Discovery Enum
- AdFind
- Advanced IP Scanner
- ShareFinder
Diavol is a Windows ransomware family linked by multiple technical and operational overlaps to the TrickBot ecosystem, including Wizard Spider, and observed in proximity to Conti operations.
Profile source: Mallory opens in a new tabDiavol
Diavol is a Windows ransomware family linked by multiple technical and operational overlaps to the TrickBot ecosystem, including Wizard Spider, and observed in proximity to Conti operations. Public reporting places its emergence in 2021, with some development-stage samples indicating earlier internal evolution. It has been associated with the broader TrickBot/Conti cluster and has been described as sharing code patterns, bot-identification logic, command-line conventions, and other implementation traits with TrickBot- and Conti-related tooling.
Diavol is a 64-bit ransomware that supports local and network-focused encryption workflows. It can generate victim and bot identifiers, collect host information such as username and local and external IP data, register infected systems to command-and-control infrastructure over HTTP using GET and POST requests, and retrieve updated configuration elements remotely. Its reconnaissance features include enumeration of local drives, network shares, and SMB-accessible resources, including discovery of shares via dedicated commands and share-enumeration APIs. It can also stop selected services, terminate processes, and attempt to stop security software prior to encryption.
The malware encrypts files using a hybrid design involving RSA and XOR-based processing, with partial or block-based encryption behavior documented across analyzed variants. It appends encryption-related metadata to affected files, drops ransom notes, and changes the desktop wallpaper. Diavol also inhibits recovery by deleting Volume Shadow Copies, with reporting describing both command-shell-based deletion and use of VSS-related interfaces such as IVssBackupComponents to enumerate and remove snapshots. Some analyses noted shellcode-loaded core functionality and resource-based storage of code and imports as anti-analysis or implementation features.
Observed tradecraft indicates post-compromise deployment in enterprise intrusions rather than broad indiscriminate self-propagation. Diavol has been seen alongside Conti in at least one reported incident and has been discussed as a possible test or parallel ransomware effort within the TrickBot-associated criminal ecosystem. Victimology in the supplied reporting is not sufficiently specific to assign a narrow sector focus, but the malware is clearly intended for organizational ransomware operations involving network discovery, impact, and in some cases extortion claims involving data theft.
Reported operators
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
The FBI has formally linked the Diavol ransomware operation to the TrickBot Group... "The FBI first learned of Diavol ransomware in October 2021."
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
...deployment of ransomware including Conti and Diavol.
MITRE ATT&CK
Reporting
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.