logo

Resurgence of DJVU/STOP Ransomware Strain in the Wild (Part 2/2)

ID: 197038d1-2a2e-5cde-a892-9d909f824bb2

STIX ID: report--197038d1-2a2e-5cde-a892-9d909f824bb2

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2021-12-02

Date Updated: 2026-04-27

...
...

**Executive summary:** This report details the behaviour of the STOP/DJVU ransomware after process hollowing, including victim geolocation via an external API, command-line argument parsing and process enumeration, persistence mechanisms (registry Run key, scheduled tasks, use of icacls), and the conditions that trigger file encryption, plus operational evasions such as whitelisting certain country codes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.