Diavol is a Windows ransomware family linked by multiple technical and operational overlaps to the TrickBot ecosystem, including Wizard Spider, and observed in proximity to Conti operations. Public reporting places its emergence in 2021, with some development-stage samples indicating earlier internal evolution. It has been associated with the broader TrickBot/Conti cluster and has been described as sharing code patterns, bot-identification logic, command-line conventions, and other implementation traits with TrickBot- and Conti-related tooling.
Diavol is a 64-bit ransomware that supports local and network-focused encryption workflows. It can generate victim and bot identifiers, collect host information such as username and local and external IP data, register infected systems to command-and-control infrastructure over HTTP using GET and POST requests, and retrieve updated configuration elements remotely. Its reconnaissance features include enumeration of local drives, network shares, and SMB-accessible resources, including discovery of shares via dedicated commands and share-enumeration APIs. It can also stop selected services, terminate processes, and attempt to stop security software prior to encryption.
The malware encrypts files using a hybrid design involving RSA and XOR-based processing, with partial or block-based encryption behavior documented across analyzed variants. It appends encryption-related metadata to affected files, drops ransom notes, and changes the desktop wallpaper. Diavol also inhibits recovery by deleting Volume Shadow Copies, with reporting describing both command-shell-based deletion and use of VSS-related interfaces such as IVssBackupComponents to enumerate and remove snapshots. Some analyses noted shellcode-loaded core functionality and resource-based storage of code and imports as anti-analysis or implementation features.
Observed tradecraft indicates post-compromise deployment in enterprise intrusions rather than broad indiscriminate self-propagation. Diavol has been seen alongside Conti in at least one reported incident and has been discussed as a possible test or parallel ransomware effort within the TrickBot-associated criminal ecosystem. Victimology in the supplied reporting is not sufficiently specific to assign a narrow sector focus, but the malware is clearly intended for organizational ransomware operations involving network discovery, impact, and in some cases extortion claims involving data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
For anti-analysis, DIAVOL loads shellcode containing its core functions into memory and executes it dynamically...
The malware loads a “JPEG” with the same name in the resource section, extracts a list of imported functions with their corresponding DLL, and manually calls LoadLibraryA and GetProcAddress to resolve it for the shellcode.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The FINDFILES shellcode first converts the target filename to lowercase... Next, DIAVOL calls FindFirstFileW to begin its enumeration on the target file... recursively calls the FINDFILES shellcode function again.
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
The researchers also note that the HTTP headers for the command and control (C2) server communication were “set to prefer Russian language content,” also favored by TrickBot operators.
All of these (malicious tools) are used to gain access to corporate networks, steal files and network credentials, and ultimately deploy ransomware on the network.
Given a list of services to stop, the shellcode iterates through the list and stops them through the service control manager. It first calls OpenSCManagerW... OpenServiceW... and ControlService to send a control stop code to stop it.
For one of the samples we analyzed the shadow copies were wiped using WinAPI which doesn’t appear to be used very often by ransomware: After calling CreateVssBackupComponents you can use the IVssBackupComponents class [5] which can then be leveraged to delete snapshots.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain financially linked in the content to Stern’s activity.
Ransomware family explicitly mentioned as associated with TrickBot.
Ransomware referenced as one of the malware variants used by the TrickBot/Conti-linked group.
Ransomware that deletes shadow copies through the IVssBackupComponents COM interface.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.