Check Point Research revealed that a number of the hijacked WordPress sites were built into a malicious software distribution network to steal data, monitor victims and place extortion software. According to the researchers, this action was related to the TopAndProtec extortion software family and the targets included passwords, documents and encrypted wallet notes and wallet files.

Nearly 2,000 hijacked sites detected

The report indicates that the site not only carries malicious procedures, but also functions such as issuing instructions and stealing data storage. The attack process usually starts with a fake authentication page that induces Windows users to perform a PowerShell command and then installs multiple malicious programs in the equipment.

These procedures are divided between theft of vouchers, collection of files, locking of screens, proliferation between networks and USB equipment and the eventual deployment of extortion software. According to researchers, this is not a single horse, but a set of criminal instruments that work in concert.

Over 6000 IPs

As of 24 July, researchers had recorded more than 6000 independent IP addresses affected, of which 1852 were in the United States and 630 were in Russia and India. Check Point also found a large number of infection logs, victim equipment intercepts and stolen data compressors in the exposure catalogue.

  • Over 6000 victims
  • U.S. affected IP number 1852
  • Over 31,000 screenshots collected

According to its disclosure, the research team collected more than 31,000 screenshots between mid-May and the end of July, as well as more than 700 data compressors, including documents, passwords and encrypted wallet-related documents.

The assailant's error exposed the internal tools.

Check Point stated that the attackers had failed in their operational safety, resulting in the release of internal documents, infection logs and bulk management tools for hijacked websites. As a result, researchers were able to more clearly restore their mode of operation and to estimate the size of the affected domain under their control.

The researchers also believe that the attackers may have misdirected the malicious program into their own equipment, as one of the stolen data packages contained unusual documents. This detail helped the research team to further identify the attack chain.

CrickFix, this year, it's been happening a lot.

The report mentions that this type of CrickFix method, which induces users to carry out orders manually by falsifying the authentication code, has appeared in several attacks this year. Microsoft researchers this month also warned that hackers were distributing malicious software using hijacked websites and BNB Chain smart contracts.

Previously, the attacks had been disseminated through ads on X platforms and other websites, including browser data, message badges and encrypted wallets. For encrypted users, the immediate risk of such attacks lies in the theft of assistive words, wallet documents and account documents.