STOP (Djvu) Ransomware

Description Summary

STOP (also known as Djvu) is by volume the most widely distributed ransomware in the world, overwhelmingly affecting home users. It spreads through cracked software, key generators, and adware bundles rather than targeted intrusions, and has produced hundreds of near-identical variants distinguished mainly by their file extensions. Emsisoft maintains a decryptor that recovers files encrypted with 'offline' keys; newer RSA-protected variants (after August 2019) are generally not decryptable.

Threat Actor

Financially-motivated operators; mass distribution via software cracks/keygens and adware bundles.

Technical Indicators

Encryption Extension
.djvu / .stop / hundreds of variants (e.g. .rumba, .gero, .promorad, .hlas)
Encryption Algorithm
Salsa20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
_readme.txt
Targeted Industries
Consumer / individuals (cross-sector)
First Seen
December 2018
Last Seen
Active
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 1 T1189 Drive-by Compromise (cracks/adware bundles)
Execution x 1 T1204.002 User Execution: Malicious File
Defense Evasion x 1 T1027 Obfuscated Files or Information
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery