The StopAndProtect operation has compromised nearly 2,000 WordPress websites to distribute malware, steal crypto wallet files, and deploy ransomware. The attack uses fake CAPTCHA prompts that trick victims into running malicious PowerShell commands on their own machines. Over 6,000 unique IP addresses have been infected, including 1,852 in the US, 630 in Russia, and 630 in India. Check Point Research accessed more than 31,000 screenshots and up to 700 archives of stolen data from the attackers’ infrastructure. The malware specifically targets crypto wallet files, making this a direct threat against digital asset holders.
Source: Read the original article

