STOP, widely known as STOP/Djvu, is a Windows ransomware family first observed in late 2018 and notable for large-scale distribution through commodity malware ecosystems and illicit software channels. It encrypts victim files and appends variant-specific extensions, then drops a ransom note demanding payment for decryption. The family has been repeatedly associated with cracked software lures, untrusted software installers, and broader malware delivery operations in which loaders and stealers are deployed before ransomware execution. Observed distribution mechanisms include software cracks, fake installers, SEO-poisoned download sites, and XLL-based infection chains; it has also been delivered by other malware such as PrivateLoader and Retadup.
STOP/Djvu commonly uses a hybrid cryptographic design in which files are encrypted with a per-file symmetric key and that key is protected with RSA. Reporting also indicates the family can operate with either online keys retrieved from command-and-control infrastructure or embedded offline keys when connectivity is unavailable. In analyzed intrusions, STOP has executed after other payloads performed credential theft, browser-data theft, proxy-bot activity, coin mining, persistence establishment, and defense evasion, indicating that it is often the final monetization stage of a multi-payload compromise rather than the sole objective.
The malware establishes persistence and may execute after reboot before beginning encryption. It has been observed retrieving a public key from remote infrastructure, using autorun mechanisms, and marking encrypted files to avoid double encryption. In multi-stage campaigns such as those built around PrivateLoader, STOP/Djvu has appeared alongside Lumma, RedLine, RisePro, Amadey, Stealc, SmokeLoader, Vidar, and proxy or miner components. This placement reflects its role in commodity cybercrime operations that maximize revenue through theft, resource hijacking, and eventual file encryption.
Victimology is broad and global. Reporting from 2019 described more than 20,000 victims worldwide and ranked STOP among the more prevalent ransomware families in commodity distribution. Although not exclusive to any one sector, it has been discussed in the context of attacks affecting municipalities and other organizations, and its reliance on untrusted software sources makes both consumers and enterprise users vulnerable when pirated or trojanized software is executed on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
This executable will also execute a PowerShell script called Script.ps1, which disabled Windows Defender's real-time monitoring using this command: Set-MpPreference -DisableRealtimeMonitoring $true
The authors chose to distribute their malware primarily through software installers. When users try to download specific software from an untrusted site or try to use software cracks, instead of the desired result their machines become infected by the ransomware.
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
The authors chose to distribute their malware primarily through software installers. When users try to download specific software from an untrusted site or try to use software cracks, instead of the desired result their machines become infected by the ransomware.
Process 4440 is also seen communicating with its C2 server, 185[.]216.70.235 and 195.20.16[.]45 via port 80 (T1071 – Application Layer Protocol).
When these cracks are installed, the main installer will be installed as %LocalAppData%\[guid]\[random].exe and executed. This program is the main ransomware component and will first download the following files to the same folder: %LocalAppData%\[guid]\1.exe %LocalAppData%\[guid]\2.exe %LocalAppData%\[guid]\3.exe %LocalAppData%\[guid]\updatewin.exe
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware distributed through fake cracked-software installers and malicious download chains.
A ransomware family identified in related samples associated with the broader set of files discussed in the analysis.
Referenced as one of the malware families in the case; STOP is the ransomware component in the broader infection chain.
Ransomware family that encrypts files and demands payment for decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.