Diavol is a Windows ransomware family linked by the FBI to the TrickBot Group, also known as Wizard Spider. First publicly reported in July 2021, it was observed alongside Conti ransomware during a June 2021 intrusion. It shares technical characteristics with Conti and TrickBot, including command-line functionality, encryption queuing mechanisms, and victim-identification formats. It targets files on local drives, mapped drives, and accessible network shares to extort affected organizations.
Diavol collects host information, including computer names, usernames, Windows versions, and network addresses, and registers compromised systems with command-and-control infrastructure using HTTP. It supports HTTP GET and POST communications and can retrieve updated encryption keys, service and process targeting lists, file-selection rules, and ransom-note content. Network discovery includes identifying hosts through the ARP table, scanning SMB resources, and enumerating available shares. Before encryption, it can stop selected services and terminate processes to make files accessible.
Its encryption implementation varies between versions. RSA-based file encryption is documented, while other variants combine partial XOR encoding with RSA protection of key material and portions of file data. Some XOR-based variants reuse a randomly generated key across files, creating weaknesses that can permit substantial data recovery through known-plaintext analysis. Diavol leaves ransom notes, renames encrypted files, and can change the desktop wallpaper to display an encryption notice. It inhibits recovery by deleting Windows Volume Shadow Copies through native utilities or Volume Shadow Copy Service interfaces. Its anti-analysis techniques include loading core functionality as shellcode from executable resources, with code and import information concealed in image objects. It can also delete its own executable after execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor quickly achieved notoriety through their ties with ransomware groups such as “Conti” and “Diavol.”
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
All of these (malicious tools) are used to gain access to corporate networks, steal files and network credentials, and ultimately deploy ransomware on the network.
For one of the samples we analyzed the shadow copies were wiped using WinAPI which doesn’t appear to be used very often by ransomware: After calling CreateVssBackupComponents you can use the IVssBackupComponents class [5] which can then be leveraged to delete snapshots.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain financially linked in the content to Stern’s activity.
Ransomware family explicitly mentioned as associated with TrickBot.
Ransomware referenced as one of the malware variants used by the TrickBot/Conti-linked group.
Ransomware that deletes shadow copies through the IVssBackupComponents COM interface.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.