DiamondFox

Aliases: Crystal, Gorynch, Gorynych

First seen
2015-01-01 00:00:00
Malware type
botnet, credential-stealer, ddos, keylogger, trojan
Family
Malware family
Last IoC activity
2026-07-14 13:01:45
Profile updated
2026-07-07 13:45:03

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums. Therefore, cyber criminals who are willing to use DiamondFox do not necessarily require any technical knowledge to perform their attacks. Once purchased, this malware can be used to log keystrokes, steal credentials (e.g., usernames, email addresses, passwords), hijack cryptocurrency wallets, perform distributed denial of service (DDoS) attacks, and to carry out other malicious tasks. DiamondFox allows cyber criminals to choose which plug-ins to keep activated and see infection statistics in real-time.

Reports & references

  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Diamondfox (report)
  • blog.malwarebytes.com — Diamond Fox P2 (report)
  • blog.malwarebytes.com — Diamond Fox P1 (report)
  • fr3d.hk — Diamondfox Bank Robbers Will Be Replaced (report)
  • github.com — D%C4%B0Amondfox%20Technical%20Analysis%20Report (report)
  • blog.checkpoint.com — Diamondfox Modular Malware One Stop Shop (report)
  • scmagazine.com — 578478 (report)
  • blog.cylance.com — A Study In Bots Diamondfox (report)

External references