Malware.View on attack.mitre.org
Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured list of extensions defined by the attacker. The Diavol Ransomware-as-a Service (RaaS) program is managed by Wizard Spider and it has been observed being deployed by Bazar.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Diavol can enumerate victims' local and external IPs when registering with C2. |
| T1018 Remote System Discovery |
Diavol can use the ARP table to find remote hosts to scan. |
| T1021.002 SMB/Windows Admin Shares |
Diavol can spread throughout a network via SMB prior to encryption. |
| T1027 Obfuscated Files or Information |
Diavol has Base64 encoded the RSA public key used for encrypting files. |
| T1027.003 Steganography |
Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| T1033 System Owner/User Discovery |
Diavol can collect the username from a compromised host. |
| T1057 Process Discovery |
Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system. |
| T1071.001 Web Protocols |
Diavol has used HTTP GET and POST requests for C2. |
| T1082 System Information Discovery |
Diavol can collect the computer name and OS version from the system. |
| T1083 File and Directory Discovery |
Diavol has a command to traverse the files and directories in a given path. |
| T1105 Ingress Tool Transfer |
Diavol can receive configuration updates and additional payloads including wscpy.exe from C2. |
| T1106 Native API |
Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack. |
| T1135 Network Share Discovery |
Diavol has a `ENMDSKS` command to enumerates available network shares. |
| T1485 Data Destruction |
Diavol can delete specified files from a targeted system. |
| T1486 Data Encrypted for Impact |
Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64". |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.