SilentEncryptor is a Windows ransomware component of the StopAndProtect cybercrime operation, first observed in 2026. It is deployed through a staged infection chain originating from compromised WordPress sites, where ClickFix-style fake CAPTCHA lures induce victims to execute attacker-supplied PowerShell commands. Subsequent PowerShell and .NET loader stages deploy the ransomware and other StopAndProtect modules.
SilentEncryptor retrieves a command file from command-and-control infrastructure to determine whether all infected systems or only endpoints matching specified host names should be encrypted. The command content also supplies the ransom message dynamically, enabling operators to tailor demands between victims. For each encrypted file, the malware derives a 32-byte key using a password and the machine name; recovered analyses indicate that information needed for decryption is incorporated into encrypted-file naming. StopAndProtect operators pair encryption with lock-screen and victim-communication components, while other campaign modules support data theft and propagation via network shares, removable media, and WMI.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed in the StopAndProtect campaign following ClickFix social engineering. It retrieves encryption-targeting instructions and ransom messages dynamically from its C2 server, enabling operators to change ransom-note content between infections. The samples also contain indicators of cryptocurrency-wallet file targeting.
Ransomware component that encrypts victim files under C2 direction, deriving a 32-byte per-file key from a password and the machine name.
Encryption component used in the StopAndProtect toolkit to encrypt infected computers, either broadly or selectively by hostname.
Ransomware component of the StopAndProtect operation. It receives encryption instructions from C2, can selectively encrypt hosts, and displays a ransom message after encrypting files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.