Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

2026-08-19T20:52:18Zc6db11dc0d827d4d81efbf5eb6273c3ace6863a055eca725093333bfd4f0c102
AI-assisted malwareCavern ManticoreClickFixCloudflare Code ModeCloudflare WorkersIran-linked APTMOISNorth Korea-linked activityOilRigOperation Dream JobPowerShellStopAndProtectWordPress compromisebrowser-only ransomwarecommand-and-controldata breachmemory corruptionransomwaresocial engineeringthreat intelligenceworkerdzero-day

What happened

Check Point Research reporting from July–August 2026 covers ransomware operations, including StopAndProtect’s ClickFix-driven infection chain targeting thousands of compromised WordPress sites, browser-only ransomware techniques, and broader ransomware activity. Additional reporting details an Iran-linked Cavern Manticore modular C2 framework targeting Israeli IT providers and government organizations, an Operation Dream Job campaign targeting aerospace and defense sectors via weaponized PDF viewers and a zero-day exploit, five memory-corruption vulnerabilities in Cloudflare workerd affectingい

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
c6db11dc0d827d4d81efbf5eb6273c3ace6863a055eca725093333bfd4f0c102
Enrichment time
2026-08-19T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect · Baitaphish