Diavol

S0659

Malware.View on attack.mitre.org

About this malware

Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured list of extensions defined by the attacker. The Diavol Ransomware-as-a Service (RaaS) program is managed by Wizard Spider and it has been observed being deployed by Bazar.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1016
System Network Configuration Discovery

Diavol can enumerate victims' local and external IPs when registering with C2.

T1018
Remote System Discovery

Diavol can use the ARP table to find remote hosts to scan.

T1021.002
SMB/Windows Admin Shares

Diavol can spread throughout a network via SMB prior to encryption.

T1027
Obfuscated Files or Information

Diavol has Base64 encoded the RSA public key used for encrypting files.

T1027.003
Steganography

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

T1033
System Owner/User Discovery

Diavol can collect the username from a compromised host.

T1057
Process Discovery

Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system.

T1071.001
Web Protocols

Diavol has used HTTP GET and POST requests for C2.

T1082
System Information Discovery

Diavol can collect the computer name and OS version from the system.

T1083
File and Directory Discovery

Diavol has a command to traverse the files and directories in a given path.

T1105
Ingress Tool Transfer

Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.

T1106
Native API

Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack.

T1135
Network Share Discovery

Diavol has a `ENMDSKS` command to enumerates available network shares.

T1485
Data Destruction

Diavol can delete specified files from a targeted system.

T1486
Data Encrypted for Impact

Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64".

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. DFIR Diavol Ransomware December 2021 Open source
    DFIR Report. (2021, December 13). Diavol Ransomware. Retrieved March 9, 2022.
  2. FBI Flash Diavol January 2022 Open source
    FBI. (2022, January 19). Indicators of Compromise Associated with Diavol. Retrieved November 17, 2024.
  3. Fortinet Diavol July 2021 Open source
    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.
  4. Microsoft Ransomware as a Service Open source
    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.