StopCrypt: Most widely distributed ransomware evolves to evade detection
ID: d39d4fa6-a581-52ec-95e6-f187cb63ca78
STIX ID: report--d39d4fa6-a581-52ec-95e6-f187cb63ca78
Feed Name: Bleeping Computer
SonicWall and BleepingComputer report a newly-observed StopCrypt (STOP/Djvu) variant that uses a multi-stage execution chain—including shellcode, dynamically constructed API calls, process hollowing, delayed loops, and persistence via ACL changes and a scheduled task—to evade detection and encrypt user files (appending a ".msjd" extension) while leaving a "_readme.txt" ransom note; the campaign primarily targets consumers through malvertising and bundled adware, and researchers have noted concerns that the analyzed sample may be an older build.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
