STOP ransomware is a Windows-targeting ransomware family used to encrypt victim files and extort payment for recovery. It has been widely observed in large-scale distribution campaigns and is notably associated with infections originating from trojanized or cracked software installers. The family has also been described as based on an open-source ransomware platform.
In addition to file encryption, STOP has been observed performing environment checks, establishing persistence, and communicating with command-and-control infrastructure to obtain encryption material. Reported persistence mechanisms include copying itself into a user-profile application data location, creating autorun execution, and scheduling recurring task execution. Some observed variants also modify file access controls as part of their execution flow.
STOP has also demonstrated secondary payload delivery behavior. In documented campaigns, it was deployed after earlier-stage commodity malware infections and then used to fetch or facilitate installation of additional malware, including information stealers and trojans. This makes STOP relevant not only as an extortion payload but also as part of broader criminal monetization chains combining credential and data theft, cryptomining, and ransomware.
The malware has been seen in mass campaigns as well as more targeted activity, with broad victimization across geographies. Distribution has been strongly linked to cracked-software ecosystems, where users seeking pirated commercial software are infected with bundled malware that later leads to STOP deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
STOP creates a RUN registry key and a scheduled task to execute itself every five minutes... The dropper also creates an XML file in %TEMP% named SystemCheck.xml along with a scheduled task SystemCheck that runs the XML file every minute.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts files, establishes persistence, contacts C2 for encryption keys, and downloads additional payloads including other malware such as Vidar.
STOP ransomware is a widely distributed ransomware strain, accounting for a significant portion of mass ransomware campaigns in 2023. Operators have shifted from mass distribution to more targeted attacks.
STOP Ransomware is mentioned as an additional infection observed on one victim system, using the .mpaj extension, though its connection to the analyzed installer or MBR locker is unconfirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.