DiamondFox was marketed on underground forums as a modular malware-as-a-service platform that lowered the barrier to entry for cybercriminals by bundling espionage, credential theft, cryptocurrency wallet theft, self-propagation, and DDoS functions into a plugin-driven botnet. Check Point linked the offering to a seller using the alias "Edbitss", who advertised the malware on both clear-web and darknet forums, provided updates and customer support, and operated a management panel that let buyers track infections and control plugins across compromised hosts.
Technical analysis of the Crystal variant showed the malware installing itself as explorer.exe in the Windows Startup folder, dropping a hidden copy, creating autorun Registry entries for persistence, and attempting to reach command-and-control endpoints such as gate.php. Researchers found the examined sample’s main C2 offline, but spot checks of broader indicators revealed active DiamondFox panels and installers in the wild, suggesting use by multiple operators; the newer build also introduced a different packer, additional persistence keys, a domain generation algorithm, and an improved cryptocurrency wallet stealer.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository named "Diamondfox-Technical-Analysis-Report" showed a PDF titled "DİAMONDFOX Technical Analysis Report.PDF" uploaded with the commit message "Add files via upload." The visible page exposed repository metadata but not the report's technical contents.
A DiamondFox Crystal sample analyzed by researchers carried a compile timestamp of 2016-06-02 19:59:10. The sample was a Visual Basic binary with anti-reversing disabled.
Researchers found that the DiamondFox seller established a clear-web landing page on a blogspot.mx domain in March 2016. The page was cited as one indicator that the operator might have been located in Mexico despite claims of being in Russia.
Check Point reported that DiamondFox was being sold as a modular malware-as-a-service offering by a vendor using the alias "Edbitss." The report detailed its plugin-based capabilities for espionage, credential theft, wallet theft, self-propagation, and DDoS, and said Check Point products detected known variants and blocked C2 communications.
An analysis described DiamondFox Crystal's persistence, packing changes, domain generation algorithm, and improved cryptocurrency wallet stealer. It also noted that the examined sample's primary command-and-control server was inactive at the time of analysis.
During analysis, researchers found a small number of active DiamondFox-related panels and installers while spot-checking a larger IOC list of more than 600 entries. This indicated the malware was in active use by multiple operators even though many listed panels were dead or removed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceblog.checkpoint.com
Open sourcescmagazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.