Ransomware family
STOP / Djvu Ransomware Decryption & Data Recovery
- Active
- Medium
- Some versions decryptable
STOP/Djvu is one of the highest-volume ransomware families worldwide, infecting individuals and micro-businesses mainly through software cracks, activators and game cheats. Extensions are typically four random lowercase letters and the note is _readme.txt. Files encrypted with an offline key can be decrypted free with Emsisoft's tool.
- First seen
- 2018-02
- File extensions
- .djvu .rumba .radman
- Ransom notes
- _readme.txt
- Affected platforms
- Windows
Family profile
- File extensions
- .djvu
- .rumba
- .radman
- .gero
- .held
- .[4位小写字母随机后缀]
- Ransom notes
- _readme.txt
- Contact patterns
- Two mailboxes in the note (one primary, one backup), contact within 72 hours
- Flat ransom tiers (USD 490 / 980, half price claimed within three days)
- IM account as a fallback in some builds
- Aliases / versions
- STOP Ransomware、Djvu、STOP/Djvu
- First seen
- 2018-02
- Status
- Active
- Operational status
- Currently dormant
- Threat level
- Medium
- Affected platforms
- Windows
- Tags
- Prevalent in China
- Consumer targets
- Legacy family
Emsisoft provides a free STOP Djvu Decryptor, but it only works on files encrypted with an "offline key".
How it works: when an infected host cannot reach the attacker's C2 server during encryption, the sample falls back to a built-in offline key. All offline-key victims of the same variant share that key, so once Emsisoft obtains it they can decrypt for every offline victim of that variant.
Key limits:
- Files encrypted with an online key cannot be decrypted. With working connectivity, the C2 issues a unique RSA public key per host and the private key stays with the attacker.
- Emsisoft can only add a variant's offline key after a victim has paid, received the key and shared it with them.
- New variants therefore often remain undecryptable for a considerable period.
- Current status: per BleepingComputer's STOP/Djvu support topic, Emsisoft has largely discontinued development and support of this decryptor, and new offline keys are added only rarely now. Keys already in the tool still work and the tool is still downloadable, but expectations for "try again in a few months" should be lowered accordingly; keeping an archived copy of the encrypted files is still worthwhile, just not something to pin hopes on.
- Indicator: if the personal ID in the _readme.txt note ends in t1, an offline key was usually used and the tool is worth trying — but the tool's actual output is the final word.
Latest activity
BleepingComputer's STOP/Djvu topic lists .held (Dec 2024) as the last known variant, no new variants reported since and none as of Sept 2026; it also says Emsisoft's decryptor is no longer developed or supported.
Sources
Overview
STOP appeared in early 2018 and spawned the Djvu branch later that year; the two are normally referred to together as STOP/Djvu. It differs fundamentally from the other families on this site: its targets are personal computers and micro-business endpoints, not enterprise servers. There is no hands-on intrusion, no lateral movement and no double extortion — it relies on sheer infection volume and has long ranked among the highest-volume families worldwide by submission counts.
Its distribution defines its victims: software cracks, activators, game cheats, pirated download sites, and unvetted drivers and optimisation utilities. Users trying to bypass licensing often disable antivirus before running these programs, effectively waving the malware through. It also causes damage beyond encryption: information stealers such as Vidar are typically downloaded alongside it, taking browser-stored passwords, cookies, cryptocurrency wallets and messaging credentials, so account security is compromised too and important passwords must be changed after clean-up. Victims in China are mostly individuals, sole traders, small studios and micro-businesses, and most have no backups at all.
How to identify it
Extensions: early builds used meaningful names such as .djvu, .rumba, .radman and .gero. Since switching to the newer generation, the developers have consistently used four random lowercase letters (for example .bbil, .rrcc, .irkf), and hundreds now exist with more added regularly. A four-lowercase-letter extension together with a _readme.txt note is effectively a STOP/Djvu identification.
Ransom note: _readme.txt, dropped into each encrypted directory and onto the desktop. Its content is stable: an ATTENTION! banner, an offer to decrypt one unimportant file as proof, two contact addresses with a 72-hour deadline, a fixed price halved within three days, and a personal ID string.
A key detail — the end of the personal ID: if the personal ID ends in t1, encryption usually used the built-in offline key and Emsisoft's decryptor has a chance of succeeding; otherwise an online key was most likely used and decryption is not possible. This is the fastest preliminary indicator, though the tool's actual output remains the final word.
Infection vectors
STOP/Djvu spreads almost entirely because users voluntarily run untrusted programs, unlike the intrusion-driven enterprise families. Cracks, keygens and activators for pirated design software, office suites and development tools are the main channel, followed by game cheats, bundled installers from pirated download sites, and links disguised as legitimate installers.
Nearly all of these instruct the user to disable antivirus first on the pretext of false positives — precisely the step where protection is bypassed. Scope of damage: STOP/Djvu does not move laterally, but it encrypts every accessible drive on the machine, including mapped network drives and attached external disks. In a micro-business, one infected computer with a mapped share or a connected backup drive extends the loss to the whole team's shared files.
Encryption behavior
STOP/Djvu encrypts file contents with Salsa20 and protects the symmetric key with RSA-2048. Its key model is the crux of decryptability.
Online key: on execution the sample sends a host identifier to the C2 server, which issues a unique RSA-2048 public key and personal ID for that machine. The matching private key exists only with the attacker, so files encrypted with an online key cannot be decrypted by a third party.
Offline key: if the host is offline, the C2 is unreachable, or the server does not respond, the sample falls back to a fixed key embedded in the payload. All offline victims of the same variant share that key, which is exactly why Emsisoft's decryptor works; the indicator is a personal ID ending in t1.
Large files: some versions encrypt only a leading portion, so depending on how encryption was applied, large videos, disk images and archives may retain most of their content, leaving room for partial repair or partial usability — something to verify per file type.
Assess before you act
Recoverability assessment
Decryptability for STOP/Djvu depends entirely on whether an offline or online key was used.
1. Emsisoft STOP Djvu Decryptor (offline keys only) The first and mandatory path. Open _readme.txt and check the personal ID: ending in t1 usually indicates an offline key. Download the decryptor and trial-decrypt files of different types and sizes on copies, counting success only when the output opens correctly. If the current variant cannot be decrypted yet, archive the encrypted files to an external drive and retry periodically with the latest version. Files encrypted with an online key cannot be decrypted, and no service claiming otherwise should be trusted.
2. Cloud version history and disconnected backups Worth checking one by one: cloud storage version history and recycle bins, external drives unplugged during encryption, copies on phones and tablets, attachments sent by email, and messaging-app transfer caches.
3. Partial usability of large files and fragment recovery Some versions encrypt only a leading portion, so large videos, disk images and archives may yield usable data by repairing the header or extracting the unencrypted remainder. Deleted originals that have not been overwritten may also be recoverable, and the critical action is to stop using the computer immediately and image the drive read-only from a clean machine.
4. Account security response (equally important) Because an information stealer usually accompanies the infection, after clean-up change passwords for email, banking, social accounts, cloud storage and corporate systems from a different clean device, and enable multi-factor authentication.
We do not pay ransoms, do not negotiate on a victim's behalf, and never promise that every file can be decrypted or restored.
Our response plan
Hit by STOP / Djvu ransomware? What to do
Step 1: Stop using the machine and preserve evidence
In consumer and micro-business cases the first instinct is usually to "search for a tool and download antivirus" — which actively reduces the odds of recovery, because every write to disk can overwrite recoverable fragments of the original files.
The correct order: stop using the computer immediately and disconnect it from the network (to stop the information stealer exfiltrating more data); unplug external drives and USB sticks; disconnect mapped network shares. Where possible, power down, remove the drive, attach it to a clean machine and image it read-only, then do all subsequent work on the image.
Evidence to preserve: the original _readme.txt (the personal ID is the key to whether an offline or online key was used), the encryption extension, several encrypted samples plus matching unencrypted originals if any can be found, and a record of what was run before the infection (cracks, activators, downloaded installers). All of this helps identify the variant and assess decryptability.
Step 2: Variant identification and key-type determination
Identifying STOP/Djvu is usually quick: a four-lowercase-letter extension, a _readme.txt note, a fixed price and a 72-hour deadline are effectively conclusive. What needs determining is the specific variant (from the extension) and the key type.
Key-type determination is the core of this step: open _readme.txt and check the personal ID. Ending in t1 usually indicates the built-in offline key and Emsisoft's decryptor has a chance; otherwise an online key was most likely used and decryption is not possible. This is preliminary — the tool's actual output settles it.
Assess the information-stealing impact at the same time: which accounts were signed in on this machine, which passwords the browser stored, and whether cryptocurrency wallets or corporate system credentials were present. That risk is independent of data recovery and must be handled in parallel.
Also scope the encryption: which local drives were hit, whether mapped shares and external drives were affected, and whether other computers on the same network are involved (STOP/Djvu does not spread laterally, so multiple simultaneous infections usually mean each machine ran the same downloaded program).
Step 3: Recoverability assessment and recovery planning
Bucket the assessment by path:
- Offline key, decryptable: trial-decrypt with Emsisoft's STOP Djvu Decryptor on copies and define the decryptable scope and runtime.
- Online key: state plainly that decryption is not possible, move to other paths, and advise archiving the encrypted files — if that variant's offline key is added later, some files may still become recoverable.
- Cloud and backups: check cloud version history and recycle bins, external drives, copies on phones and tablets, and messaging-app file records.
- Partial usability of large files: test videos, disk images and archives by type to assess repairing headers or extracting unencrypted remainders.
- Fragment recovery: assess on the read-only image what proportion of deleted originals is recoverable.
- Confirmed unrecoverable: listed explicitly.
The plan should also include an account security checklist: which passwords to change from a clean device, which accounts need multi-factor authentication, and which need their sign-in history reviewed. For micro-businesses, assess the impact of client-data exposure and any notification obligations.
Step 4: Recovery execution
All work happens on read-only images or copies, leaving the original drive untouched.
- Decryption (where the offline key applies): decrypt in batches, validating openability after each; prioritise business-critical files such as contracts, accounts, client records and design sources.
- Cloud and backup restoration: restore from cloud version history and recycle bins, confirming that the restored version predates encryption.
- Large-file repair: repair headers and extract unencrypted remainders for videos, disk images and archives by type, producing usable fragments verified individually.
- Fragment recovery: scan the image for deleted originals, archive them by type and verify usability.
- Cross-source fill-in: recover missing files from phones, tablets, email attachments and messaging histories.
Delivery includes an inventory: which files were fully recovered, which are partially usable and which are confirmed lost. For micro-businesses, organise it by business category (client records, contracts, accounts, design files) so the real operational impact can be assessed.
Step 5: Clean-up, hardening and account security sign-off
System clean-up: after data recovery, reinstalling the operating system is recommended rather than continuing to use the compromised installation — STOP/Djvu usually arrives with information stealers and other bundled programs, and confirming a complete clean-up is difficult. Verify that data is fully backed up to clean media before reinstalling.
Account security (this step cannot be skipped): from a different, clean device, change passwords one by one for email, online banking and payments, social and messaging accounts, cloud storage, corporate systems and cryptocurrency wallets, and enable multi-factor authentication; review sign-in history and authorised devices on each account; clear browser-stored passwords and move to a password manager.
Hardening recommendations:
- Use licensed or open-source software and stop using cracks and activators entirely — this is the root cause.
- Never run a program that asks you to disable antivirus.
- Install security software, keep it running and enable real-time protection.
- Build a backup habit: sync important files to cloud storage with version history, and back up periodically to an external drive that is disconnected as soon as the backup finishes.
- For micro-businesses, consolidate client and business records on a platform with version control and access management rather than leaving them on a personal computer.
The engagement closes with a response report covering the recovery inventory, the account remediation checklist and prevention recommendations.
Risk warning
What not to do
- Do not keep browsing, downloading software or installing antivirus on the infected computer. Every write can overwrite recoverable fragments; power down and image the drive read-only from a clean machine instead.
- Do not run the decryptor directly against the original drive. Copy the encrypted files to other media first, trial-decrypt on the copy, validate the output, and only then process the rest.
- Do not delete _readme.txt. The personal ID inside is the key indicator of whether an offline or online key was used, and without it feasibility cannot be judged quickly.
- Do not trust services or tools claiming to decrypt "online keys". The private key exists only with the attacker and no such promise can be honoured.
- Do not delete encrypted files because they cannot be decrypted today. Archive them to an external drive and retry later with the latest version — but Emsisoft has largely stopped updating the decryptor, so do not build the recovery plan around a key arriving.
- Do not neglect account security. STOP/Djvu usually drops an information stealer as well, so change every important password from a different clean device and enable multi-factor authentication.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Synology NAS Encrypted by Ransomware
Synology incidents come in two shapes: the NAS itself is compromised (DSM exposed to the internet, accounts brute-forced), or an infected Windows host on the LAN encrypts it over SMB. The handling and recovery paths differ completely. This page explains how to tell them apart and what Btrfs snapshots and Hyper Backup can actually do.
Related industries
Education and Research Ransomware Response
Schools and research institutions run open networks with dispersed endpoints and systems built across many eras, often unattended at night and during holidays — a combination attackers exploit. This page covers the sector's threat profile, recovery priorities for academic and research data, and defences suited to campus networks.
Retail and E-commerce Ransomware Response
In retail and e-commerce, ransomware translates directly into an inability to sell: order systems, membership, POS and warehouse fulfilment stop together and losses accrue by the hour. This page covers the sector's attack patterns, a recovery order built around the order-to-fulfilment chain, and handling of member data exposure.
Similar families
- Some versions decryptable
WannaCry
WannaCry is the ransomware worm that spread worldwide in May 2017 by exploiting the EternalBlue SMB vulnerability (MS17-010), appending .WNCRY. The original campaign is long over, but unpatched legacy networks still get hit by residual samples that continue to spread automatically.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- Some versions decryptable
GlobeImposter
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
Related questions
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
- First response
My files all have a new extension and won't open - what should I do?
Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.
FAQ
STOP / Djvu Frequently asked questions
Can four-letter extensions such as .bbil or .rrcc be decrypted for free?
Possibly, depending on whether an offline or online key was used.
Emsisoft provides a free STOP Djvu Decryptor, but it only works on files encrypted with an offline key. When the infected host cannot reach the attacker's server during encryption, the sample falls back to a fixed embedded key shared by all offline victims of that variant, and once Emsisoft obtains it they can decrypt for all of them.
Quick check: open _readme.txt and find the personal ID. Ending in t1 usually means an offline key and the tool is worth trying; otherwise it is most likely an online key and decryption is not possible.
Do not delete the files even if they cannot be decrypted today: archive them to an external drive and retry later with the latest version of the tool. Be realistic about the odds, though — per BleepingComputer's STOP/Djvu support topic, Emsisoft has largely discontinued development and support of the decryptor and new offline keys are added only rarely, so the archive preserves a chance rather than a timetable for recovery.
The personal ID in _readme.txt ends in t1 — what does that mean?
It usually means encryption used an offline key, which is good news — Emsisoft's STOP Djvu Decryptor has a chance of succeeding.
The mechanism: during encryption STOP/Djvu first tries to contact the attacker's C2 server for an RSA public key unique to that host (the online key). If the network is unavailable, the server does not respond, or security software blocks the request, the sample falls back to the fixed offline key embedded in the payload, and the t1 suffix on the ID marks that case.
This is only preliminary, however — the tool's actual output is the final word. The correct method: copy several encrypted files of different types and sizes to other media, run the latest Emsisoft decryptor against the copies, and count it a success only when the output opens correctly in the relevant application, then process the remaining files. Never run it in bulk against the original drive.
Besides encrypted files, what other risk does STOP/Djvu bring?
Account compromise, and it is often more urgent than the data loss. Alongside encryption, STOP/Djvu typically downloads and runs an information stealer (Vidar-class being the most common) that takes browser-stored passwords and autofill data, cookies (which allow logon without the password), cryptocurrency wallet files, and messaging and remote-access credentials.
Response therefore runs on two tracks. Data side: stop using the computer, image it read-only, assess decryptability. Account side: from a different, clean device, immediately change every important password — email, online banking and payments, social and messaging, cloud storage, corporate systems, cryptocurrency wallets — and enable multi-factor authentication; review sign-in history and authorised devices on each account and sign out all sessions.
For micro-businesses, also assess whether client records and commercial information were exposed and whether affected parties need to be notified.
We got infected from cracked software — can the files on the work computer be saved?
It depends on the combination of several paths, and the outlook is usually better than expected.
First, decryption. Check whether the personal ID in _readme.txt ends in t1; if it is an offline key, try Emsisoft's tool, and success can restore most files directly.
Second, cloud and side-channel copies. Most cloud sync services keep version history and a recycle bin, so local encryption does not affect older cloud versions. Add attachments previously sent by email, messaging-app transfer records and caches, copies on phones and tablets, and files colleagues already hold. This often recovers a substantial share of business material.
Third, disconnected backups. An external drive that was not plugged in during encryption is intact.
Fourth, large files and fragment recovery. Some versions encrypt only a leading portion, so large files may retain most of their content, and deleted originals may be recoverable from unallocated space — provided you stop using the computer immediately.
Two further points: the cracked software is the root cause, so move to licensed or open-source alternatives afterwards; and account security must be handled, because an information stealer very likely came with it.
Should we pay the STOP/Djvu ransom?
We do not pay ransoms, do not negotiate on a victim's behalf, and advise against paying independently. The amount looks modest (typically two price tiers with a half-price discount within three days), but there are practical problems: victims have paid and received no decryptor or a non-working one; payment marks you as willing to pay; and sending funds to an overseas criminal operation carries compliance risk.
Better first steps: check whether the personal ID ends in t1 and trial the free Emsisoft tool; check cloud version history and recycle bins, disconnected external drives, and copies on phones and in messaging histories; assess partial usability of large files; and evaluate fragment recovery, having stopped using the computer.
One point deserves emphasis: if the current variant cannot be decrypted yet, archiving the encrypted files is still worthwhile. Keep expectations low, though: Emsisoft has largely discontinued development and support of the decryptor, and new offline keys now enter the tool only rarely.
Sources
- Emsisoft: STOP Djvu Decryptor(免费解密工具与适用说明)
- Emsisoft Blog: Emsisoft releases new decryptor for STOP Djvu ransomware
- CyberGeeks: A detailed analysis of the STOP/Djvu Ransomware
- Quick Heal: STOP (Djvu) Ransomware – Ransom For Your Shady Habits
- Malpedia: STOP (Malware Family)
- BleepingComputer: STOP Ransomware (.STOP, .Puma, .Djvu, .Promo, .Drume) Help & Support Topic
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated