Nearly 2,000 Hacked WordPress Sites Turned Into Malware Distribution Network
Security researchers have identified a widespread cybercrime campaign, dubbed StopAndProtect, that has compromised nearly 2,000 WordPress websites and repurposed them as criminal infrastructure. Rather than relying on a single piece of malware, the operation uses a broad toolkit of malicious software to infect visitors, take control of compromised systems, and store stolen data including documents, screenshots, and activity logs.
This campaign highlights a growing trend where attackers exploit legitimate but poorly secured websites to host and distribute malware, making detection harder since traffic often appears to come from trusted domains. For small businesses running WordPress sites, this means their website could unknowingly become part of a criminal network if left unpatched or poorly configured, damaging both their reputation and customer trust.
Businesses that rely on WordPress for their website should treat it as a critical piece of infrastructure requiring the same security diligence as any other business system. Regular updates, strong admin credentials, and monitoring for unusual activity are essential steps to avoid becoming an unwitting host for malware distribution.