Diavol is a Windows ransomware family associated with the TrickBot and Conti cybercrime ecosystem and operated by actors tracked as DEV-0193, with reporting also linking its distribution to GOLD ULRICK. It emerged as one of the ransomware strains used alongside or after Ryuk and Conti within the same broader criminal network.
Diavol encrypts victim files using RSA through the Windows CryptEncrypt API and has been observed appending a distinct encrypted-file extension. It also inhibits recovery by deleting Volume Shadow Copies through the IVssBackupComponents COM interface and can delete selected files from compromised systems. Post-encryption, it modifies the victim desktop by creating a ransom-themed wallpaper and changing the background to display an extortion message.
The malware includes multiple pre-encryption and operational capabilities that support enterprise-wide impact. It can collect the username from a compromised host, communicate with command-and-control infrastructure over HTTP using GET and POST requests, attempt to stop security software, and use the ARP table to identify remote hosts for scanning. Diavol has also been observed spreading through Windows SMB shares prior to encryption, enabling propagation across internal networks.
Diavol is best understood as part of the financially motivated, human-operated ransomware tradecraft surrounding TrickBot and Conti rather than as a standalone commodity strain. Its observed behavior aligns with double-extortion-era ransomware operations that combine host discovery, defense evasion, lateral spread, recovery inhibition, and disruptive victim messaging to maximize pressure on targeted organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DEV-0193 managed the Ryuk RaaS program before the latter’s shutdown in June 2021, and Ryuk’s successor, Conti as well as Diavol.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
“Sandworm Team deployed CaddyWiper…to wipe files…along with mapped drives, and physical drive partitions… AcidPour…perform an in-depth wipe…through either data overwrite or calling various IOCTLS… AcidRain performs an in-depth wipe… Apostle…data destruction tool… writes random data… resizing… deleting… BlackEnergy 2 contains a ‘Destroy’ plug-in… overwriting file contents… HermeticWiper… recursively wipe folders and files… Industroyer’s data wiper module clears registry keys and overwrites… KillDisk deletes system files to make the OS unbootable… Shamoon attempts to overwrite operating system files and disk structures… WhisperGate… corrupt files by overwriting…”
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain financially linked in the content to Stern’s activity.
Ransomware family explicitly mentioned as associated with TrickBot.
Ransomware referenced as one of the malware variants used by the TrickBot/Conti-linked group.
Ransomware that deletes shadow copies through the IVssBackupComponents COM interface.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.