Fake CAPTCHA on Hacked WordPress Spreads Malware

The Hacker News · High sophistication
Last updated August 19, 2026

Researchers described a real cybercrime operation (“StopAndProtect”) that compromised nearly 2,000 WordPress sites and used them to show fake CAPTCHA pages that trick visitors into running malicious commands. Victims can end up with malware that steals files and screenshots and, in some cases, deploys ransomware and a lock screen. The campaign turns poorly maintained websites into a large-scale delivery network for data theft and extortion.

Key findings

  • The campaign used nearly 2,000 hacked WordPress sites as infrastructure to host malware stages, act as command-and-control (C2), and store stolen logs and documents.
  • Initial infection starts with a ClickFix-style fake CAPTCHA that tricks users into executing a PowerShell command, which pulls down additional malware stages.
  • The toolkit can include ransomware, a lock-screen extortion module, file and screenshot theft, and spreading mechanisms via network shares and removable media.
  • Researchers observed victims’ systems being surveilled and files selectively stolen even when ransomware was not deployed.
  • The attackers used a custom WordPress plugin and MU-plugin persistence to enable file uploads and hide traces by self-deleting.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security, Web/DevOps teams managing WordPress, Helpdesk.
  • Affected industries: Organizations running WordPress websites, Any organization whose employees browse the web on Windows endpoints.
  • Attack channels: website.
  • Impersonated: Website CAPTCHA / verification plugin.

Awareness takeaways

  • Teach staff to immediately leave any website that asks them to copy/paste or run commands (especially PowerShell) as part of a CAPTCHA or “verification.”
  • Emphasize that even “normal” websites can be weaponized; a familiar site layout does not mean it is safe if an overlay or verification prompt appears.
  • Reinforce patching and website hygiene for teams running WordPress, including keeping WordPress core and plugins updated to reduce the chance your site becomes part of an attacker’s infrastructure.

Red flags to watch for

  • A CAPTCHA asking you to copy/paste or run commands outside the browser
  • Unexpected verification overlay that replaces the site’s real content
  • Instructions specifically targeting Windows/PowerShell behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a normal WordPress site, then, boom, a full-page message: “Security check: Please complete the CAPTCHA to continue.” But this isn’t a real CAPTCHA. It’s a ClickFix-style trap from a hacked WordPress site, telling you to copy and run a PowerShell command to prove you’re human. If you run it, that PowerShell pulls down malware from a network of nearly 2,000 hacked WordPress sites, stealing files and screenshots, and in some cases triggering ransomware and a lock screen. Remember this: a CAPTCHA that asks you to copy, paste, or run any command, especially PowerShell, is fake. Close the tab immediately and walk away from that site.

Categories

Similar attacks

Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
Fake CAPTCHA Trick Spreads StopAndProtect

Fake CAPTCHA Trick Spreads StopAndProtect

Researchers uncovered a large campaign called StopAndProtect that uses hacked WordPress sites to show visitors a fake CAPTCHA and trick them into running a PowerShell command. That one action kicks off a multi-stage infection that can encrypt files (ransomware), steal documents, passwords/wallet…

August 18, 2026
Fake Resumes + Watering Holes Hit AnySign4PC Users

Fake Resumes + Watering Holes Hit AnySign4PC Users

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download…

July 30, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026