Ransomware Group intelligence
Diavol
ActiveTrack Diavol with 0 published victims and 1 known leak locations in a single intelligence view.
Overview
Diavol is tracked by Breach House as a ransomware group with 0 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 6h ago | 7ypnbv3snejqmgce4kbewwvym4cm5j6lkzf2hra2hyhtsvwjaxwipkyd.onion |
Top Activity Sectors
No sector intelligence available.
Typical Attacks (19)
▼How Diavol typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Diavol.
-
T1106 Native API Execution
What they do: Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1027 Obfuscated Files or Information Stealth
What they do: Diavol has Base64 encoded the RSA public key used for encrypting files.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1027.003 Steganography Stealth
What they do: Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.
What that means: Adversaries may use steganography techniques in order to prevent the detection of hidden information.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Diavol can attempt to stop security software.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1016 System Network Configuration Discovery Discovery
What they do: Diavol can enumerate victims' local and external IPs when registering with C2.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Diavol can use the ARP table to find remote hosts to scan.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Diavol can collect the username from a compromised host.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1057 Process Discovery Discovery
What they do: Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Diavol can collect the computer name and OS version from the system.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Diavol has a command to traverse the files and directories in a given path.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Diavol has a `ENMDSKS` command to enumerates available network shares.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Diavol can spread throughout a network via SMB prior to encryption.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1071.001 Web Protocols Command and Control
What they do: Diavol has used HTTP GET and POST requests for C2.
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1485 Data Destruction Impact
What they do: Diavol can delete specified files from a targeted system.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1486 Data Encrypted for Impact Impact
What they do: Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64".
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Diavol will terminate services using the Service Control Manager (SCM) API.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Diavol can delete shadow copies using the `IVssBackupComponents` COM object to call the `DeleteSnapshots` method.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted!
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (7)
▼Software Diavol has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
diavol2.txt
You've been hacked. All your corporate network servers and workstations are encrypted. Your company is a victim of double extortion ransomware attack. What is it? Basically it means that not only your data is encrypted, but it's also have been exfiltrated from your network. Double Extortion attack explained in details : https://www.zscaler.com/resources/security-terms-glossary/what-is-double-extortion-ransomware ===== What now? ===== If you want your network to be fully operational again and if you want us not to publish all files we've taken : 1. Download Tor Browser from original site : https://torproject.org 2. Open this url in Tor Browser and visit this website : hxxps://7ypnbv3snejqmgce4kbewwvym4cm5j6lkzf2hra2hyhtsvwjaxwipkyd\.onion/ 3. Enter this key : [snip] If you've done everything correctly - now you are able to contact us and take a chance to leave this all behind for a reasonable fee. NOTE : If TOR network is unavailable by any reason - you can use any VPN service to solve it.
diavol1.txt
# What happened? # Your network was ATTACKED, your computers and servers were LOCKED. You need to buy decryption tool for restore the network. Take into consideration that we have also downloaded data from your network that in case of not making payment will be published on our news website. # How to get my files back? # 1. Download Tor Browser and install it. 2. Open the Tor Browser and visit our website - hxxps://r2gttyb5vqu6swf5\.onion/eE5PWTlvbWc6OmxGYW5HM0dMd3FIRGQyUFo=/%cid_bot% Tor Browser may be block in your country or corporate network. Try to use Tor over VPN!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (0)
Search, filter and paginate the victim timeline for Diavol.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|