# The Irony of StopAndProtect: A Malware Network That Weaponized Nearly 2,000 Legitimate Websites


You don't build a malware distribution network from scratch anymore. Why register sketchy domains that security vendors flag on day one when you can just borrow someone else's legitimate infrastructure? That's the operating logic behind StopAndProtect, a campaign that hijacked roughly 2,000 compromised WordPress installations to serve as dual-purpose attack nodes — spreading malware to victims while simultaneously siphoning their data.


The name alone is worth a beat: StopAndProtect. Whoever runs this operation has a sense of humor, or a particular contempt for defenders.


## How a Legitimate Website Becomes a Weapon


The mechanics here follow a well-worn playbook, but the scale matters. WordPress powers somewhere north of 43% of the entire web — which means it also powers the largest single reservoir of attackable web infrastructure on the planet. Plugins with unpatched CVEs, abandoned sites running PHP versions that haven't seen a security update since 2019, credential stuffing against wp-admin, XML-RPC abuse: the attack surface is enormous and largely unmaintained.


Once attackers establish a foothold, a WordPress site transforms into something far more useful than a vandalized homepage. It becomes a node with a trusted domain reputation, valid TLS certificates, and a history of legitimate traffic — all the qualities that help requests slip past reputation-based filters. Security tools that would immediately flag a newly registered .xyz domain have a much harder time blocking traffic from a small-business bakery site that's been around since 2011.


The StopAndProtect network exploited exactly this trust gap. Compromised WordPress sites were enlisted as distribution points, pushing malware payloads to targets while simultaneously operating as data exfiltration channels — a two-way street that maximizes the value of each compromised host.


## Two Jobs, One Hacked Site


The dual function — malware delivery and data theft — is what distinguishes this campaign from simpler redirect chains. Many criminal operations use compromised sites purely as stepping stones: redirect the victim somewhere else, and the WordPress site is just an intermediary. StopAndProtect skips the middleman in the other direction too. The compromised infrastructure isn't passive; it's actively receiving stolen data.


This creates a specific detection challenge. Network defenders looking for outbound connections to known-bad infrastructure will get a clean bill of health if the exfiltration endpoint is a cooking blog in Ohio. DNS-based blocking fails for the same reason. Behavioral detection — catching the actual malicious activity on the endpoint — becomes the primary viable layer, which is precisely the detection posture that most small and mid-sized organizations haven't fully built.


The breadth of the network is also significant. At 2,000 sites, there's enough distributed infrastructure to rotate endpoints frequently, rendering individual blocklists largely useless. Take down ten sites, and the operation has 1,990 fallbacks.


## Who's Actually Running This


"StopAndProtect" as a campaign name suggests organized operation rather than opportunistic spray-and-pray activity. The irony in the branding, the scale of the infrastructure build-out, and the dual-use design all point to actors who have done this before — who understand that the hard part of running a malware distribution network isn't writing the payload, it's building infrastructure that survives defender response.


The targeting profile would tell us a lot about attribution and motive, though campaigns at this scale often aren't picky. Mass WordPress exploitation tends to attract opportunistic operations — initial access brokers, infostealer distributors, ransomware affiliates looking to acquire victims at scale before a more targeted second stage. The data theft component suggests the operators are interested in credentials, session tokens, financial information, or some combination — intelligence that either has direct monetization value or enables the next phase of a larger operation.


## What WordPress Site Owners Don't Know


Here's the uncomfortable truth that rarely gets enough attention in coverage like this: most of those 2,000 compromised WordPress sites belong to people who have no idea they're participating in a criminal network.


The typical WordPress site owner isn't a system administrator. They installed a theme three years ago, set up WooCommerce, and haven't thought about it since. Their site is quietly hosting malware payloads while their visitors get quietly infected. Eventually they might notice a suspicious link injection in their homepage, or their host might suspend their account for abuse complaints, but by then the damage is done — and the attackers have already moved most of their operations to other nodes.


This is the externality that never gets properly priced into the WordPress ecosystem. The security costs of running outdated, unmaintained sites aren't borne by the site owners — they're distributed across every visitor who gets malware and every organization whose employees download an infected file.


---


## HackWire Analysis


StopAndProtect fits squarely into a threat pattern that's been accelerating over the past three years: legitimate infrastructure hijacking as a service delivery model. This isn't new — the Balada Injector campaign compromised over a million WordPress sites across multiple waves between 2017 and 2023, and SocGholish has been using compromised sites for drive-by downloads since at least 2018. What's changed is the sophistication of the dual-use deployment and the normalization of legitimate-site-as-C2 among a broader range of threat actors beyond just APT groups.


The specific timing matters here. We're watching an industry-wide failure to address the WordPress security debt problem. Wordfence, Sucuri, and Patchstack collectively publish hundreds of WordPress vulnerability disclosures every year. The plugin ecosystem cannot patch fast enough, and site owners cannot stay current. The attack surface isn't getting smaller.


For defenders, the priority shift should be clear: perimeter and reputation-based blocking is increasingly insufficient when the traffic comes from legitimate domains with clean histories. Endpoint detection, behavioral analysis of downloaded files, and network traffic inspection at the payload level — not the domain level — are the controls that catch this. Organizations should also audit their DNS and proxy logs for high-frequency connections to small, low-traffic websites that suddenly appear in outbound request patterns. That's often the tell.


For the hosting industry, this is overdue: hosting providers have the visibility and the leverage to detect compromised sites far earlier than anyone else. Automated scanning at the hosting layer — WordPress core integrity checks, plugin vulnerability matching, outbound connection monitoring — could dramatically shrink the available attack surface. Some hosts do this already. Most don't, because it's expensive and customers don't ask for it.


The 2,000-site network won't be the largest we see this year.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)