logo

Resurgence of DJVU/STOP Ransomware Strain in the Wild (Part 1/2)

ID: 9e3c737b-dcda-5c66-bf15-e1054a173b31

STIX ID: report--9e3c737b-dcda-5c66-bf15-e1054a173b31

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2021-12-01

Date Updated: 2026-04-27

...
...

This blog provides a technical analysis of the DJVU/STOP ransomware family, describing a multi-stage infection chain in which a loader allocates executable memory, stages primary and secondary shellcode, resolves Win32 APIs dynamically, and performs process hollowing to inject a ransomware crypter that encrypts files and drops ransom notes; the report also notes widespread distribution via cracked software and adware bundles and promises a follow-up analyzing the crypter payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.