SimpleChatProxy is a custom victim-operator chat component used in the StopAndProtect cybercrime operation. It is deployed as part of the operation’s stage-three payload set alongside the SilentEncryptor ransomware, the SilentDataCollector stealer, propagation modules for SMB, USB, and removable media, and a lock-screen component. Its purpose is to provide a direct communication channel between an infected victim and the operator, supporting the campaign’s hands-on-keyboard style of intrusion and extortion activity.
The broader StopAndProtect operation relies on compromised WordPress sites as distributed infrastructure for malware hosting, command-and-control, and storage of stolen data. Infections commonly begin with ClickFix-style fake CAPTCHA social engineering that tricks victims into executing PowerShell, followed by staged .NET loaders that deliver the final payloads. Within that ecosystem, SimpleChatProxy functions as an interactive utility rather than a propagation or theft module. It has been observed as a downloadable and executable component delivered by other StopAndProtect malware, including the ransomware or stealer modules.
SimpleChatProxy targets Windows environments as part of a modular intrusion set used in financially motivated attacks. The campaign has affected victims globally and has combined covert data theft with selective ransomware deployment, indicating that the chat utility supports direct operator engagement during post-compromise operations and ransom-related interactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom communication component enabling chat between the victim and the operator.
Custom communication utility enabling live chat between the victim and the operator.
Custom operator-to-victim communication utility used during infections; supports interactive messaging and sending images to the victim system.
Custom operator-to-victim chat utility used during infections; can block victim input and allows the operator to send messages and images, supporting interactive extortion or hands-on-keyboard activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.