Cybersecurity
Unveiling StopAndProtect: Massive cybercriminal blunder exposes internal network
Operational failures uncover global network behind 5,000+ compromised devices and 2,000 websites
- Interpol cracks down on global cyber fraud and West Africa’s organised crime money laundering
- Tech-armed crime: Europol warns AI and encryption are giving villains the edge
- 1
The Arctic Draws the Line with the Great Powers: Cooperation, Yes; Subordination, No
- 2
A Gripen crashes in Hungary—the same fighter jet Thailand’s queen wants to fly
- 3
Costa Rica takes on drug cartels, purges its police force and classifies its operations as state secrets
- 4
Post-Quantum cryptography is a present business risk requiring action
- 5
Unveiling StopAndProtect: Massive cybercriminal blunder exposes internal network
- Antonio Bustos
- Expert in Defense, Security and Terrorism.
- Published on
31 August 2026 at 07:15
The StopAndProtect operation was exposed after a series of operational security errors committed by the attackers themselves, allowing investigators access to victim records, screenshots,chers from the cybersecurity company Check Point Software Technologies Ltd. have published their findings on the internal workings of this cybercrime organization
This analysis reconstructs how a modern criminal infrastructure is organized from the inside, not from the victims’ perspective. The campaign, which affected more than 5,000 infected computers worldwide, employed nearly 2,000 compromised WordPress domains as a means to distribute malware and manage the operation.
The vulnerabilities of WordPress
It is particularly noteworthy that StopAndProtect avoided using traditional command and control servers. Instead, the operators enabled a distributed infrastructure by leveraging thousands of vulnerable WordPress websitesto conceal their activity among legitimate internet traffic and make detection more difficult.
The compromised sites performed different functions throughout the attack cycle: hosting and distributing malware, delivering additional malicious payloads, communicating with infected systems, and storing stolen documents, screenshots, and activity logs. This strategy turns seemingly innocuous web pages into fundamental pieces of a resilient and scalable criminal network.
WordPress representsmore than 43% of the global content management market in 2026, a popularity that makes it an especially attractive target for cybercriminals looking to operate on a large scale without deploying their own infrastructure.
The entry point
The investigation also highlights a persistent problem for companies and web administrators: the lack of updates for applications and plugins. During the analysis, Check Point Research found a compromised site that was still running a version of WordPress released in 2021, accumulating nearly 40 known vulnerabilities. The case illustrates how a single neglected page can end up being part of an international criminal operation without its owner being aware of it.
The researchers warn that thousands of installations continue to operate with outdated software, expanding the attack surface available to groups specializing in compromising legitimate websites.
The cybercriminals’ weak points
The partial downfall of StopAndProtect was not due to a technical vulnerability but rather a chain of human errors. The operators exposed internal files containing critical information about their infrastructure, including administrative tools, operational logs, and evidence of compromised victims.
Analysts estimate that such failures demonstrate that even the most sophisticated criminal organizations depend on the correct management of their own operational security. A single oversight can provide investigators with exceptional visibility into their operations and accelerate the identification of their methods and resources.
The entry point
Become a premium member for free!
You may be interested in
- CybersecurityInterpol cracks down on global cyber fraud and West Africa’s organised crime money launderingAlberto Payo
- CybersecurityTech-armed crime: Europol warns AI and encryption are giving villains the edgeAntonio M. Figueras
- CybersecurityCyberattack paralyzes part of Boston Scientific operations, disrupting medical device shipmentsAlberto Payo
- CybersecurityTech giants call for a united front to bolster global cybersecurity against AI-driven attacksAntonio Bustos
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 2) { //TIEMPO
var respuesta =
“No ha pasado aún un minuto desde tu último comentario. Espera un poco y podrás comentar de nuevo una noticia.
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 3) { //PALABROTA
var respuesta = “Por favor, utiliza un lenguaje correcto para comentar las noticias.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else { //NO LOGUEADO
var respuesta =
“Lo sentimos, al parecer no tienes una sesión iniciada. Vuelve a Iniciar Sesión y podrás publicar este comentario.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarPositivo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘positivo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var likes = parseInt($(“#like_” + id_comentario + ” span”).text());
$(“#like_” + id_comentario + ” span”).text(parseInt(likes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarNegativo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘negativo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var dislikes = parseInt($(“#dislike_” + id_comentario + ” span”).text());
$(“#dislike_” + id_comentario + ” span”).text(parseInt(dislikes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function recargar_widgets_sesion() {
recargar_cabecero_sesion();
recargar_menu_sesion();
recargar_comentar_sesion();
recargar_comentar_comentar();
comprobar_user_sesion_215_articulo(0);
}
function iniciarSesion() {
var continuar = true;
var msg = “”;
var usuario_log = $(“#usuario_log”).val();
var password_log = $(“#password_log”).val();
var valor_periodico = $(‘#valor_periodico’).val();
// console.log(valor_periodico);
if (usuario_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico n”;
}
if (password_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar la contraseña.n”;
}
if (continuar) {
$.ajax({
type: “POST”,
data: $(“#formulario_login”).serialize(),
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/login-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
// console.log(data);
if (data == 1) {
recargar_widgets_sesion();
$(“#modal-login .modal-action.modal-close.close-btn”).trigger(“click”);
$(“#usuario_log”).val(“”);
$(“#password_log”).val(“”);
if (window.location.href.includes(“area-usuario”)) {
// window.location.reload();
}
} else {
var respuesta =
“No hemos encontrado ningún usuario con el correo electrónico y la contraseña introducidos. Por favor, vuelve a intentarlo o recupera la contraseña pulsando el botón inferior.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function comprobar_user_sesion_215_articulo(es_premium) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
} else {
// $(“#art-cuerpo-visible”).removeClass(“art-cuerpo-visible”);
// $(“#art-cuerpo-visible”).addClass(“art-cuerpo-no-visible”);
if (es_premium) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“d-none”);
$(“#art-cuerpo-visible-premium”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“d-none”);
$(“#banner-premium”).removeClass(“d-none”);
} else {
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
}
}
}
});
}
function comprobar_user_sesion_215() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(‘.col-comparador-registro-login’).addClass(‘w-auto’)
} else {
$(‘.col-comparador-registro-login’).removeClass(‘w-auto’)
}
}
});
}
function cerrarSesion() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/delete-session-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
recargar_widgets_sesion();
$(“#offCanvasClose”).trigger(“click”);
if (window.location.href.includes(“area-usuario”)) {
window.location.href = ‘/’;
}
}
});
}
function registrarCuenta() {
var continuar = true;
var msg = “”;
var email_registro = $(“#email_reg”).val();
var pass_registro = $(“#password_reg”).val();
var pass_registro2 = $(“#password_reg_2”).val();
var nombre_registro = $(“#nombre_reg”).val();
var apellidos_registro = $(“#apellidos_reg”).val();
var ref_id_periodico = $(“#ref_id_periodico”).val();
if (pass_registro2 != pass_registro) {
continuar = false;
msg += “Deben coincidir ambas contraseñas. n”;
}
if (email_registro.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico. n”;
}
// if (pass_registro.length < 8) {
// continuar = false;
// msg += “Cal omplir la contrasenya amb un mínim de 8 caràcters. n”;
// }
if (nombre_registro.length == 0) {
continuar = false;
msg += “Hay que llenar el nombre. n”;
}
if (!$(“#aceptopoliticas”).is(“:checked”)) {
continuar = false;
if (ref_id_periodico == 8) {
msg += “You must accept the privacy policy. n”;
} else {
msg += “Debes aceptar la política de privacidad. n”;
}
}
if (continuar) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(“#formulario_registro”).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/register-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
if (data == 0) {
var respuesta = “Este correo electrónico ya está registrado.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else {
var respuesta = “¡Enhorabuena! Te has registrado con éxito.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
recargar_widgets_sesion();
$(“#email_reg”).val(“”);
$(“#password_reg”).val(“”);
$(“#nombre_reg”).val(“”);
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function recuperarPass() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#formulario_recuperarpass’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/reset-pass-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
var respuesta =
“Revisa tu e-mail y sigue las instrucciones para recuperar tu contraseña.”;
Swal.fire({
text: respuesta,
icon: “info”
});
$(“#modal-pass .modal-action.modal-close”).trigger(“click”);
$(“email_recuperar”).val(“”);
}
});
}
function resetearPass() {
if ($(“#nuevo-pass”).val() == $(“#nuevo-pass-repeat”).val()) {
if ($(“#nuevo-pass”).val().length >= 8) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#resetear-clave’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/resetear-pass.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
$(“#email_recuperar”).val(“”);
var respuesta = “La contraseña se ha actualizado. Ya puedes volver a Iniciar Sesión.”;
Swal.fire({
text: respuesta,
icon: “success”
}).then((result) => {
window.location.href = ‘http://www.escudodigital.com/’;
});
}
});
} else {
var respuesta = “La contraseña debe tener un mínimo de 8 caracteres.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
} else {
var respuesta = “Ambas contraseñas deben coincidir.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
$(document).ready(function() {
recargar_widgets_sesion(); //DESCOMENTAR ESTO
});
‘)
.text(msg)
.insertAfter($el);
}
function esEmailValido(email) {
return /^[^s@]+@[^s@]+.[^s@]{2,}$/.test(String(email).trim());
}
function validar() {
limpiarErrores();
let ok = true;
const $nombre = $(“#nombre”);
const $email = $(“#email”);
const $motivo = $(“#motivo”);
const $check = $(“#checkbox”);
const nombre = $nombre.val().trim();
const email = $email.val().trim();
const motivo = $motivo.val().trim();
if (nombre.length < 2) {
marcarError($nombre, “Enter your full name.”);
ok = false;
}
if (!esEmailValido(email)) {
marcarError($email, “Enter a valid email.”);
ok = false;
}
if (motivo.length < 5) {
marcarError($motivo, “Briefly explain how we can help you.”);
ok = false;
}
if (!$check.is(“:checked”)) {
marcarError($check, “You must accept the legal terms.”);
ok = false;
}
return ok;
}
function setLoading(isLoading) {
$btn.prop(“disabled”, isLoading);
$btn.text(isLoading ? “Sending…” : “Sent”);
}
function submitFormWithToken(token) {
setLoading(true);
const payload = {
nombre: $(“#nombre”).val().trim(),
email: $(“#email”).val().trim(),
motivo: $(“#motivo”).val().trim(),
legal: $(“#checkbox”).is(“:checked”) ? 1 : 0,
periodico_id_periodico: 8,
periodico: ‘www.escudodigital.com’,
url: window.location.href,
periodico_nombre: ‘DigitalShield’,
token: token
};
$.ajax({
url: URL_ENDPOINT,
method: “POST”,
data: payload,
dataType: “json” // Expects JSON response from server
})
.done(function(res) {
if (res && (res === 1 || res === “1” || res.ok)) {
$(“#msgFormContacto”).html(‘Message sent successfully.
‘);
$form[0].reset();
} else {
$(“#msgFormContacto”).html(‘Message not sent. Try again.
‘);
}
})
.fail(function(xhr) {
$(“#msgFormContacto”).html(‘Connection error. Try again.
‘);
})
.always(function() {
setLoading(false);
});
}
$btn.on(“click”, function(e) {
e.preventDefault();
e.stopPropagation(); // Stop default button behavior if any
if (!validar()) return;
// Execute reCAPTCHA
if (window.grecaptcha) {
grecaptcha.ready(function() {
grecaptcha.execute(RECAPTCHA_SITE_KEY, {
action: ‘submit’
}).then(function(token) {
submitFormWithToken(token);
});
});
} else {
// Fallback or error if grecaptcha not loaded
alert(“reCAPTCHA not loaded. Please refresh.”);
}
});
$(“#nombre,#email,#motivo,#checkbox”).on(“input change”, function() {
$(this).removeClass(“is-invalid”);
$(this).next(“.error-text”).remove();
});
});
