Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors diavol

Description

A ransomware with potential ties to Wizard Spider. 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Diavol is a medium-sophisticated criminal threat actor associated with ransomware operations, likely linked to the Wizard Spider group. They primarily target organizations for financial gain through ransom demands, utilizing phishing and exploit techniques.

Goals & Targeting

With a focus on financial gain, Diavol targets industries with significant financial resources, such as healthcare and education. Their victims are typically organizations that can afford the ransom and may lack robust security measures, making them prime candidates for exploitation.

Enhanced Description

Diavol operates as a ransomware group, potentially connected to Wizard Spider. Their modus operandi involves targeting organizations across various sectors to extort ransoms. Using advanced phishing tactics and exploit tools, they deploy ransomware to encrypt systems, demanding cryptocurrency payments for decryption keys.

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1070.002
T1059.003
T1566.001

Software / Tooling

Cobalt Strike
Custom Ransomware

Campaigns & Victims

Diavol has conducted multiple ransomware campaigns, leveraging their technical capabilities to target various sectors. Their operations often involve high-volume attacks with notable increases in activity during certain periods.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of cryptocurrency wallets for payments
  • Encrypted files with specific extensions

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Perform regular system backups and ensure they are offline-secured
  • Provide employee training on recognizing suspicious emails and attachments

Suggested Tags

Ransomware
Crime
Financial Sector

Confidence Assessment

Low confidence in specific details due to limited data. This assessment is based on inferred behaviors from linked groups and general ransomware tactics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Crime
Financial Sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.