Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 21 hostnames
STOP, widely known as STOP/Djvu, is a Windows ransomware family first observed in late 2018 and notable for large-scale distribution through commodity malware ecosystems and illicit software channels.
Profile source: Mallory opens in a new tabStop
STOP, widely known as STOP/Djvu, is a Windows ransomware family first observed in late 2018 and notable for large-scale distribution through commodity malware ecosystems and illicit software channels. It encrypts victim files and appends variant-specific extensions, then drops a ransom note demanding payment for decryption. The family has been repeatedly associated with cracked software lures, untrusted software installers, and broader malware delivery operations in which loaders and stealers are deployed before ransomware execution. Observed distribution mechanisms include software cracks, fake installers, SEO-poisoned download sites, and XLL-based infection chains; it has also been delivered by other malware such as PrivateLoader and Retadup.
STOP/Djvu commonly uses a hybrid cryptographic design in which files are encrypted with a per-file symmetric key and that key is protected with RSA. Reporting also indicates the family can operate with either online keys retrieved from command-and-control infrastructure or embedded offline keys when connectivity is unavailable. In analyzed intrusions, STOP has executed after other payloads performed credential theft, browser-data theft, proxy-bot activity, coin mining, persistence establishment, and defense evasion, indicating that it is often the final monetization stage of a multi-payload compromise rather than the sole objective.
The malware establishes persistence and may execute after reboot before beginning encryption. It has been observed retrieving a public key from remote infrastructure, using autorun mechanisms, and marking encrypted files to avoid double encryption. In multi-stage campaigns such as those built around PrivateLoader, STOP/Djvu has appeared alongside Lumma, RedLine, RisePro, Amadey, Stealc, SmokeLoader, Vidar, and proxy or miner components. This placement reflects its role in commodity cybercrime operations that maximize revenue through theft, resource hijacking, and eventual file encryption.
Victimology is broad and global. Reporting from 2019 described more than 20,000 victims worldwide and ranked STOP among the more prevalent ransomware families in commodity distribution. Although not exclusive to any one sector, it has been discussed in the context of attacks affecting municipalities and other organizations, and its reliance on untrusted software sources makes both consumers and enterprise users vulnerable when pirated or trojanized software is executed on Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Samples
047e138efd0c8dbb52cc949ad66ffc45f4a64eeecd7d35fc2fa473495785fb1a 5760bf3dfa834dd40a2d43d948d7bb617014f6fd324bd8be6701e91f9176921f 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a 8684751f02d87ad7979218ee32929bd7d1dbad5f22dd78016f4d9d9144662ece 94ef48cdfeaf9733cab63ef0b640c506856ed636da5c6760ed6727a005657b19 0c0acbbbcd88b3dc0c39b9b564c2d50abdcfae9b20a9403e9c31698d2d6fd61c 41db2af800c560c4e3e75da1f5b5cb0c8fbf3bead448cab2147db691cc85fb3a 6d3e2b33028b585f5b97ad031c4fc38165bcfe09a765bab23d4a24f688871e52 7598f3bb6f3b745f15f23a3fc5bae2d660393ad0c84d1ecd466965c004f5789d b9f992a46caa3b898a960ceb13b8be215054e74d80b288de82b662c028faecb6 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.