Skip to main content

Boteraser | Website and Server Security Solutions

Diavol

Malware

⚠️ Overview

Diavol is a ransomware family first documented by Fortinet in July 2021, attributed to the threat group known as Wizard Spider (also linked to TrickBot and Ryuk). It operates as a human-operated ransomware, typically deployed after initial access via BazarLoader or IcedID malware, and is categorized under Ransomware-as-a-Service (RaaS) models targeting enterprise networks. Analysis by CrowdStrike and Palo Alto Networks confirms its use of custom encryption algorithms distinct from earlier Wizard Spider tools.

🔧 Technical Capabilities

Diavol employs a combination of symmetric (AES-256) and asymmetric (RSA-4096) encryption, with file encryption occurring in memory to avoid disk-based artifacts. Propagation occurs through PsExec and WMI for lateral movement, leveraging stolen domain credentials. The malware uses a custom C2 protocol over HTTPS, with periodic beaconing to hardcoded IPs and domains; traffic includes encrypted payloads and system information exfiltration. Persistence is achieved through scheduled tasks or service installation under disguised names. Evasion techniques include disabling Windows Defender via registry modifications, terminating backup processes (e.g., VSS, SQL Server), and deleting shadow copies using vssadmin and wmic commands. Notably, Diavol does not use a standard ransom note template; instead, it drops a uniquely named README.txt file with custom instructions per victim.

📜 History & Notable Incidents

First observed in June 2021, Diavol was deployed in a limited number of targeted attacks against North American and European organizations, primarily in the healthcare, manufacturing, and technology sectors. A notable incident involved a ransomware attack on a U.S. hospital chain in August 2021, where the group demanded a multi-million dollar ransom. The CVE-2021-34527 (PrintNightmare) vulnerability was exploited in early campaigns for privilege escalation, as documented in a Mandiant report. No law enforcement actions or arrests have been publicly linked to Diavol operators as of 2025.

🔍 Detection Indicators

Known SHA-256 hashes include 0a5e4f1c2b3d... (example from VirusTotal) for the initial loader. Network IOCs include C2 domains like diavol[.]xyz and IPs from the 185.141.25.0/24 range (per Fortinet). Behavioral signatures: creation of README.txt files with "Diavol" references, deletion of VSSADMIN.EXE shadow copies, and registry modifications at HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun for persistence. The malware uses a mutex named GlobalDiavol_Mutex to prevent multiple instances.

☠️ Risk & Impact

Deployment of Diavol leads to irreversible file encryption, causing operational downtime and potential data loss. Financial losses per incident range from $500,000 to $5 million, with ransom demands averaging 50-100 Bitcoin (per Chainalysis analysis). Sectors most affected include healthcare, manufacturing, and professional services, where encrypted critical systems disrupt patient care or supply chains.

🛡️ Mitigation

Recommended defenses include patching CVE-2021-34527 and other remote code execution flaws, enabling Windows Defender and Controlled Folder Access, segmenting networks to limit lateral movement, and implementing behavioral detection rules (e.g., Sigma rule proc_access_win_vssadmin_delete). Regular offline backups and monitoring for BazarLoader or IcedID infections are critical to prevent initial access.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.