More Than 1,650 Sites Identified in Seven-Week Campaign
Attackers have compromised more than 1,650 legitimate websites, many belonging to small and midsized businesses running WordPress, and turned them into distribution points for malware designed to steal cryptocurrency wallets and other sensitive data from Mac users.
Security researchers at Ransom-ISAC disclosed the campaign on Sept. 17 after tracking it since July 28. Visitors selected by the malicious code are shown a convincing fake “Bot Protection” verification page that imitates Google’s reCAPTCHA interface.
Instead of completing a normal browser challenge, Mac users are instructed to open Terminal and paste a command supposedly required to prove they are human.
Following those instructions installs Atomic macOS Stealer, commonly known as AMOS, an information-stealing malware family built to collect cryptocurrency wallets and seed phrases, browser passwords and cookies, macOS Keychain contents, password-manager data and other credentials.
The campaign uses a social-engineering technique known as ClickFix. Rather than exploiting the visitor’s browser directly or asking them to download an obvious executable file, the attacker persuades the victim to run the malicious command themselves.
That allows the infection flow to sidestep some protections designed around conventional file downloads.
Ransom-ISAC said the final AMOS payload targets wallet software including Exodus, Electrum, MetaMask, Phantom, Keplr and Rabby, alongside software associated with hardware wallets.
The focus on wallet credentials makes the operation particularly relevant to users of self-custodial cryptocurrency wallets, where possession of a recovery phrase or private-key material can give an attacker direct control over assets without requiring access to a centralized exchange account.
Previous incidents have shown how quickly exposed wallet credentials can become financially consequential. A recent Trezor phishing campaign used a malicious verification file designed to capture recovery phrases, demonstrating that attackers increasingly target the user controlling the wallet rather than trying to break the wallet’s cryptography.
Malicious Code Disguises Itself as Google Analytics
The WordPress campaign is notable for how effectively it hides inside otherwise legitimate websites.
Ransom-ISAC found that compromised pages load a small malicious script designed to resemble a Google Analytics component. In many cases, the injected tag even uses a name intended to look like an analytics tracker.
The loader then checks the visitor’s browser before deciding whether to display the malicious verification page.
Known bots, crawlers and automated security scanners are filtered out. Ordinary desktop users can instead receive the fake challenge, which is available in 14 languages.
This creates a problem for website owners and security companies because an automated inspection may see a page that appears normal while a real visitor receives malicious content.
Ransom-ISAC said some compromised websites remained infected for weeks.
The researchers identified more than 1,650 distinct affected sites during the seven-week tracking period and stressed that this was a minimum figure because the dataset only included websites visible through the scanning sources they monitored.
The infection rate among tracked sites remained between roughly 20% and 34% during much of the campaign before rising to 37% and 39% during the two most recent scanning rounds.
The infrastructure behind the operation has also moved rapidly.
Researchers recorded 154 command-and-control hostnames over seven weeks. By Sept. 16, 121 of those hostnames were still resolving, with 120 pointing to infrastructure associated with NetCrafters OU or Aeza Group.
The constantly rotating domains mean simple blocklists can quickly become outdated. Ransom-ISAC instead recommends detecting the structural characteristics of the injected loader, which have remained more consistent than the domains serving it.
The pattern resembles a broader security problem recently visible across the crypto sector: attackers increasingly compromise trusted infrastructure rather than relying exclusively on obviously fake websites.
The recent Brevo breach, for example, allowed malicious cryptocurrency-related emails to travel through legitimate marketing infrastructure. In the latest campaign, attackers are instead borrowing the trust of legitimate websites themselves.
Researchers Have Not Identified One WordPress Vulnerability
The most important unanswered question is how the attackers are gaining access to so many websites.
Ransom-ISAC assesses that the malicious script was injected through vulnerable WordPress themes or plugins and maps the initial access to exploitation of a public-facing application.
But the researchers have not identified one common plugin, theme or vulnerability responsible for the campaign.
That distinction is important.
If a single widely used WordPress component is being exploited, one vulnerability could provide attackers with a scalable distribution network across thousands of otherwise unrelated websites.
If the affected sites instead contain different outdated plugins, stolen administrator credentials or unrelated weaknesses, the campaign is primarily demonstrating how easily attackers can aggregate individually compromised sites into one malware-delivery system.
The current research does not establish which explanation is correct.
Ransom-ISAC’s report focuses mainly on mapping the attacker infrastructure and infection chain rather than conducting a forensic investigation of how every WordPress installation was initially compromised.
That leaves the initial-access mechanism as the strongest area for further investigation.
The case also echoes previous crypto incidents where the most important weakness was found in surrounding off-chain infrastructure rather than the blockchain or cryptographic component users naturally assumed attackers would target.
Once AMOS reaches a Mac, the consequences can extend well beyond one login. Stolen browser sessions may allow account access without a fresh password entry, while Keychain data, wallet credentials and recovery material can create multiple routes toward financial theft.
Cases involving unauthorized wallet transfers also illustrate why reconstructing the initial compromise can become difficult after crypto has moved: a valid blockchain transaction may show that somebody obtained signing authority without revealing whether the underlying cause was malware, phishing, an exposed seed phrase or another device compromise.
The Dangerous Part Is That the Website Can Be Real
This campaign changes one of the assumptions people normally make about malicious websites.
The victim does not necessarily arrive at an obviously misspelled crypto domain.
They can visit a legitimate small business website they have used before.
The business itself may not even realize it has been compromised.
That is a much stronger distribution model for malware because the attacker gets to borrow an existing site’s domain history, search visibility and reputation instead of building trust from zero.
The fake bot check then takes advantage of another behavior users have learned online: websites routinely ask people to prove they are human.
Most people have clicked enough CAPTCHAs that another verification screen barely registers as unusual.
The attack becomes suspicious only when the supposed verification process moves outside the browser and tells a user to open Terminal.
That should be the hard boundary.
A legitimate CAPTCHA does not need a visitor to execute commands on their computer.
The larger issue for WordPress operators is more complicated.
Updating plugins and themes is obvious advice, but it is not yet enough to explain this campaign because no single vulnerable component has been identified. The researchers’ findings suggest site owners also need to look for unexpected scripts inside page source and avoid assuming that an automated malware scanner will necessarily see what a normal visitor sees.
The bot-filtering element is particularly clever. Security scanners and search crawlers are exactly the systems most likely to discover a mass website compromise. Excluding them lets an infected page maintain two identities: clean for automated inspection and malicious for selected humans.
That could help explain why some sites remained compromised for weeks.
There is also an uncomfortable crypto-security lesson here.
Self-custody removes the risk that an exchange controls the user’s assets, but it concentrates the value of the user’s own device and credentials. An AMOS infection does not need to compromise Bitcoin, Ethereum or a hardware-wallet protocol if it can steal the information a person uses to control those systems.
This is why malware campaigns increasingly target browsers, password managers and wallet software together. The attack surface is the user’s digital identity rather than one specific cryptocurrency.
The infrastructure numbers suggest the operation is designed for persistence rather than a brief hit-and-run campaign. More than 150 command-and-control hostnames and rising infection rates after seven weeks indicate that taking down individual malicious domains is unlikely to solve the problem on its own.
The more consequential discovery would be the WordPress entry point.
If researchers can identify one common vulnerable plugin or theme across a meaningful share of the 1,650-plus sites, the story changes from a broad website-compromise campaign into a potentially systemic software-supply problem.
If they cannot, the conclusion may be almost as important: attackers have become efficient enough at compromising ordinary WordPress installations that they can assemble hundreds or thousands of unrelated websites into a distributed malware-delivery network without relying on one zero-day vulnerability.
Either way, the websites are only the delivery layer.
The real target is sitting in front of them: a Mac user whose browser, passwords and cryptocurrency wallets become accessible after one fake bot check convinces them to run the wrong command.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

