LSN News › India

Technology · India Bureau

Nearly 2,000 WordPress Sites Hijacked for Malware Distribution

Cybercriminals have compromised thousands of WordPress websites in a coordinated campaign to establish infrastructure for spreading malware and stealing sensitive data. The sophisticated operation demonstrates the ongoing vulnerability of content management systems to large-scale exploitation.

LSN India · 24 August 2026

Nearly 2,000 WordPress Sites Hijacked for Malware Distribution

Security researchers have identified a major cybercrime operation dubbed StopAndProtect that successfully infiltrated approximately 2,000 WordPress websites, repurposing them as nodes in a malicious network. The compromised sites were converted into infrastructure capable of distributing malware, harvesting user credentials, and maintaining command-and-control systems for infected devices across multiple networks.

The campaign highlights the persistent risks facing website administrators who fail to implement adequate security protocols. WordPress, which powers a significant portion of websites globally, remains an attractive target for cybercriminals seeking to establish distributed networks for their illicit activities. The attackers exploited common vulnerabilities in outdated plugins, weak authentication mechanisms, and unpatched software installations.

Once compromised, the affected websites served as relay points for malware distribution and data exfiltration without the knowledge of their legitimate owners. The infrastructure enabled perpetrators to maintain anonymity while conducting their operations at scale, leveraging the legitimate hosting of thousands of compromised sites to evade detection by security systems.

Security experts advise website administrators to implement robust security measures including regular software updates, strong authentication protocols, and continuous monitoring for suspicious activity. Organizations managing WordPress installations are urged to conduct immediate security audits and remediation efforts to identify and expel any malicious code that may have been installed on their systems.