Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

STOP / Djvu Ransomware Decryption & Data Recovery

  • Active
  • Medium
  • Some versions decryptable

STOP/Djvu is one of the highest-volume ransomware families worldwide, infecting individuals and micro-businesses mainly through software cracks, activators and game cheats. Extensions are typically four random lowercase letters and the note is _readme.txt. Files encrypted with an offline key can be decrypted free with Emsisoft's tool.

First seen
2018-02
File extensions
.djvu .rumba .radman
Ransom notes
_readme.txt
Affected platforms
Windows

Family profile

File extensions
  • .djvu
  • .rumba
  • .radman
  • .gero
  • .held
  • .[4位小写字母随机后缀]
Ransom notes
  • _readme.txt
Contact patterns
  • Two mailboxes in the note (one primary, one backup), contact within 72 hours
  • Flat ransom tiers (USD 490 / 980, half price claimed within three days)
  • IM account as a fallback in some builds
Aliases / versions
STOP Ransomware、Djvu、STOP/Djvu
First seen
2018-02
Status
Active
Operational status
Currently dormant
Threat level
Medium
Affected platforms
  • Windows
Tags
  • Prevalent in China
  • Consumer targets
  • Legacy family
Decryptor
Some versions decryptable

Emsisoft provides a free STOP Djvu Decryptor, but it only works on files encrypted with an "offline key".

How it works: when an infected host cannot reach the attacker's C2 server during encryption, the sample falls back to a built-in offline key. All offline-key victims of the same variant share that key, so once Emsisoft obtains it they can decrypt for every offline victim of that variant.

Key limits:

  • Files encrypted with an online key cannot be decrypted. With working connectivity, the C2 issues a unique RSA public key per host and the private key stays with the attacker.
  • Emsisoft can only add a variant's offline key after a victim has paid, received the key and shared it with them.
  • New variants therefore often remain undecryptable for a considerable period.
  • Current status: per BleepingComputer's STOP/Djvu support topic, Emsisoft has largely discontinued development and support of this decryptor, and new offline keys are added only rarely now. Keys already in the tool still work and the tool is still downloadable, but expectations for "try again in a few months" should be lowered accordingly; keeping an archived copy of the encrypted files is still worthwhile, just not something to pin hopes on.
  • Indicator: if the personal ID in the _readme.txt note ends in t1, an offline key was usually used and the tool is worth trying — but the tool's actual output is the final word.
Sources

Latest activity

  1. BleepingComputer's STOP/Djvu topic lists .held (Dec 2024) as the last known variant, no new variants reported since and none as of Sept 2026; it also says Emsisoft's decryptor is no longer developed or supported.

    Sources

Overview

STOP appeared in early 2018 and spawned the Djvu branch later that year; the two are normally referred to together as STOP/Djvu. It differs fundamentally from the other families on this site: its targets are personal computers and micro-business endpoints, not enterprise servers. There is no hands-on intrusion, no lateral movement and no double extortion — it relies on sheer infection volume and has long ranked among the highest-volume families worldwide by submission counts.

Its distribution defines its victims: software cracks, activators, game cheats, pirated download sites, and unvetted drivers and optimisation utilities. Users trying to bypass licensing often disable antivirus before running these programs, effectively waving the malware through. It also causes damage beyond encryption: information stealers such as Vidar are typically downloaded alongside it, taking browser-stored passwords, cookies, cryptocurrency wallets and messaging credentials, so account security is compromised too and important passwords must be changed after clean-up. Victims in China are mostly individuals, sole traders, small studios and micro-businesses, and most have no backups at all.

How to identify it

Extensions: early builds used meaningful names such as .djvu, .rumba, .radman and .gero. Since switching to the newer generation, the developers have consistently used four random lowercase letters (for example .bbil, .rrcc, .irkf), and hundreds now exist with more added regularly. A four-lowercase-letter extension together with a _readme.txt note is effectively a STOP/Djvu identification.

Ransom note: _readme.txt, dropped into each encrypted directory and onto the desktop. Its content is stable: an ATTENTION! banner, an offer to decrypt one unimportant file as proof, two contact addresses with a 72-hour deadline, a fixed price halved within three days, and a personal ID string.

A key detail — the end of the personal ID: if the personal ID ends in t1, encryption usually used the built-in offline key and Emsisoft's decryptor has a chance of succeeding; otherwise an online key was most likely used and decryption is not possible. This is the fastest preliminary indicator, though the tool's actual output remains the final word.

Infection vectors

STOP/Djvu spreads almost entirely because users voluntarily run untrusted programs, unlike the intrusion-driven enterprise families. Cracks, keygens and activators for pirated design software, office suites and development tools are the main channel, followed by game cheats, bundled installers from pirated download sites, and links disguised as legitimate installers.

Nearly all of these instruct the user to disable antivirus first on the pretext of false positives — precisely the step where protection is bypassed. Scope of damage: STOP/Djvu does not move laterally, but it encrypts every accessible drive on the machine, including mapped network drives and attached external disks. In a micro-business, one infected computer with a mapped share or a connected backup drive extends the loss to the whole team's shared files.

Encryption behavior

STOP/Djvu encrypts file contents with Salsa20 and protects the symmetric key with RSA-2048. Its key model is the crux of decryptability.

Online key: on execution the sample sends a host identifier to the C2 server, which issues a unique RSA-2048 public key and personal ID for that machine. The matching private key exists only with the attacker, so files encrypted with an online key cannot be decrypted by a third party.

Offline key: if the host is offline, the C2 is unreachable, or the server does not respond, the sample falls back to a fixed key embedded in the payload. All offline victims of the same variant share that key, which is exactly why Emsisoft's decryptor works; the indicator is a personal ID ending in t1.

Large files: some versions encrypt only a leading portion, so depending on how encryption was applied, large videos, disk images and archives may retain most of their content, leaving room for partial repair or partial usability — something to verify per file type.

Assess before you act

Recoverability assessment

Decryptability for STOP/Djvu depends entirely on whether an offline or online key was used.

1. Emsisoft STOP Djvu Decryptor (offline keys only) The first and mandatory path. Open _readme.txt and check the personal ID: ending in t1 usually indicates an offline key. Download the decryptor and trial-decrypt files of different types and sizes on copies, counting success only when the output opens correctly. If the current variant cannot be decrypted yet, archive the encrypted files to an external drive and retry periodically with the latest version. Files encrypted with an online key cannot be decrypted, and no service claiming otherwise should be trusted.

2. Cloud version history and disconnected backups Worth checking one by one: cloud storage version history and recycle bins, external drives unplugged during encryption, copies on phones and tablets, attachments sent by email, and messaging-app transfer caches.

3. Partial usability of large files and fragment recovery Some versions encrypt only a leading portion, so large videos, disk images and archives may yield usable data by repairing the header or extracting the unencrypted remainder. Deleted originals that have not been overwritten may also be recoverable, and the critical action is to stop using the computer immediately and image the drive read-only from a clean machine.

4. Account security response (equally important) Because an information stealer usually accompanies the infection, after clean-up change passwords for email, banking, social accounts, cloud storage and corporate systems from a different clean device, and enable multi-factor authentication.

We do not pay ransoms, do not negotiate on a victim's behalf, and never promise that every file can be decrypted or restored.

Our response plan

Hit by STOP / Djvu ransomware? What to do

  1. Step 1: Stop using the machine and preserve evidence

    In consumer and micro-business cases the first instinct is usually to "search for a tool and download antivirus" — which actively reduces the odds of recovery, because every write to disk can overwrite recoverable fragments of the original files.

    The correct order: stop using the computer immediately and disconnect it from the network (to stop the information stealer exfiltrating more data); unplug external drives and USB sticks; disconnect mapped network shares. Where possible, power down, remove the drive, attach it to a clean machine and image it read-only, then do all subsequent work on the image.

    Evidence to preserve: the original _readme.txt (the personal ID is the key to whether an offline or online key was used), the encryption extension, several encrypted samples plus matching unencrypted originals if any can be found, and a record of what was run before the infection (cracks, activators, downloaded installers). All of this helps identify the variant and assess decryptability.

  2. Step 2: Variant identification and key-type determination

    Identifying STOP/Djvu is usually quick: a four-lowercase-letter extension, a _readme.txt note, a fixed price and a 72-hour deadline are effectively conclusive. What needs determining is the specific variant (from the extension) and the key type.

    Key-type determination is the core of this step: open _readme.txt and check the personal ID. Ending in t1 usually indicates the built-in offline key and Emsisoft's decryptor has a chance; otherwise an online key was most likely used and decryption is not possible. This is preliminary — the tool's actual output settles it.

    Assess the information-stealing impact at the same time: which accounts were signed in on this machine, which passwords the browser stored, and whether cryptocurrency wallets or corporate system credentials were present. That risk is independent of data recovery and must be handled in parallel.

    Also scope the encryption: which local drives were hit, whether mapped shares and external drives were affected, and whether other computers on the same network are involved (STOP/Djvu does not spread laterally, so multiple simultaneous infections usually mean each machine ran the same downloaded program).

  3. Step 3: Recoverability assessment and recovery planning

    Bucket the assessment by path:

    • Offline key, decryptable: trial-decrypt with Emsisoft's STOP Djvu Decryptor on copies and define the decryptable scope and runtime.
    • Online key: state plainly that decryption is not possible, move to other paths, and advise archiving the encrypted files — if that variant's offline key is added later, some files may still become recoverable.
    • Cloud and backups: check cloud version history and recycle bins, external drives, copies on phones and tablets, and messaging-app file records.
    • Partial usability of large files: test videos, disk images and archives by type to assess repairing headers or extracting unencrypted remainders.
    • Fragment recovery: assess on the read-only image what proportion of deleted originals is recoverable.
    • Confirmed unrecoverable: listed explicitly.

    The plan should also include an account security checklist: which passwords to change from a clean device, which accounts need multi-factor authentication, and which need their sign-in history reviewed. For micro-businesses, assess the impact of client-data exposure and any notification obligations.

  4. Step 4: Recovery execution

    All work happens on read-only images or copies, leaving the original drive untouched.

    • Decryption (where the offline key applies): decrypt in batches, validating openability after each; prioritise business-critical files such as contracts, accounts, client records and design sources.
    • Cloud and backup restoration: restore from cloud version history and recycle bins, confirming that the restored version predates encryption.
    • Large-file repair: repair headers and extract unencrypted remainders for videos, disk images and archives by type, producing usable fragments verified individually.
    • Fragment recovery: scan the image for deleted originals, archive them by type and verify usability.
    • Cross-source fill-in: recover missing files from phones, tablets, email attachments and messaging histories.

    Delivery includes an inventory: which files were fully recovered, which are partially usable and which are confirmed lost. For micro-businesses, organise it by business category (client records, contracts, accounts, design files) so the real operational impact can be assessed.

  5. Step 5: Clean-up, hardening and account security sign-off

    System clean-up: after data recovery, reinstalling the operating system is recommended rather than continuing to use the compromised installation — STOP/Djvu usually arrives with information stealers and other bundled programs, and confirming a complete clean-up is difficult. Verify that data is fully backed up to clean media before reinstalling.

    Account security (this step cannot be skipped): from a different, clean device, change passwords one by one for email, online banking and payments, social and messaging accounts, cloud storage, corporate systems and cryptocurrency wallets, and enable multi-factor authentication; review sign-in history and authorised devices on each account; clear browser-stored passwords and move to a password manager.

    Hardening recommendations:

    • Use licensed or open-source software and stop using cracks and activators entirely — this is the root cause.
    • Never run a program that asks you to disable antivirus.
    • Install security software, keep it running and enable real-time protection.
    • Build a backup habit: sync important files to cloud storage with version history, and back up periodically to an external drive that is disconnected as soon as the backup finishes.
    • For micro-businesses, consolidate client and business records on a platform with version control and access management rather than leaving them on a personal computer.

    The engagement closes with a response report covering the recovery inventory, the account remediation checklist and prevention recommendations.

Risk warning

What not to do

  • Do not keep browsing, downloading software or installing antivirus on the infected computer. Every write can overwrite recoverable fragments; power down and image the drive read-only from a clean machine instead.
  • Do not run the decryptor directly against the original drive. Copy the encrypted files to other media first, trial-decrypt on the copy, validate the output, and only then process the rest.
  • Do not delete _readme.txt. The personal ID inside is the key indicator of whether an offline or online key was used, and without it feasibility cannot be judged quickly.
  • Do not trust services or tools claiming to decrypt "online keys". The private key exists only with the attacker and no such promise can be honoured.
  • Do not delete encrypted files because they cannot be decrypted today. Archive them to an external drive and retry later with the latest version — but Emsisoft has largely stopped updating the decryptor, so do not build the recovery plan around a key arriving.
  • Do not neglect account security. STOP/Djvu usually drops an information stealer as well, so change every important password from a different clean device and enable multi-factor authentication.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Similar families

Related questions

FAQ

STOP / Djvu Frequently asked questions

  • Can four-letter extensions such as .bbil or .rrcc be decrypted for free?

    Possibly, depending on whether an offline or online key was used.

    Emsisoft provides a free STOP Djvu Decryptor, but it only works on files encrypted with an offline key. When the infected host cannot reach the attacker's server during encryption, the sample falls back to a fixed embedded key shared by all offline victims of that variant, and once Emsisoft obtains it they can decrypt for all of them.

    Quick check: open _readme.txt and find the personal ID. Ending in t1 usually means an offline key and the tool is worth trying; otherwise it is most likely an online key and decryption is not possible.

    Do not delete the files even if they cannot be decrypted today: archive them to an external drive and retry later with the latest version of the tool. Be realistic about the odds, though — per BleepingComputer's STOP/Djvu support topic, Emsisoft has largely discontinued development and support of the decryptor and new offline keys are added only rarely, so the archive preserves a chance rather than a timetable for recovery.

  • The personal ID in _readme.txt ends in t1 — what does that mean?

    It usually means encryption used an offline key, which is good news — Emsisoft's STOP Djvu Decryptor has a chance of succeeding.

    The mechanism: during encryption STOP/Djvu first tries to contact the attacker's C2 server for an RSA public key unique to that host (the online key). If the network is unavailable, the server does not respond, or security software blocks the request, the sample falls back to the fixed offline key embedded in the payload, and the t1 suffix on the ID marks that case.

    This is only preliminary, however — the tool's actual output is the final word. The correct method: copy several encrypted files of different types and sizes to other media, run the latest Emsisoft decryptor against the copies, and count it a success only when the output opens correctly in the relevant application, then process the remaining files. Never run it in bulk against the original drive.

  • Besides encrypted files, what other risk does STOP/Djvu bring?

    Account compromise, and it is often more urgent than the data loss. Alongside encryption, STOP/Djvu typically downloads and runs an information stealer (Vidar-class being the most common) that takes browser-stored passwords and autofill data, cookies (which allow logon without the password), cryptocurrency wallet files, and messaging and remote-access credentials.

    Response therefore runs on two tracks. Data side: stop using the computer, image it read-only, assess decryptability. Account side: from a different, clean device, immediately change every important password — email, online banking and payments, social and messaging, cloud storage, corporate systems, cryptocurrency wallets — and enable multi-factor authentication; review sign-in history and authorised devices on each account and sign out all sessions.

    For micro-businesses, also assess whether client records and commercial information were exposed and whether affected parties need to be notified.

  • We got infected from cracked software — can the files on the work computer be saved?

    It depends on the combination of several paths, and the outlook is usually better than expected.

    First, decryption. Check whether the personal ID in _readme.txt ends in t1; if it is an offline key, try Emsisoft's tool, and success can restore most files directly.

    Second, cloud and side-channel copies. Most cloud sync services keep version history and a recycle bin, so local encryption does not affect older cloud versions. Add attachments previously sent by email, messaging-app transfer records and caches, copies on phones and tablets, and files colleagues already hold. This often recovers a substantial share of business material.

    Third, disconnected backups. An external drive that was not plugged in during encryption is intact.

    Fourth, large files and fragment recovery. Some versions encrypt only a leading portion, so large files may retain most of their content, and deleted originals may be recoverable from unallocated space — provided you stop using the computer immediately.

    Two further points: the cracked software is the root cause, so move to licensed or open-source alternatives afterwards; and account security must be handled, because an information stealer very likely came with it.

  • Should we pay the STOP/Djvu ransom?

    We do not pay ransoms, do not negotiate on a victim's behalf, and advise against paying independently. The amount looks modest (typically two price tiers with a half-price discount within three days), but there are practical problems: victims have paid and received no decryptor or a non-working one; payment marks you as willing to pay; and sending funds to an overseas criminal operation carries compliance risk.

    Better first steps: check whether the personal ID ends in t1 and trial the free Emsisoft tool; check cloud version history and recycle bins, disconnected external drives, and copies on phones and in messaging histories; assess partial usability of large files; and evaluate fragment recovery, having stopped using the computer.

    One point deserves emphasis: if the current variant cannot be decrypted yet, archiving the encrypted files is still worthwhile. Keep expectations low, though: Emsisoft has largely discontinued development and support of the decryptor, and new offline keys now enter the tool only rarely.