Criminal Group Uses Nearly 2,000 WordPress Blogs to Host Malware Stealing Crypto Wallet Seeds

TL;DR:
- The criminal group StopAndProtect used nearly 2,000 compromised WordPress blogs to distribute malware that steals crypto wallet seeds.
- The attack tricks Windows users with fake CAPTCHA pages that prompt them to run malicious PowerShell commands on their devices.
- Between May and July, the campaign infected more than 6,000 unique IP addresses and collected over 700 stolen data files from victims.
A criminal group identified by Check Point Research as StopAndProtect used nearly 2,000 poorly maintained WordPress sites to distribute Malware capable of stealing seeds from wallets, passwords and files from Windows computers. The details were published on August 18, after linking a ransomware sample detected in mid-May to an extortion and surveillance campaign.
What sets this operation apart from similar ones is the infrastructure used. Rather than renting or compromising their own servers, the attackers turned legitimate WordPress domains into platforms to host payloads, redirect instructions to malware-infected devices and store stolen files. Researcher Jaromír Hořejší noted that a single server can fulfill all those functions simultaneously, without the criminals spending a single cent.
… Continue reading the full article at the original source below.



