📰 Source : CybersecurityNews.com, basé sur un rapport de Check Point Research, publié le 18 août 2026.

Contexte

Une campagne malveillante nommée StopAndProtect a été découverte, transformant des milliers de sites WordPress piratés en infrastructure C2 (command-and-control) distribuée. L’opération combine ransomware à double extorsion et vol de données ciblant des entreprises à l’échelle mondiale.

Vecteur d’infection

Le vecteur initial repose sur des leurres CAPTCHA frauduleux injectés dans des sites WordPress vulnérables. Les visiteurs sont invités à copier-coller une commande PowerShell malveillante dans leur terminal, déclenchant une chaîne d’infection multi-étapes.

Chaîne d’infection

La séquence d’infection se déroule en plusieurs étapes :

  • Étape 1 : Scripts PowerShell (stages 1 et 2) et loaders .NET modulaires
  • Étape 2 : Déploiement d’un toolkit complet comprenant :
    • 🔒 Ransomware (encrypteur)
    • 🕵️ Credential stealer
    • 🖥️ Screen locker
    • 🐛 VBS spreader
    • 🔌 SMB/USB worm
    • 💬 Chat utility (exfiltration de données WhatsApp notamment)

Capacités de collecte de renseignement

Avant tout déploiement de ransomware, les opérateurs procèdent à :

  • Énumération de documents
  • Keylogging
  • Cartographie des partages réseau
  • Captures d’écran périodiques
  • Scraping de données de communication locales

Infrastructure

  • ~2 000 domaines WordPress compromis utilisés comme C2 rotatifs
  • +6 000 adresses IP victimes uniques identifiées via des logs exposés
  • Concentrations d’infections : États-Unis, Russie, Inde
  • Des endpoints PHP exposés et des listings de répertoires ouverts ont permis aux chercheurs d’accéder aux logs internes, à la télémétrie et au code source
  • Un opérateur a infecté sa propre machine, exposant des fichiers de développement incluant un outil Visual Basic 6 de gestion de masse des domaines WordPress compromis

Facteur aggravant

Un site analysé n’avait pas été mis à jour depuis 2021, exposant près de 40 vulnérabilités non corrigées. Les CMS non maintenus et les plugins obsolètes constituent des backdoors persistantes.

Type d’article

Publication de recherche / analyse technique issue d’une investigation de Check Point Research, visant à documenter une opération cybercriminelle active et à fournir des IOCs exploitables.

🧠 TTPs et IOCs détectés

TTP

  • T1566 — Phishing (Initial Access)
  • T1204.002 — User Execution: Malicious File (Execution)
  • T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
  • T1059.005 — Command and Scripting Interpreter: Visual Basic (Execution)
  • T1486 — Data Encrypted for Impact (Impact)
  • T1056.001 — Input Capture: Keylogging (Collection)
  • T1113 — Screen Capture (Collection)
  • T1083 — File and Directory Discovery (Discovery)
  • T1021.002 — Remote Services: SMB/Windows Admin Shares (Lateral Movement)
  • T1091 — Replication Through Removable Media (Lateral Movement)
  • T1555 — Credentials from Password Stores (Credential Access)
  • T1041 — Exfiltration Over C2 Channel (Exfiltration)
  • T1584.004 — Compromise Infrastructure: Server (Resource Development)
  • T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)

IOC

  • Domaines : maximumrock.roVT · URLhaus · ThreatFox
  • Domaines : platinumcar.caVT · URLhaus · ThreatFox
  • Domaines : norakremer.co.ukVT · URLhaus · ThreatFox
  • Domaines : pharmart.aeVT · URLhaus · ThreatFox
  • Domaines : ksr-racingparts.comVT · URLhaus · ThreatFox
  • Domaines : v-k.com.uaVT · URLhaus · ThreatFox
  • Domaines : www.lapellelaser.plVT · URLhaus · ThreatFox
  • Domaines : www.parsrulman.comVT · URLhaus · ThreatFox
  • Domaines : mectcalcutta.comVT · URLhaus · ThreatFox
  • Domaines : discherniation.comVT · URLhaus · ThreatFox
  • SHA256 : cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0VT · MalwareBazaar
  • SHA256 : cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9VT · MalwareBazaar
  • SHA256 : 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940bVT · MalwareBazaar
  • SHA256 : 8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5VT · MalwareBazaar
  • SHA256 : 4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504VT · MalwareBazaar
  • SHA256 : 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527VT · MalwareBazaar
  • SHA256 : 7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20cVT · MalwareBazaar
  • SHA256 : 976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153VT · MalwareBazaar
  • SHA256 : b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489VT · MalwareBazaar
  • SHA256 : 65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143VT · MalwareBazaar
  • SHA256 : 0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40VT · MalwareBazaar
  • SHA256 : 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4VT · MalwareBazaar
  • SHA256 : 10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0VT · MalwareBazaar
  • SHA256 : f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41VT · MalwareBazaar
  • SHA256 : 11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42eVT · MalwareBazaar
  • SHA256 : 2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68cVT · MalwareBazaar
  • SHA256 : 38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9VT · MalwareBazaar
  • SHA256 : 23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70VT · MalwareBazaar
  • SHA256 : b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08adVT · MalwareBazaar
  • SHA256 : 3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9VT · MalwareBazaar
  • SHA256 : 3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8VT · MalwareBazaar

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 20 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • StopAndProtect (other)
  • StopAndProtect Ransomware (encryptor) (ransomware)
  • StopAndProtect Credential Stealer (stealer)
  • StopAndProtect Screen Locker (other)
  • StopAndProtect VBS Spreader (other)
  • StopAndProtect SMB/USB Worm (other)
  • StopAndProtect Chat Utility (other)
  • StopAndProtect .NET Loader (loader)

🟡 Indice de vérification factuelle : 60/100 (moyenne)

  • ⬜ cybersecuritynews.com — source non référencée (0pts)
  • ✅ 8496 chars — texte complet (15pts)
  • ✅ 31 IOCs dont des hashes (15pts)
  • ✅ 6/6 IOCs confirmés (MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 14 TTPs MITRE identifiées (15pts)
  • ⬜ date RSS ou approximée (0pts)
  • ⬜ aucun acteur de menace nommé (0pts)
  • ⬜ pas de CVE à vérifier (0pts)

IOCs confirmés externellement :

  • cab7f141fd6f2c58… (sha256) → VT (29/76 détections)
  • cc8aa2bd7bf74ca0… (sha256) → VT (28/76 détections)
  • 99bcb531d6dd3c93… (sha256) → VT (41/76 détections)
  • maximumrock.ro (domain) → VT (5/91 détections)
  • platinumcar.ca (domain) → VT (9/91 détections)

🔗 Source originale : https://cybersecuritynews.com/wordpress-sites-stopandprotect-malware/

🖴 Archive : https://web.archive.org/web/20260819074615/https://cybersecuritynews.com/wordpress-sites-stopandprotect-malware/