Diavol is a ransomware family first documented by Fortinet in July 2021, attributed to the threat group known as Wizard Spider (also linked to TrickBot and Ryuk). It operates as a human-operated ransomware, typically deployed after initial access via BazarLoader or IcedID malware, and is categorized under Ransomware-as-a-Service (RaaS) models targeting enterprise networks. Analysis by CrowdStrike and Palo Alto Networks confirms its use of custom encryption algorithms distinct from earlier Wizard Spider tools.
Diavol employs a combination of symmetric (AES-256) and asymmetric (RSA-4096) encryption, with file encryption occurring in memory to avoid disk-based artifacts. Propagation occurs through PsExec and WMI for lateral movement, leveraging stolen domain credentials. The malware uses a custom C2 protocol over HTTPS, with periodic beaconing to hardcoded IPs and domains; traffic includes encrypted payloads and system information exfiltration. Persistence is achieved through scheduled tasks or service installation under disguised names. Evasion techniques include disabling Windows Defender via registry modifications, terminating backup processes (e.g., VSS, SQL Server), and deleting shadow copies using vssadmin and wmic commands. Notably, Diavol does not use a standard ransom note template; instead, it drops a uniquely named README.txt file with custom instructions per victim.
First observed in June 2021, Diavol was deployed in a limited number of targeted attacks against North American and European organizations, primarily in the healthcare, manufacturing, and technology sectors. A notable incident involved a ransomware attack on a U.S. hospital chain in August 2021, where the group demanded a multi-million dollar ransom. The CVE-2021-34527 (PrintNightmare) vulnerability was exploited in early campaigns for privilege escalation, as documented in a Mandiant report. No law enforcement actions or arrests have been publicly linked to Diavol operators as of 2025.
Known SHA-256 hashes include 0a5e4f1c2b3d... (example from VirusTotal) for the initial loader. Network IOCs include C2 domains like diavol[.]xyz and IPs from the 185.141.25.0/24 range (per Fortinet). Behavioral signatures: creation of README.txt files with "Diavol" references, deletion of VSSADMIN.EXE shadow copies, and registry modifications at HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun for persistence. The malware uses a mutex named GlobalDiavol_Mutex to prevent multiple instances.
Deployment of Diavol leads to irreversible file encryption, causing operational downtime and potential data loss. Financial losses per incident range from $500,000 to $5 million, with ransom demands averaging 50-100 Bitcoin (per Chainalysis analysis). Sectors most affected include healthcare, manufacturing, and professional services, where encrypted critical systems disrupt patient care or supply chains.
Recommended defenses include patching CVE-2021-34527 and other remote code execution flaws, enabling Windows Defender and Controlled Folder Access, segmenting networks to limit lateral movement, and implementing behavioral detection rules (e.g., Sigma rule proc_access_win_vssadmin_delete). Regular offline backups and monitoring for BazarLoader or IcedID infections are critical to prevent initial access.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.