logo

StopCrypt: Most widely distributed ransomware now evades detection

ID: d1e6186b-7e76-59cc-b8c3-47c9b4e47260

STIX ID: report--d1e6186b-7e76-59cc-b8c3-47c9b4e47260

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SonicWall researchers reported a new multi-stage variant of the StopCrypt (STOP/Djvu) ransomware that employs shellcodes, stack-built API calls, process hollowing, delayed loops, and persistence via ACL changes and scheduled tasks; it encrypts files (adding a .msjd extension) and drops _readme.txt ransom notes. The operation primarily targets consumers via malvertising and bundled adware, producing many low-dollar ransom demands rather than large enterprise extortion, and researchers later noted some analyzed samples may have been older while confirming the described tactics remain relevant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.