logo

StopCrypt: Most widely distributed ransomware evolves to evade detection

ID: d39d4fa6-a581-52ec-95e6-f187cb63ca78

STIX ID: report--d39d4fa6-a581-52ec-95e6-f187cb63ca78

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SonicWall and BleepingComputer report a newly-observed StopCrypt (STOP/Djvu) variant that uses a multi-stage execution chain—including shellcode, dynamically constructed API calls, process hollowing, delayed loops, and persistence via ACL changes and a scheduled task—to evade detection and encrypt user files (appending a ".msjd" extension) while leaving a "_readme.txt" ransom note; the campaign primarily targets consumers through malvertising and bundled adware, and researchers have noted concerns that the analyzed sample may be an older build.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.