Fake CAPTCHA on Hacked WordPress Spreads Malware

The Hacker News · High sophistication
Last updated August 19, 2026

Researchers described a real cybercrime operation (“StopAndProtect”) that compromised nearly 2,000 WordPress sites and used them to show fake CAPTCHA pages that trick visitors into running malicious commands. Victims can end up with malware that steals files and screenshots and, in some cases, deploys ransomware and a lock screen. The campaign turns poorly maintained websites into a large-scale delivery network for data theft and extortion.

Key findings

  • The campaign used nearly 2,000 hacked WordPress sites as infrastructure to host malware stages, act as command-and-control (C2), and store stolen logs and documents.
  • Initial infection starts with a ClickFix-style fake CAPTCHA that tricks users into executing a PowerShell command, which pulls down additional malware stages.
  • The toolkit can include ransomware, a lock-screen extortion module, file and screenshot theft, and spreading mechanisms via network shares and removable media.
  • Researchers observed victims’ systems being surveilled and files selectively stolen even when ransomware was not deployed.
  • The attackers used a custom WordPress plugin and MU-plugin persistence to enable file uploads and hide traces by self-deleting.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security, Web/DevOps teams managing WordPress, Helpdesk.
  • Affected industries: Organizations running WordPress websites, Any organization whose employees browse the web on Windows endpoints.
  • Attack channels: website.
  • Impersonated: Website CAPTCHA / verification plugin.

Awareness takeaways

  • Teach staff to immediately leave any website that asks them to copy/paste or run commands (especially PowerShell) as part of a CAPTCHA or “verification.”
  • Emphasize that even “normal” websites can be weaponized; a familiar site layout does not mean it is safe if an overlay or verification prompt appears.
  • Reinforce patching and website hygiene for teams running WordPress, including keeping WordPress core and plugins updated to reduce the chance your site becomes part of an attacker’s infrastructure.

Red flags to watch for

  • A CAPTCHA asking you to copy/paste or run commands outside the browser
  • Unexpected verification overlay that replaces the site’s real content
  • Instructions specifically targeting Windows/PowerShell behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a normal WordPress site, then, boom, a full-page message: “Security check: Please complete the CAPTCHA to continue.” But this isn’t a real CAPTCHA. It’s a ClickFix-style trap from a hacked WordPress site, telling you to copy and run a PowerShell command to prove you’re human. If you run it, that PowerShell pulls down malware from a network of nearly 2,000 hacked WordPress sites, stealing files and screenshots, and in some cases triggering ransomware and a lock screen. Remember this: a CAPTCHA that asks you to copy, paste, or run any command, especially PowerShell, is fake. Close the tab immediately and walk away from that site.

Categories

Similar attacks

Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
Fake Cloudflare Check Tricks Users Into Running PowerShell

Fake Cloudflare Check Tricks Users Into Running PowerShell

Researchers observed real-world infections where compromised WordPress sites showed a fake “Cloudflare Turnstile” verification and instructed visitors to press Win+R and run a PowerShell command. The attacker’s page guides victims step-by-step (and reports progress back to the operator) to execute…

September 21, 2026
Fake CAPTCHA Trick Spreads StopAndProtect

Fake CAPTCHA Trick Spreads StopAndProtect

Researchers uncovered a large campaign called StopAndProtect that uses hacked WordPress sites to show visitors a fake CAPTCHA and trick them into running a PowerShell command. That one action kicks off a multi-stage infection that can encrypt files (ransomware), steal documents, passwords/wallet…

August 18, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
ClickFix Lures Turn Trusted Sites Into Malware Traps

ClickFix Lures Turn Trusted Sites Into Malware Traps

A CTM360 report describes real-world “ClickFix” campaigns where attackers compromise legitimate websites and show fake error/verification messages that trick users into copying a command and pasting it into trusted system tools (Run box, PowerShell, Terminal). This approach avoids traditional…

September 24, 2026
Fake Resumes + Watering Holes Hit AnySign4PC Users

Fake Resumes + Watering Holes Hit AnySign4PC Users

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download…

July 30, 2026