Skip to content

Stop

STOP, widely known as STOP/Djvu, is a Windows ransomware family first observed in late 2018 and notable for large-scale distribution through commodity malware ecosystems and illicit software channels.

Profile source: Mallory opens in a new tab

Stop

Family profile

STOP, widely known as STOP/Djvu, is a Windows ransomware family first observed in late 2018 and notable for large-scale distribution through commodity malware ecosystems and illicit software channels. It encrypts victim files and appends variant-specific extensions, then drops a ransom note demanding payment for decryption. The family has been repeatedly associated with cracked software lures, untrusted software installers, and broader malware delivery operations in which loaders and stealers are deployed before ransomware execution. Observed distribution mechanisms include software cracks, fake installers, SEO-poisoned download sites, and XLL-based infection chains; it has also been delivered by other malware such as PrivateLoader and Retadup.

STOP/Djvu commonly uses a hybrid cryptographic design in which files are encrypted with a per-file symmetric key and that key is protected with RSA. Reporting also indicates the family can operate with either online keys retrieved from command-and-control infrastructure or embedded offline keys when connectivity is unavailable. In analyzed intrusions, STOP has executed after other payloads performed credential theft, browser-data theft, proxy-bot activity, coin mining, persistence establishment, and defense evasion, indicating that it is often the final monetization stage of a multi-payload compromise rather than the sole objective.

The malware establishes persistence and may execute after reboot before beginning encryption. It has been observed retrieving a public key from remote infrastructure, using autorun mechanisms, and marking encrypted files to avoid double encryption. In multi-stage campaigns such as those built around PrivateLoader, STOP/Djvu has appeared alongside Lumma, RedLine, RisePro, Amadey, Stealc, SmokeLoader, Vidar, and proxy or miner components. This placement reflects its role in commodity cybercrime operations that maximize revenue through theft, resource hijacking, and eventual file encryption.

Victimology is broad and global. Reporting from 2019 described more than 20,000 victims worldwide and ranked STOP among the more prevalent ransomware families in commodity distribution. Although not exclusive to any one sector, it has been discussed in the context of attacks affecting municipalities and other organizations, and its reliance on untrusted software sources makes both consumers and enterprise users vulnerable when pirated or trojanized software is executed on Windows systems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
1 IP / 21 hostnames

Leading locations

  • US6
  • DE1
  • NL1

Leading providers

  • Google LLC4
  • Amazon.com, Inc.1
  • Amazon.com, Inc.1
  • G-Core Labs S.A.1
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 8
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

Stop in ATT&CK

19 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.