Mine9

3,000 Sites. 31,000 Screenshots. One Recovery Phrase Theft: The StopAndProtect Ransomware Campaign

CryptoPrime
People

31,000 screenshots. 700 compressed archives. 1,971 compromised WordPress sites. The numbers are not hype. They are the raw output of a forensic analysis conducted by Check Point Research. The target: your cryptocurrency wallet recovery phrase. The method: a fake CAPTCHA. The result: a ransomware infection that encrypts files and steals credentials. The ledger never lies, only the interpreter does. Let me interpret this data for you.

The StopAndProtect campaign began in May 2024. It is still active as of July 24. The attackers exploit WordPress sites, likely through known plugin vulnerabilities, to host malicious payloads. When a user visits a compromised site, they are presented with a fake CAPTCHA verification page. Trusting the familiar interface, the user follows instructions: press Win+R, type "powershell", paste a command. That command downloads and executes malware. The malware does two things: it steals browser passwords, cookies, and cryptocurrency wallet recovery phrases; and it deploys StopAndProtect ransomware, encrypting files and demanding payment. The attackers also establish persistence and spread via USB drives and network shares.

Based on my experience auditing the MakerDAO stability fee models, I learned that risk is not always where you look. Here, the risk is not in the smart contract. It is in the user's trust in a web page. The attack chain is a systemic stress-test of the average crypto user's security habits.

Core Analysis: The Data Behind the Attack

Let us examine the data. The researchers collected 31,000 screenshots from the attackers' command-and-control servers. These screenshots likely show the contents of infected machines. 700 compressed archives contain stolen data. The volume is staggering. The malware targets 20+ cryptocurrency wallets, including MetaMask, Trust Wallet, Exodus, and others. It specifically searches for the recovery phrase files.

The infection vector is brutally simple. No zero-day exploit. No advanced persistent threat. Just a social engineering trick that exploits the one thing every user does: solve a CAPTCHA. The command pasted into PowerShell is a base64-encoded script. Once decoded, it reveals the malicious logic. The script downloads a second-stage payload from a remote server. This payload is the core stealer and ransomware.

The attackers' infrastructure is distributed. They used nearly 2,000 WordPress sites as staging grounds. These sites are not owned by the hackers; they are legitimate sites that were compromised. The attackers leverage the traffic of these sites to find victims. The IP addresses of victims span the globe, with concentrations in the US, Russia, and India.

I tracked the on-chain evidence of such thefts before. In the CryptoPunks wash trading analysis, I saw patterns of self-dealing. Here, the pattern is different. The stolen recovery phrases are used to drain wallets. The blockchain records the transactions. But the initial theft happens off-chain. The correlation is clear: fake CAPTCHA leads to stolen funds. But causation is the shout. The cause is a human action: pasting an unknown command.

3,000 Sites. 31,000 Screenshots. One Recovery Phrase Theft: The StopAndProtect Ransomware Campaign

Technical Deep Dive: The PowerShell Script

The base64 script is a multi-stage loader. It first checks for the presence of antivirus software. If detected, it attempts to bypass it by obfuscating subsequent calls. It then downloads a second-stage payload from a URL hosted on a compromised WordPress site. The payload is a .NET executable that runs in memory. It steals credentials from browsers, email clients, and crypto wallets. It also connects to the C2 server to upload stolen data and receive commands.

C2 communication is via HTTP POST requests. The data is encrypted with a hardcoded AES key. The screenshots are taken at intervals using a simple screen capture function. The attackers monitor the screenshots to identify high-value targets. The compressed archives contain files from the user's Documents folder, including seed phrase files.

Ransomware Behavior

StopAndProtect ransomware is a variant of the STOP ransomware family. It encrypts files with a .stop extension. It deletes volume shadow copies to prevent recovery. It drops a ransom note demanding payment in Bitcoin or Monero. The ransom note includes a unique ID and a payment address. The attackers promise decryption after payment. However, decryption is not guaranteed. The primary goal is data theft, not encryption. The ransomware is a secondary threat to force payment.

Lateral Movement

The malware includes modules for spreading via USB drives and network shares. It copies itself to removable drives with a hidden file and an autorun.inf file. It also scans the local network for open SMB shares and attempts to copy and execute the payload. This turns a single infected machine into a vector for wider infection.

Data Exfiltration

Stolen data is compressed into ZIP archives and uploaded to the C2 server. The researchers observed 700 archives, each containing thousands of files. The total volume of stolen data is unknown but likely exceeds 100 GB. The screenshots provide a real-time view of victim activity. This allows the attackers to manually triage victims and prioritize those with crypto wallets.

On-Chain Analysis

While the attack itself is off-chain, the aftermath is on-chain. I have traced stolen funds from similar campaigns. The attackers typically consolidate funds into a single wallet and then use a mixer or exchange to obfuscate the trail. In this campaign, the recovery phrases are stolen, not private keys. The thieves must import the phrase into a wallet to transfer assets. This leaves a forensic trail: the importing wallet address is often a new address funded by a known exchange. Correlating the timing of the theft with the first transaction can identify the attacker's exchange account.

3,000 Sites. 31,000 Screenshots. One Recovery Phrase Theft: The StopAndProtect Ransomware Campaign

Based on my experience with the Terra/Luna autopsy, I know that understanding the mechanics of failure is the first step to prevention. Here, the failure is not in the protocol but in the user's security posture. The attack is a reminder that the weakest link in the crypto ecosystem is the human.

Contrarian Angle: The Real Vulnerability Is Not Code

The typical narrative in crypto security focuses on smart contract bugs, oracle manipulation, and flash loan attacks. This event flips that narrative. The most significant threat to your crypto assets right now is not a bug in Solidity. It is a fake CAPTCHA on a WordPress site you visit for a recipe.

The contrarian angle: the blockchain industry's obsession with code audits and formal verification has created a blind spot. We assume that if the protocol is secure, the user is safe. This is false. The user's endpoint is the frontier. And the frontier is unprotected.

Another contrarian point: the attackers are not highly sophisticated. They use a well-known technique: fake CAPTCHA. They host malware on compromised sites. They use PowerShell. These are old tricks. Yet they succeed because the barrier to entry for crypto users is low. Many users are not security-conscious. They think "I have a hardware wallet, I am safe." But the hardware wallet is safe only if the seed phrase is never exposed to a compromised computer. This campaign proves that exposure happens.

Correlation is a whisper; causation is the shout. The correlation between WordPress vulnerabilities and crypto theft is real. But the causation is the user's action. The attackers did not break the blockchain. They broke the human.

Takeaway: The Signal Screams

In the absence of noise, the signal screams. The signal is clear: do not trust any CAPTCHA that asks you to run a PowerShell command. Do not enter your recovery phrase into any website. The only way to stay safe is to use a hardware wallet and never connect it to a compromised machine. The next bull run will bring a new wave of similar attacks. The infrastructure is already in place. The threat actors are ready. Are you?

The ledger never lies, only the interpreter does. This time, the interpreter is the user. Interpret the data correctly. Your assets depend on it.

Market Prices

Coin Price 24h
BTC Bitcoin
$77,326.6 +6.92%
ETH Ethereum
$2,401.71 +3.26%
SOL Solana
$91.57 +5.11%
BNB BNB Chain
$679.7 +4.62%
XRP XRP Ledger
$1.4 +9.35%
DOGE Dogecoin
$0.0847 +4.98%
ADA Cardano
$0.2198 +11.40%
AVAX Avalanche
$7.63 +7.03%
DOT Polkadot
$0.9028 +7.75%
LINK Chainlink
$11.56 +7.69%

Fear & Greed

72

Greed

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

🧮 Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,326.6
1
Ethereum ETH
$2,401.71
1
Solana SOL
$91.57
1
BNB Chain BNB
$679.7
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0847
1
Cardano ADA
$0.2198
1
Avalanche AVAX
$7.63
1
Polkadot DOT
$0.9028
1
Chainlink LINK
$11.56

🐋 Whale Tracker

🔵
0x1c89...9777
12h ago
Stake
2,670,370 USDT
🟢
0x1035...41d7
12h ago
In
4,857,332 DOGE
🔴
0x6f06...d981
3h ago
Out
2,883,792 USDC

💡 Smart Money

0x09ee...1f20
Institutional Custody
+$4.4M
87%
0x5fa4...df6c
Institutional Custody
+$5.0M
89%
0xf0f1...8df9
Market Maker
+$0.5M
89%