that was still running a version of WordPress released in 2021, accumulating nearly 40 known vulnerabilities. The case illustrates how a single neglected page can end up being part of an international criminal operation without its owner being aware of it.

The researchers warn that thousands of installations continue to operate with outdated software, expanding the attack surface available to groups specializing in compromising legitimate websites.

The cybercriminals’ weak points

The partial downfall of StopAndProtect was not due to a technical vulnerability but rather a chain of human errors. The operators exposed internal files containing critical information about their infrastructure, including administrative tools, operational logs, and evidence of compromised victims.

Analysts estimate that such failures demonstrate that even the most sophisticated criminal organizations depend on the correct management of their own operational security. A single oversight can provide investigators with exceptional visibility into their operations and accelerate the identification of their methods and resources.




Click Here For The Original Source.

——————————————————–

..........

.

.