Discovery Enum
- AdFind
- Advanced IP Scanner
- ShareFinder
Diavol is a Windows ransomware family associated with the TrickBot and Conti cybercrime ecosystem and operated by actors tracked as DEV-0193, with reporting also linking its distribution to GOLD ULRICK.
Profile source: Mallory opens in a new tabDiavol
Diavol is a Windows ransomware family associated with the TrickBot and Conti cybercrime ecosystem and operated by actors tracked as DEV-0193, with reporting also linking its distribution to GOLD ULRICK. It emerged as one of the ransomware strains used alongside or after Ryuk and Conti within the same broader criminal network.
Diavol encrypts victim files using RSA through the Windows CryptEncrypt API and has been observed appending a distinct encrypted-file extension. It also inhibits recovery by deleting Volume Shadow Copies through the IVssBackupComponents COM interface and can delete selected files from compromised systems. Post-encryption, it modifies the victim desktop by creating a ransom-themed wallpaper and changing the background to display an extortion message.
The malware includes multiple pre-encryption and operational capabilities that support enterprise-wide impact. It can collect the username from a compromised host, communicate with command-and-control infrastructure over HTTP using GET and POST requests, attempt to stop security software, and use the ARP table to identify remote hosts for scanning. Diavol has also been observed spreading through Windows SMB shares prior to encryption, enabling propagation across internal networks.
Diavol is best understood as part of the financially motivated, human-operated ransomware tradecraft surrounding TrickBot and Conti rather than as a standalone commodity strain. Its observed behavior aligns with double-extortion-era ransomware operations that combine host discovery, defense evasion, lateral spread, recovery inhibition, and disruptive victim messaging to maximize pressure on targeted organizations.
Reported operators
DEV-0193 managed the Ryuk RaaS program before the latter’s shutdown in June 2021, and Ryuk’s successor, Conti as well as Diavol.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
...deployment of ransomware including Conti and Diavol.
MITRE ATT&CK
Reporting
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.