<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>StopAndProtect Ransomware (Encryptor) on CyberVeille</title>
    <link>https://cyberveille.ch/tags/stopandprotect-ransomware-encryptor/</link>
    <description>Recent content in StopAndProtect Ransomware (Encryptor) on CyberVeille</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>fr-fr</language>
    <copyright>Cyberveille CC BY-NC-SA 4.0</copyright>
    <lastBuildDate>Thu, 20 Aug 2026 00:00:00 +0200</lastBuildDate>
    <atom:link href="https://cyberveille.ch/tags/stopandprotect-ransomware-encryptor/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>StopAndProtect : des milliers de sites WordPress détournés en infrastructure C2 de ransomware</title>
      <link>https://cyberveille.ch/posts/2026-08-20-stopandprotect-des-milliers-de-sites-wordpress-detournes-en-infrastructure-c2-de-ransomware/</link>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0200</pubDate>
      <guid>https://cyberveille.ch/posts/2026-08-20-stopandprotect-des-milliers-de-sites-wordpress-detournes-en-infrastructure-c2-de-ransomware/</guid>
      <description>&lt;p&gt;📰 &lt;strong&gt;Source&lt;/strong&gt; : CybersecurityNews.com, basé sur un rapport de Check Point Research, publié le 18 août 2026.&lt;/p&gt;
&lt;h2 id=&#34;contexte&#34;&gt;Contexte&lt;/h2&gt;
&lt;p&gt;Une campagne malveillante nommée &lt;strong&gt;StopAndProtect&lt;/strong&gt; a été découverte, transformant des milliers de sites &lt;strong&gt;WordPress&lt;/strong&gt; piratés en infrastructure &lt;strong&gt;C2 (command-and-control)&lt;/strong&gt; distribuée. L&amp;rsquo;opération combine &lt;strong&gt;ransomware à double extorsion&lt;/strong&gt; et &lt;strong&gt;vol de données&lt;/strong&gt; ciblant des entreprises à l&amp;rsquo;échelle mondiale.&lt;/p&gt;
&lt;h2 id=&#34;vecteur-dinfection&#34;&gt;Vecteur d&amp;rsquo;infection&lt;/h2&gt;
&lt;p&gt;Le vecteur initial repose sur des &lt;strong&gt;leurres CAPTCHA frauduleux&lt;/strong&gt; injectés dans des sites WordPress vulnérables. Les visiteurs sont invités à copier-coller une &lt;strong&gt;commande PowerShell malveillante&lt;/strong&gt; dans leur terminal, déclenchant une chaîne d&amp;rsquo;infection multi-étapes.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
