Skip to content

DiamondFox

DiamondFox is a modular malware-as-a-service botnet sold on underground forums and associated with the actor alias Edbitss.

Profile source: Mallory opens in a new tab

DiamondFox

Family profile

DiamondFox is a modular malware-as-a-service botnet sold on underground forums and associated with the actor alias Edbitss. It is designed as a plugin-based platform that allows operators to tailor functionality per victim through a management panel that provides infection statistics and plugin control. Reported capabilities include credential theft, keylogging, cryptocurrency wallet theft, espionage-oriented collection, monetary theft, self-spreading, and distributed denial-of-service activity. DiamondFox has also been linked to removable-media and social-network propagation features, and a 2017 version reportedly included a point-of-sale plugin distinct from GlitchPOS. The malware has been marketed with ongoing updates and customer support, reflecting a commercial crimeware model aimed at a broad range of buyers, including comparatively low-skill operators. DiamondFox primarily targets Windows environments and is notable for its extensible architecture, operator panel, and use as a general-purpose criminal botnet platform.

Capabilities

  • Credential Theft
  • Ddos
  • Exfiltration
  • Keylogging
  • Reconnaissance

Reported operators

Threat actors

1 named in public reporting
Edbitss

DiamondFox, a modular botnet offered for sale on various underground forums, is an outstanding demonstration of the many advantages of this business module.

MITRE ATT&CK

DiamondFox in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.