{"id":4941,"date":"2026-08-23T14:28:32","date_gmt":"2026-08-23T14:28:32","guid":{"rendered":"https:\/\/justfineinfotech.com\/study-reveals-5000-computers-infected-via-wordpress-sites\/"},"modified":"2026-08-23T14:28:32","modified_gmt":"2026-08-23T14:28:32","slug":"study-reveals-5000-computers-infected-via-wordpress-sites","status":"publish","type":"post","link":"https:\/\/justfineinfotech.com\/fr\/study-reveals-5000-computers-infected-via-wordpress-sites\/","title":{"rendered":"Study reveals 5,000 computers infected via WordPress sites"},"content":{"rendered":"<figure>\n<img decoding=\"async\" src=\"https:\/\/justfineinfotech.com\/wp-content\/uploads\/2026\/08\/1413213_2243651_the-news-2026-08-22T185705_101_updates.jpg\" alt=\"Study reveals 5,000 computers infected via WordPress sites\"><figcaption>Study reveals 5,000 computers infected via WordPress sites<\/figcaption><\/figure>\n<p>Check Point Research has uncovered a global cybercrime operation that quietly ran its entire infrastructure through nearly 2,000 hacked WordPress websites<\/p>\n<p>The investigation, known as StopAndProtect, traced a network of more than 5,000 infected computers worldwide back to a toolkit of malware hosted on compromised, otherwise ordinary WordPress domains<\/p>\n<h2>Why did WordPress make such an easy target?<\/h2>\n<p>WordPress is the most extensively used content management system today, as it controls about 43% of websites worldwide. However, what makes WordPress accessible is that the CMS can be easily installed because of installation scripts and web builder plug-ins<\/p>\n<p>According to the researchers, the owners of the ring were able to hijack legitimate websites through exploitation of vulnerabilities of both the core WordPress installation and third-party plug-ins and use them for their own criminal purposes without creating any suspicious infrastructure<\/p>\n<p>The attack chain starts with a misleading CAPTCHA message presented to visitors on the compromised website through social engineering exploitation called ClickFix, which forces the victim to copy and execute a harmful PowerShell command himself<\/p>\n<p>Subsequently, multiple downloaders are used to deliver a whole kit of cybercriminals&#8217; <a href=\"https:\/\/justfineinfotech.com\/fr\/shopify-stock-and-2-cloud-software-picks-retail-investors-are-watching\/\" title=\"Shopify Stock And 2 Cloud Software Picks Retail Investors Are Watching\">software<\/a> instead of one type of malware, namely, SilentEncryptor ransomware, a worm that scans the network, a screenlocker, and a stealer that is capable of stealing credentials and cryptocurrency wallets<\/p>\n<p>As Eli Smadja from Check Point stated, &#8220;how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.&#8221;<\/p>\n<p>The StopAndProtect name was initially coined by Check Point for the ransomware part of the attack only after they first observed the malware in May 2026<\/p>\n<p>The name was later extended to refer to the whole process once researchers figured out that not all victims were subjected to a ransomware attack but some attackers stealthily stole particular files based on reconnaissance<\/p>\n<p>The investigation itself only became possible because the criminals made mistakes. Exposed servers and open directory listings let researchers inspect victim logs, screenshots, internal management tools, and source code the attackers used to control hijacked domains at scale, including one instance where an operator appears to have infected their own machine and accidentally uploaded internal development files.<\/p>\n<p>Among the compromised sites, Check Point identified one running a WordPress installation more than five years out of date, carrying roughly 40 unresolved vulnerabilities<\/p>\n<p>Smadja urged organisations to treat unexpected CAPTCHA prompts asking them to copy, paste, or run commands as a red flag and to leave immediately any site requesting unusual steps outside the browser.\u00a0<\/p>\n<p>Partagez cette histoire\u00a0:<br \/>\n<a href=\"https:\/\/www.google.com\/preferences\/source?q=thenews.com.pk\" rel=\"nofollow noopener\" target=\"_blank\">Rendez-nous favoris sur Google<\/a><\/p>\n<div style=\"clear:both;margin:30px 0 15px 0\">\n<p>\n    <strong>En rapport:<\/strong><br \/>\n    <a href=\"https:\/\/yoursite.com\/automation-training-benin\/\" title=\"Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026\" target=\"_blank\" rel=\"noopener\"><br \/>\n      Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026<br \/>\n    <\/a>\n  <\/p>\n<p>\n    <a href=\"https:\/\/yoursite.com\/automation-africa\/\" title=\"Automatisation du marketing WhatsApp en Afrique\u00a0: 6 erreurs dangereuses commises par les marques au Nig\u00e9ria\" target=\"_blank\" rel=\"noopener\"><br \/>\n      Automatisation du marketing WhatsApp en Afrique\u00a0: 6 erreurs dangereuses commises par les marques au Nig\u00e9ria<br \/>\n    <\/a>\n  <\/p>\n<\/div>\n<div style=\"clear:both;margin:30px 0;padding:25px;background:#f8f9fc;border:1px solid #ddd;border-radius:8px;text-align:center\">\n<h3>Vous souhaitez apprendre cela de mani\u00e8re pratique ?<\/h3>\n<p>Rejoindre <strong>Justfine Infotech<\/strong> et d\u00e9velopper de v\u00e9ritables comp\u00e9tences num\u00e9riques en IA, automatisation, d\u00e9veloppement web, marketing digital, bureautique, e-commerce, <a href=\"https:\/\/justfineinfotech.com\/fr\/freelancing-can-provide-livelihood-opportunities-for-youth-pafla-chief\/\" title=\"Le travail ind\u00e9pendant peut offrir des opportunit\u00e9s de revenus aux jeunes\u00a0: chef de Pafla\">travail ind\u00e9pendant<\/a> et <a href=\"https:\/\/justfineinfotech.com\/fr\/40-teams-gather-in-hong-kong-to-compete-in-the-ai-x-cybersecurity-challenge-macau-business\/\" title=\"40 \u00e9quipes r\u00e9unies \u00e0 Hong Kong pour participer au &quot;\u00a0D\u00e9fi IA x Cybers\u00e9curit\u00e9\u00a0&quot; | Macau Business\">cybers\u00e9curit\u00e9<\/a>.<\/p>\n<p><strong>Programmes disponibles :<\/strong><br \/>\n  Certificat de 6 semaines \u2022 Certificat professionnel de 3 mois \u2022 Dipl\u00f4me de 6 mois \u2022 Dipl\u00f4me professionnel complet<\/p>\n<p><strong>WhatsApp :<\/strong><br \/>\n  +229 01 57 57 99 15<br \/>\n  +229 01 66 68 11 60<\/p>\n<p><a href=\"https:\/\/api.whatsapp.com\/send?phone=2348132690270&amp;text=Hello\" target=\"_blank\" rel=\"noopener\">Inscrivez-vous d\u00e8s maintenant<\/a><\/p>\n<\/div>\n<p class=\"ani-source\">Source: <a href=\"https:\/\/www.thenews.com.pk\/latest\/1413213-study-reveals-5000-computers-infected-via-wordpress-sites\" target=\"_blank\" rel=\"nofollow noopener\">www.thenews.com.pk<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Check Point Research has uncovered a global cybercrime operation that quietly ran its entire infrastructure through nearly 2,000 hacked WordPress websites<\/p>","protected":false},"author":1,"featured_media":4944,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[72],"tags":[1401,1402,1403,407,321],"class_list":["post-4941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress-seo-smart-websites","tag-1401","tag-computers","tag-infected","tag-reveals","tag-study"],"_links":{"self":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/4941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/comments?post=4941"}],"version-history":[{"count":1,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/4941\/revisions"}],"predecessor-version":[{"id":4943,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/4941\/revisions\/4943"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media\/4944"}],"wp:attachment":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media?parent=4941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/categories?post=4941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/tags?post=4941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}