Hackers set traps on over 2,000 hacked WordPress sites for crypto users

A criminal group that Check Point Research has dubbed StopAndProtect has been using nearly 2,000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seeds, passwords, and files from infected Windows computers.
For crypto holders, the most alarming part is that the takeovers are distributed across legitimate sites that appear to be standard business blogs or sites.
Check Point published the details on August 18, having tied the ransomware sample it spotted in mid-May to a larger extortion and surveillance campaign.
Why is the hosting the story
Most malware campaigns these days are distributed from servers rented or compromised by the attackers. StopAndProtect takes a different route, said the researcher Jaromír Hořejší. Their ransomware, payloads, command-and-control infrastructure, and storage for stolen data are all hosted on WordPress domains that the criminals did not have to pay for or compromise.
This is the most interesting part of the campaign, Hořejší noted. One server can host the payload, redirect instructions to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can turn into a launchpad for attacks by other bad actors.
… Continue reading the full article at the original source below.
