Diavol

MITRE ATT&CK: S0659 View on attack.mitre.org

Aliases: Diavol

First seen
2021-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-04 21:37:48
Profile updated
2026-07-07 12:55:02

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured list of extensions defined by the attacker. The Diavol Ransomware-as-a Service (RaaS) program is managed by Wizard Spider and it has been observed being deployed by Bazar.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Diavol (S0659). The 1 most recently updated:

Detection coverage

  • 2 YARA rules
  • 587 Sigma rules

Malware & tools used

  • Data Destruction (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Service Stop (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Internal Defacement (attack-pattern)
  • Steganography (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Native API (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Inhibit System Recovery (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_INDICATOR_KB_ID_Ransomware_Diavol (yara-rule)
  • MALPEDIA_Win_Diavol_Auto (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • arcticwolf.com — Karakurt Web (report)
  • thedfirreport.com — Diavol Ransomware (report)
  • fortinet.com — Diavol New Ransomware Used By Wizard Spider (report)
  • chuongdong.com — Diavolransomware (report)
  • heimdalsecurity.com — Is Diavol Ransomware Connected To Wizard Spider (report)
  • medium.com — Diavol Resurfaces 91Dd93C7D922 (report)
  • medium.com — Diavol The Enigma Of Ransomware 1Fd78Ffda648 (report)
  • securityintelligence.com — Analysis Of Diavol Ransomware Link Trickbot Gang (report)
  • binarydefense.com — New Ransomware Diavol Being Dropped By Trickbot (report)
  • bleepingcomputer.com — Diavol Ransomware Sample Shows Stronger Connection To Trickbot Gang (report)
  • bleepingcomputer.com — Fbi Links Diavol Ransomware To The Trickbot Cybercrime Group (report)
  • bleepingcomputer.com — Trickbot Gang Developer Arrested When Trying To Leave Korea (report)
  • ic3.gov — 220120 (report)
  • scythe.io — Adversary Emulation Diavol Ransomware Threatthursday (report)
  • ransomlook.io — Diavol (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Diavol (report)
  • MITRE ATT&CK — S0659 (report)
  • ic3.gov — 220120 (report)

External references