The StopAndProtect cybercrime operation has compromised nearly 2,000 poorly maintained WordPress websites to distribute malware, steal cryptocurrency wallet seeds, passwords and files, conduct surveillance, and deploy ransomware against Windows users. Check Point Research published details on August 18 after linking a ransomware sample first observed in mid-May 2026 to a broader extortion and surveillance campaign. By July 24, the operation had infected more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India. Visitors to hijacked sites encounter a fake CAPTCHA that directs them to copy and execute a PowerShell command, triggering .NET payloads that can extract saved passwords, wallet data and other files. The malware can also scan shared folders and USB drives, log keystrokes, take screenshots, collect WhatsApp contact information and encrypt computers for ransom. More than 700 archives of stolen files were identified between mid-May and the end of July, while an exposed directory contained more than 20,000 victim screenshots; an earlier account cited more than 31,000 screenshots, indicating a discrepancy in reported totals. The compromised WordPress sites serve as malware hosts, command-and-control infrastructure and storage for stolen data. Open directories, logs and source code exposed by the attackers gave researchers insight into the campaign's management tools and a list of nearly 2,000 hacked domains.