Their Command-and-Control Layer Is Two Thousand Hacked Small Businesses. We Fed the Hashes and Refused to Blocklist a Single Domain — Here Is Why That Is Not Squeamishness.
- Patrick Duggan
- 4 minutes ago
- 6 min read
Check Point Research unmasked an operation called StopAndProtect on 19 August, and they got it the way you always eventually get someone: the operators made a mistake and left their own server readable.
The numbers are: roughly 2,000 hacked WordPress sites, 6,000-plus unique victim IP addresses, around 31,000 screenshots and 700-plus archives of stolen data, collected between mid-May and the end of July 2026.
We had zero attributed indicators for this campaign in our feed when we started writing. We have twenty-one now. And we deliberately did not ingest the ten domains, which is the part of this worth arguing about.
What the operation actually is
The entry point is ClickFix — the social-engineering trick where a webpage shows you a fake verification or error prompt and instructs you to paste a command into your own terminal or Run box. The user performs the compromise. No exploit, no vulnerability, no patch that would have helped.
From there it is a conveyor: hidden-window PowerShell with the execution policy bypassed, pulling a second PowerShell stage, which pulls a .NET downloader, which pulls a loader, which pulls the working set. The working set is not one piece of malware. It is a toolkit of six — an encryptor called SilentEncryptor, an SMB and USB worm called NetworkShareScanner, a VBS spreader, a LockScreen component, a credential stealer called SilentDataCollector, and a chat proxy so the operators can talk to their victims live.
That last one tells you what kind of operation this is. Somebody built a customer-support channel for extortion.
The structural thing: the infrastructure is the victims
Here is the part that changed how we handled the feed write.
The delivery sites are hacked WordPress installs. Fine, that is ordinary. But the base command-and-control servers are also hacked WordPress installs — a laser clinic, a parts business, a haulage firm, ordinary small companies whose sites got popped and are now, without their knowledge, running the C2 for a ransomware operation. And the stolen data from victims is uploaded back onto those same hacked sites, so the small business is unknowingly hosting other people's stolen documents on its own paid hosting.
One compromised estate, three jobs: delivery, C2, and storage. The operator's own capital expenditure is roughly zero. Everything they run, someone else is paying the hosting bill for.
So what do you actually put in a blocklist?
Our doctrine on this is fixed and it exists because it is easy to get wrong in the direction that feels productive.
Victims are not threats. If a hacked host lands in a blocklist that thousands of defenders consume, you have taken a small company's website off the internet for its own customers, on top of the compromise it already suffered. It will be down long after the attacker has moved on, because blocklists are quick to add and slow to forget. The company will likely never know why its traffic died.
So we made the split explicitly:
Fed to the feed — 21 records. Every published SHA-256: both PowerShell stages, three stage-one downloaders, three stage-two loaders, three encryptor builds, three worm builds, three lockscreens, the stealer, the VBS spreader, and both chat-proxy builds. Confidence 90, attributed to StopAndProtect, written under the campaign-specific source manual-batch-stopandprotect so this campaign is auditable later. A hash identifies the attacker's artifact. Blocking it cannot hurt a bystander — that is the whole property that makes a hash safe to distribute.
Deliberately not blocklisted — 10 domains. All ten, both the delivery sites and the C2 sites, because all ten are compromised legitimate businesses. We publish them as hunting context. If one appears in your proxy logs, that is worth investigating hard. That is a different act from shipping it to every consumer of our IP and domain blocklists as a thing to drop.
We also checked all ten against our corpus before deciding, and every single one came back with zero correlations — no cross-feed corroboration, nothing adjacent, nothing previously seen. They are clean small-business domains that got hijacked, which is exactly what the doctrine predicted and exactly why they stay out of the block.
If you are running a security operation rather than consuming a feed, use the domains. If you are a defender consuming a blocklist, take the hashes. The distinction is not fastidiousness — it is the difference between a feed that reduces harm and a feed that redistributes it.
The mistake that gave them up
The reason any of this is public is that an archive uploaded to the collection server did not come from a victim. It came from an operator's own desktop: source code, configuration files, a list of the roughly 2,000 compromised domains, and two project names — 0a_botnet and fake-captcha.
They infected themselves and shipped the evidence to their own exfiltration server.
It is funny, and it is worth resisting the urge to make that the whole story, because the operational lesson runs the other way. We wrote a piece a few days ago admitting that we found our own infrastructure inside our own incident data. Everybody who runs the tooling ends up inside the tooling eventually. The attacker's version of that mistake ended a global campaign's anonymity. The defender's version is usually just embarrassing. The difference in consequence is enormous and the difference in cause is nil.
Where we were, honestly
We did not catch this. Check Point did, and the credit is theirs — this post exists because they published a full indicator set rather than a teaser.
What we can say is where our corpus already stood. We ingested a ClickFix cluster from ReliaQuest's PowerShell-RAT research back in May 2026, which is the same window in which Check Point first spotted the StopAndProtect ransomware family. Those are almost certainly different clusters and we are not going to claim they are the same one — the honest statement is that the technique was in our feed while this campaign was ramping, and the campaign itself was not.
Zero attributed indicators on a live global operation, until today. That is the gap the audit exists to find. We closed it in the same session that found it, which is the only part of this we would defend.
Sources
StopAndProtect campaign research, indicator set, victim statistics and the operator self-infection detail: Check Point Research, published 19 August 2026, with follow-on coverage 19–24 August. The ClickFix technique and the ReliaQuest PowerShell-RAT cluster reference are from our own May 2026 coverage and our iocs index under source=reliaquest-clickfix-may2026.
The twenty-one hashes were written to our feed on 24 August 2026 under source=manual-batch-stopandprotect, each confirmed landed by primary-key read-back rather than by write acknowledgement — and one of them did not land on the first pass, was caught by that read-back, and was re-written. We then checked the artifact rather than the API: all twenty-one appear in the public hashes.csv, which currently carries 41,007 rows. A verified write is not a delivered product until you have pulled the file a customer would pull.
Capped at 95 percent: the indicator set is Check Point's, not ours, and we have no first-party observation of this campaign; the ~2,000 domain figure is from the operators' own leaked list and is a snapshot, not a live count; and hash-based blocking is the weakest form of blocking there is, because a recompile defeats it. Take the hashes as a retrospective hunt across your endpoint telemetry, not as a durable control.
If you run a small-business WordPress estate for clients, the useful move tonight is not to look for these domains — it is to check whether any site you manage is serving files it did not have last month. That is how all two thousand of these were found from the outside. Rate this post below.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=their-command-and-control-layer-is-two-thousand-hacked-small-businesses-we-fed-the-hashes-and-refus




Comments