Malware Named StopAndProtect Exploits Nearly 2,000 Compromised WordPress Sites to Steal Data

Malware Named StopAndProtect Exploits Nearly 2,000 Compromised WordPress Sites to Steal Data

A malicious campaign has taken over close to 2,000 WordPress websites to spread a data-stealing malware, putting site owners and visitors at risk.

A newly reported malware campaign is using a large network of hacked WordPress websites to spread malicious software and steal information. The operation involves a malware called StopAndProtect and has compromised nearly 2,000 WordPress sites. Each of those sites can serve as a launching point for the malware, meaning that visitors to an infected page may be exposed to data theft. For the owners of those sites, the compromise is often invisible at first, because the attackers do not always change the site's visible content.

WordPress is a content management system (CMS), a type of software that lets people build and manage websites without writing code from scratch. It powers a very large portion of websites on the internet, from personal blogs to business sites. Because it is so common, it is also a frequent target for criminals who look for security weaknesses. Many WordPress sites are run by individuals or small teams without dedicated security staff. Attackers often break in by exploiting outdated plugins, which are add-on features such as contact forms or image sliders, or by guessing weak administrator passwords. Once inside, they can plant malicious code that steals visitor data, redirects traffic to scam pages, or uses the server to send spam.

The reported StopAndProtect campaign shows how ordinary websites can become part of criminal infrastructure without their owners knowing. Nearly 2,000 compromised sites is a significant number because each one has its own audience and reputation, making the malicious activity harder to spot and block. Search engines and security tools frequently flag hacked sites, which can lead to browser warnings that scare away visitors and damage the site's search ranking. For a business, a hacked website can also mean loss of customer trust, potential fines for failing to protect data, and expensive cleanup work.

Website owners should treat this campaign as a reminder to review their own WordPress installations. The most common entry points are outdated core files, old themes, and plugins that are no longer maintained. Weak or reused passwords are another major problem, because attackers use automated tools to try thousands of common passwords against admin login pages. Enabling two-factor authentication, which asks for a second code from a phone after the password, can prevent many automated break-ins. Even a forgotten staging site or a subdomain with an old WordPress test installation can provide a way in. Regular, offsite backups are essential, because if a site is compromised, the fastest and cleanest recovery is often to restore a backup from before the infection and then immediately update all software to close the hole.

For those who do not want to handle security maintenance themselves, managed WordPress hosting can reduce the risk. A managed host typically takes care of routine updates, malware scanning, and basic security hardening, making it harder for attackers to hijack the site. AEU Hosting offers managed WordPress hosting that is secured end to end, which helps site owners keep their installations patched and monitored without deep technical effort. This does not eliminate the need for strong passwords and careful plugin choices, but it does shift much of the day to day security burden to professionals.

Site owners who suspect their WordPress site has been used in this or any other malware campaign should act quickly. Check the WordPress admin area for user accounts you did not create, look for recently modified files in the theme or plugin folders, and run a security scan with a reputable plugin. If you find signs of compromise, change all admin passwords, restore from a clean backup, update everything, and then inform your hosting provider. Visitors who encounter a site that suddenly shows unusual pop ups or redirects should leave the page and avoid entering any personal information.

How to Protect Yourself

  1. If you run a WordPress website, turn on automatic updates for WordPress itself, your theme, and all plugins so known security holes are fixed without you needing to act.
  2. Use a password manager to create a long, unique password for your website's admin area, and turn on two-step login if your site offers it.
  3. Make a full backup of your website at least weekly and store it somewhere separate, like cloud storage, so you can restore it if it is ever hacked.
  4. Install a well-known WordPress security plugin and set it to scan your site automatically each week for harmful code or unexpected file changes.
  5. Remove any plugins or themes you are not using, because each one is an extra door an attacker can try to open.
  6. If you visit websites and a page suddenly shows strange pop-ups or sends you to another site, close the tab and do not enter any personal information.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting