Description Summary
STOP (also known as Djvu) is by volume the most widely distributed ransomware in the world, overwhelmingly affecting home users. It spreads through cracked software, key generators, and adware bundles rather than targeted intrusions, and has produced hundreds of near-identical variants distinguished mainly by their file extensions. Emsisoft maintains a decryptor that recovers files encrypted with 'offline' keys; newer RSA-protected variants (after August 2019) are generally not decryptable.
Threat Actor
Financially-motivated operators; mass distribution via software cracks/keygens and adware bundles.
Technical Indicators
Encryption Extension
.djvu / .stop / hundreds of variants (e.g. .rumba, .gero, .promorad, .hlas)
Encryption Algorithm
Salsa20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
_readme.txt
Targeted Industries
Consumer / individuals (cross-sector)
First Seen
December 2018
Last Seen
Active
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 1 | T1189 | Drive-by Compromise (cracks/adware bundles) |
| Execution x 1 | T1204.002 | User Execution: Malicious File |
| Defense Evasion x 1 | T1027 | Obfuscated Files or Information |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |