IBM X-Force analysis of an older Diavol ransomware sample found stronger technical ties to the TrickBot gang, adding weight to long-standing suspicions that the malware was developed by or closely associated with the same operators. Researchers said a development-stage sample submitted to VirusTotal in January 2021, with a reported March 2020 compilation date, used a Bot ID format that closely matched TrickBot and resembled Anchor DNS, another tool linked to the group.
The sample also showed Russian-language HTTP header preferences and code apparently designed to avoid infecting systems in Russia and CIS countries, patterns that align with previous TrickBot-linked activity. IBM said the evidence stops short of definitive attribution, but the findings reinforce earlier reporting that Diavol shares behavioral similarities with Conti and appears to have evolved from an earlier development build into a later, fully weaponized ransomware variant.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Walmart Global Tech published analysis of a resurfacing of Diavol ransomware after an uptick in newer samples submitted to VirusTotal. The report detailed a 64-bit variant using hybrid XOR and RSA file encryption, identified the WARNING.txt ransom note and .bully extension, and published related IOCs.
Walmart Global Tech researchers identified Diavol-related infrastructure linking enigma-hq[.]net to diavol-news[.]net, with HTML referencing both a Tor mirror and a web mirror. The analysis described the site as a Diavol test leak site, providing new visibility into the group’s public-facing infrastructure.
Kryptos Logic reported that since June 2021, TrickBot has been deploying a revamped banking webinject module to infected systems. The module used Zeus-style webinject techniques and shared substantial code with IcedID's webinject component, indicating renewed bank-fraud activity.
The article states that the Diavol sample previously analyzed by Fortinet had a compilation date of April 30, 2021, representing a later and more weaponized variant than IBM's sample.
The Diavol sample later analyzed by IBM X-Force was submitted to VirusTotal on January 27, 2021.
IBM X-Force's later analysis said the older Diavol sample it examined had a reported compilation date of March 5, 2020, indicating an early development-stage version of the ransomware.
IBM X-Force published research reporting stronger technical links between Diavol ransomware and the TrickBot gang, including near-identical Bot ID formatting and other behavioral overlaps, while stopping short of definitive attribution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
securityintelligence.com
Open sourcemedium.com
Open sourcemedium.com
Open sourcechuongdong.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.