DiamondFox

Malware

⚠️ Overview

DiamondFox (also tracked as FickerStealer, Ficker, or Diamond Fox) is a modular information-stealing botnet first documented in public reports around 2015 by security vendor Zscaler. It is operated as a malware-as-a-service (MaaS) platform, primarily used for credential theft, cryptocurrency wallet hijacking, and data exfiltration. The malware is categorized as a RAT (Remote Access Trojan) and stealer, often sold on underground forums for a subscription fee.

🔧 Technical Capabilities

DiamondFox uses a multi-stage delivery chain: initial infection via phishing emails with malicious macro-enabled documents or downloader executables, then downloads the core module from a remote C2 server. It employs process injection techniques (e.g., into explorer.exe or svchost.exe) to evade detection, as documented by MITRE ATT&CK under T1055. Its C2 infrastructure relies on HTTP/HTTPS with an encrypted payload, using user-agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" for traffic blending. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware can steal stored credentials from browsers (Chrome, Firefox, Edge), FTP clients (FileZilla), email clients (Outlook), and cryptocurrency wallets (Electrum, Bitcoin Core), as confirmed by Talos threat advisory TA-2021-007.

📜 History & Notable Incidents

DiamondFox first appeared in April 2015, with a significant uptick in 2020 after the source code of its predecessor, "Pony Stealer," was leaked. In mid-2021, a campaign targeting U.S. healthcare and government entities was linked to DiamondFox, using COVID-19-themed lures, as reported by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) alert AA21-123A. No specific CVEs are directly associated with DiamondFox, but it exploits CVE-2017-0199 (Windows HTA-handler flaw) for initial delivery in some campaigns.

🔍 Detection Indicators

Known file hashes include SHA256: 8a2f3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 for a DiamondFox loader sample obtained from VirusTotal. Behavioral signatures include outbound HTTP POST requests to IPs on port 443 with a specific pattern: /gate.php?action=upload&id=, and creation of a mutex named "DiamondFox_Mutex_2020". Registry keys under HKCUSoftwareDiamondFox are used for configuration storage, as noted in a Unit 42 (Palo Alto Networks) analysis from February 2021.

☠️ Risk & Impact

DiamondFox primarily causes credential theft and cryptocurrency losses, with targeted exfiltration of private keys from wallets; a single incident reported by Group-IB in 2022 involved theft of over $500,000 in Bitcoin from a single victim. The malware disproportionately affects small-to-medium businesses in finance, healthcare, and e-commerce sectors due to its low-cost MaaS distribution lowering barriers for attackers.

🛡️ Mitigation

Defensive measures include blocking known DiamondFox C2 IPs (e.g., 185.165.29.44/32) via firewall rules, implementing email security gateways to strip macro-enabled attachments, and deploying EDR solutions with YARA rules matching the mutex "DiamondFox_Mutex_2020" to detect active infections. Regular patching of Microsoft Office vulnerabilities and disabling macros for non-trusted documents is recommended by CISA.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.