📰 Source : CybersecurityNews.com, basé sur un rapport de Check Point Research, publié le 18 août 2026.
Contexte
Une campagne malveillante nommée StopAndProtect a été découverte, transformant des milliers de sites WordPress piratés en infrastructure C2 (command-and-control) distribuée. L’opération combine ransomware à double extorsion et vol de données ciblant des entreprises à l’échelle mondiale.
Vecteur d’infection
Le vecteur initial repose sur des leurres CAPTCHA frauduleux injectés dans des sites WordPress vulnérables. Les visiteurs sont invités à copier-coller une commande PowerShell malveillante dans leur terminal, déclenchant une chaîne d’infection multi-étapes.
Chaîne d’infection
La séquence d’infection se déroule en plusieurs étapes :
- Étape 1 : Scripts PowerShell (stages 1 et 2) et loaders .NET modulaires
- Étape 2 : Déploiement d’un toolkit complet comprenant :
- 🔒 Ransomware (encrypteur)
- 🕵️ Credential stealer
- 🖥️ Screen locker
- 🐛 VBS spreader
- 🔌 SMB/USB worm
- 💬 Chat utility (exfiltration de données WhatsApp notamment)
Capacités de collecte de renseignement
Avant tout déploiement de ransomware, les opérateurs procèdent à :
- Énumération de documents
- Keylogging
- Cartographie des partages réseau
- Captures d’écran périodiques
- Scraping de données de communication locales
Infrastructure
- ~2 000 domaines WordPress compromis utilisés comme C2 rotatifs
- +6 000 adresses IP victimes uniques identifiées via des logs exposés
- Concentrations d’infections : États-Unis, Russie, Inde
- Des endpoints PHP exposés et des listings de répertoires ouverts ont permis aux chercheurs d’accéder aux logs internes, à la télémétrie et au code source
- Un opérateur a infecté sa propre machine, exposant des fichiers de développement incluant un outil Visual Basic 6 de gestion de masse des domaines WordPress compromis
Facteur aggravant
Un site analysé n’avait pas été mis à jour depuis 2021, exposant près de 40 vulnérabilités non corrigées. Les CMS non maintenus et les plugins obsolètes constituent des backdoors persistantes.
Type d’article
Publication de recherche / analyse technique issue d’une investigation de Check Point Research, visant à documenter une opération cybercriminelle active et à fournir des IOCs exploitables.
🧠 TTPs et IOCs détectés
TTP
- T1566 — Phishing (Initial Access)
- T1204.002 — User Execution: Malicious File (Execution)
- T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
- T1059.005 — Command and Scripting Interpreter: Visual Basic (Execution)
- T1486 — Data Encrypted for Impact (Impact)
- T1056.001 — Input Capture: Keylogging (Collection)
- T1113 — Screen Capture (Collection)
- T1083 — File and Directory Discovery (Discovery)
- T1021.002 — Remote Services: SMB/Windows Admin Shares (Lateral Movement)
- T1091 — Replication Through Removable Media (Lateral Movement)
- T1555 — Credentials from Password Stores (Credential Access)
- T1041 — Exfiltration Over C2 Channel (Exfiltration)
- T1584.004 — Compromise Infrastructure: Server (Resource Development)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
IOC
- Domaines :
maximumrock.ro— VT · URLhaus · ThreatFox - Domaines :
platinumcar.ca— VT · URLhaus · ThreatFox - Domaines :
norakremer.co.uk— VT · URLhaus · ThreatFox - Domaines :
pharmart.ae— VT · URLhaus · ThreatFox - Domaines :
ksr-racingparts.com— VT · URLhaus · ThreatFox - Domaines :
v-k.com.ua— VT · URLhaus · ThreatFox - Domaines :
www.lapellelaser.pl— VT · URLhaus · ThreatFox - Domaines :
www.parsrulman.com— VT · URLhaus · ThreatFox - Domaines :
mectcalcutta.com— VT · URLhaus · ThreatFox - Domaines :
discherniation.com— VT · URLhaus · ThreatFox - SHA256 :
cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0— VT · MalwareBazaar - SHA256 :
cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9— VT · MalwareBazaar - SHA256 :
99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b— VT · MalwareBazaar - SHA256 :
8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5— VT · MalwareBazaar - SHA256 :
4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504— VT · MalwareBazaar - SHA256 :
9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527— VT · MalwareBazaar - SHA256 :
7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c— VT · MalwareBazaar - SHA256 :
976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153— VT · MalwareBazaar - SHA256 :
b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489— VT · MalwareBazaar - SHA256 :
65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143— VT · MalwareBazaar - SHA256 :
0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40— VT · MalwareBazaar - SHA256 :
8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4— VT · MalwareBazaar - SHA256 :
10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0— VT · MalwareBazaar - SHA256 :
f042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41— VT · MalwareBazaar - SHA256 :
11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e— VT · MalwareBazaar - SHA256 :
2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c— VT · MalwareBazaar - SHA256 :
38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9— VT · MalwareBazaar - SHA256 :
23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70— VT · MalwareBazaar - SHA256 :
b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad— VT · MalwareBazaar - SHA256 :
3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9— VT · MalwareBazaar - SHA256 :
3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8— VT · MalwareBazaar
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 20 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- StopAndProtect (other)
- StopAndProtect Ransomware (encryptor) (ransomware)
- StopAndProtect Credential Stealer (stealer)
- StopAndProtect Screen Locker (other)
- StopAndProtect VBS Spreader (other)
- StopAndProtect SMB/USB Worm (other)
- StopAndProtect Chat Utility (other)
- StopAndProtect .NET Loader (loader)
🟡 Indice de vérification factuelle : 60/100 (moyenne)
- ⬜ cybersecuritynews.com — source non référencée (0pts)
- ✅ 8496 chars — texte complet (15pts)
- ✅ 31 IOCs dont des hashes (15pts)
- ✅ 6/6 IOCs confirmés (MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 14 TTPs MITRE identifiées (15pts)
- ⬜ date RSS ou approximée (0pts)
- ⬜ aucun acteur de menace nommé (0pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
cab7f141fd6f2c58…(sha256) → VT (29/76 détections)cc8aa2bd7bf74ca0…(sha256) → VT (28/76 détections)99bcb531d6dd3c93…(sha256) → VT (41/76 détections)maximumrock.ro(domain) → VT (5/91 détections)platinumcar.ca(domain) → VT (9/91 détections)
🔗 Source originale : https://cybersecuritynews.com/wordpress-sites-stopandprotect-malware/