
A large-scale malware operation called StopAndProtect is using compromised WordPress sites to distribute ransomware and steal credentials via deceptive ClickFix CAPTCHA prompts.
Researchers identified over 6,000 unique IP addresses linked to the campaign as of July 24, with the highest concentrations in the United States, Russia, and India.
The attackers utilize modular payloads, including the SilentEncryptor ransomware and SilentDataCollector, to exfiltrate data and monitor victims, with over 700 stolen data archives discovered on open directories.