Netskope Threat Labs

StopCrypt

ATP Sandbox Adv. HeuristicsAV

StopCrypt refers to detections of the STOP ransomware family (a.k.a. Djvu), one of the most widely distributed ransomware strains of recent years. It typically reaches victims through malvertising, fake software cracks, and trojanized installers, encrypts files with a hybrid scheme, and demands payment, and its builders have produced hundreds of variant builds over its long history.

First seen
March 2022
Last seen
October 2026
Stopcrypt
Alert Name
ByteCode-MSIL.Ransomware.Stopcrypt
ByteCode-MSIL.Ransomware.StopCrypt
Trojan.Ransom.StopCrypt.A
Trojan.Ransom.StopCrypt.I
Win32.Ransomware.Stopcrypt
Win32.Ransomware.StopCrypt
Win32.Trojan.Stopcrypt
Win32.Trojan.StopCrypt
Win64.Ransomware.StopCrypt
Win64.Trojan.StopCrypt