Diavol is a ransomware operation active in the Conti-era cybercrime ecosystem and closely associated with the broader cluster of actors, affiliates, and initial-access providers that also supported Conti intrusions. It has been linked to campaigns in which initial access was obtained through phishing-delivered malware and loaders, including activity overlapping with operators such as Exotic Lily and later Bumblebee delivery chains. Diavol has been referenced alongside other enterprise-targeting ransomware crews and appears to have relied on the same criminal access marketplace and post-compromise tooling common to major big-game ransomware operations of 2021–2022. Observed tradecraft associated with Diavol-related intrusions includes credential theft from domain controllers, use of LSASS dumping for credential access, deployment of remote administration tools for persistence, and extensive post-exploitation using Cobalt Strike. Operators in related cases used scheduled tasks, registry-based persistence, new account creation, and third-party remote access software to maintain access. Discovery and lateral movement behaviors in the same intrusion set included Active Directory reconnaissance, use of native Windows administration utilities, and movement via RDP, WMI, PsExec, and Cobalt Strike. Data exfiltration was also observed in ransomware casework from this ecosystem, consistent with modern extortion-oriented operations. Diavol also includes recovery-inhibition functionality. It can delete Volume Shadow Copies by invoking the IVssBackupComponents COM interface and calling DeleteSnapshots, a technique intended to hinder restoration and increase pressure on victims. Reporting has also noted connections between Diavol, the Karakurt extortion group, and the Conti ransomware group, reinforcing the view that Diavol operated within an interconnected financially motivated ransomware and extortion landscape rather than as an isolated actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware affiliates observed using BumbleBee as an initial access loader before deploying follow-on payloads and ransomware.
Ransomware group referenced as connected to Karakurt and Conti through prior blockchain analysis (2022).
Referenced as a subgroup-like ransomware operation associated with Conti for comparison purposes.
Follow-on ransomware actor/group linked in the content to campaigns enabled by Bumblebee-delivered initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.