DiamondFox is a modular malware-as-a-service botnet sold on underground forums and associated with the actor alias Edbitss. It is designed as a plugin-based platform that allows operators to tailor functionality per victim through a management panel that provides infection statistics and plugin control. Reported capabilities include credential theft, keylogging, cryptocurrency wallet theft, espionage-oriented collection, monetary theft, self-spreading, and distributed denial-of-service activity. DiamondFox has also been linked to removable-media and social-network propagation features, and a 2017 version reportedly included a point-of-sale plugin distinct from GlitchPOS. The malware has been marketed with ongoing updates and customer support, reflecting a commercial crimeware model aimed at a broad range of buyers, including comparatively low-skill operators. DiamondFox primarily targets Windows environments and is notable for its extensible architecture, operator panel, and use as a general-purpose criminal botnet platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DiamondFox, a modular botnet offered for sale on various underground forums, is an outstanding demonstration of the many advantages of this business module.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The main purpose of this malware is to steal credit card numbers (Track1 and Track2) from the memory of the infected system.
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
diamondfox_panels - pan-unit42 - feed format: freetext
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
A botnet family linked in the article through shared panel/code similarities and prior POS functionality; presented as related background to GlitchPOS rather than the main malware under analysis.
A modular malware-as-a-service botnet sold on underground forums. It provides plugin-based capabilities including keylogging, browser password theft, cryptocurrency wallet theft, DDoS attacks, self-spread via removable devices and social networks, and can support credential theft, monetary theft, or tailored espionage campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.