A criminal group that Check Point Research has dubbed StopAndProtect has been using nearly 2,000 poorly maintained WordPress blogs to host malware that steals cryptocurrency wallet seeds, passwords, and files from infected Windows computers.
For crypto holders, the most alarming part is that the takeovers are distributed across legitimate sites that appear to be standard business blogs or sites.
Check Point published the details on August 18, having tied the ransomware sample it spotted in mid-May to a larger extortion and surveillance campaign.
Most malware campaigns these days are distributed from servers rented or compromised by the attackers. StopAndProtect takes a different route, said the researcher Jaromír Hořejší. Their ransomware, payloads, command-and-control infrastructure, and storage for stolen data are all hosted on WordPress domains that the criminals did not have to pay for or compromise.
This is the most interesting part of the campaign, Hořejší noted. One server can host the payload, redirect instructions to compromised computers, and store stolen files. According to Security Affairs, a hacked website is no longer just a hacked website. It can turn into a launchpad for attacks by other bad actors.
The sites are poorly maintained, as Hořejší’s team discovered when they decided to look at the WordPress instance behind one of the malicious domains. The researcher found nearly 40 different vulnerabilities in the software dating back to 2021.
Crypto holders should be especially wary of this threat. The phishing campaign tricks Windows users into believing that they need to complete a CAPTCHA test to gain access to a website. However, the CAPTCHA is actually a scam, and users who try to complete it will be instructed to copy and paste a PowerShell command into their command prompt.
This PowerShell command will then begin downloading .NET payloads that will allow the attacker to extract saved passwords, crypto wallet seeds, and other data from the compromised computer.
The malware can also copy files from shared network folders, USB drives, take screenshots of the infected computer, and even encrypt it and demand payment in ransomware. According to Decrypt, users should be wary of sites that prompt them to paste or type anything and leave the page as soon as they see such a request.
Crypto wallets are not the only target of this campaign. In many cases, the attackers are using the malware to steal files from the victim’s computer. According to reports, the threat actors are scanning the files on the infected computer and selecting the most interesting ones to steal.
The newer versions of the malware also have the ability to log keystrokes, take screenshots every 30 seconds, and even use WhatsApp to take photos of the victim’s contact list.
The most valuable intelligence on the StopAndProtect campaign came from the criminals’ own servers. The attackers had poor cybersecurity practices, leaving directories and log files open to the web. Check Point suspects that one of the attackers’ own computers had been compromised and that the criminal had accidentally uploaded some files to the server.
Among the files, Hořejší found the source code for an automation tool that the attackers were using to control the hacked websites.
The tool, written in legacy Visual Basic 6, allows the criminal to remotely toggle the CAPTCHA phishing page, redirect site visitors, and update the malware on the compromised sites. Text files attached to the tool also include a list of the nearly 2,000 domains that have been hacked and turned into phishing sites.
The log files also helped the researcher understand the scale of the attack. As of July 24, the campaign had already infected more than 6,000 unique IP addresses. Of these, 1,852 users were located in the United States, and 630 each in Russia and India.
Between mid-May and the end of July, researchers discovered more than 700 archives of stolen files. One of the open directories on the server contained more than 20,000 screenshots of victims’ computers.
The smartest crypto minds already read our newsletter. Want in? Join them.