Overview
- Researchers first observed the threat in mid-May 2026 and Check Point published a full technical report in August 2026 that publicly mapped the operation’s scale and techniques.
- The attack begins with a ClickFix fake‑CAPTCHA that instructs users to paste and run a PowerShell command outside the browser, which downloads stage one .NET loaders.
- Those loaders deploy a modular toolkit that includes a selective encryptor, an SMB/USB worm, a screen‑locker, a VBS spreader, a chat proxy and a stealer called SilentDataCollector that logs keystrokes and automates WhatsApp searches.
- Opsec mistakes exposed the infrastructure and gave researchers direct access to logs, about 31,000 screenshots, over 700 stolen‑data archives and text files listing close to 2,000 compromised WordPress domains tied to roughly 6,000 victim IPs.
- Check Point urges site owners to update WordPress and plugins, remove unexpected must‑use plugins, secure admin accounts with strong passwords and multi‑factor authentication, and warns users never to run commands requested by a webpage while endpoints should be monitored for suspicious PowerShell activity.