Uptime Hamster: 10d 18h 23mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza diavol

diavol

2 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Aliases: DEV-0569, Conti, Quantum, Black Byte, Diavol, Black Basta, Ryuk (como FIN12)
Ver en IntelTracker → APTTrail →
Diavol is a ransomware group that first emerged in May 2021, closely linked to the cybercrime organization Wizard Spider, also known as the Trickbot Group. Initially, there was some ambiguity regarding its data exfiltration capabilities, but it was later confirmed that the group does steal data from victims. Its primary motivation is financial gain through ransomware attacks and double extortion. Diavol distinguishes itself by utilizing user-mode Asynchronous Procedure Calls (APCs) with an asymmetric encryption algorithm, a method slower than typical symmetric algorithms, and by storing its core routines within bitmap images to complicate analysis. The group is notable for its willingness to negotiate ransom demands, which typically range from $10,000 to $500,000, often accepting lower payments compared to other prominent ransomware operations. The group operates under aliases such as LockMainDIB and Enigma, clarifying its distinct, albeit connected, identity within the broader cybercr

Aliases del actor

DEV-0569ContiQuantumBlack ByteDiavolBlack BastaRyuk (como FIN12)

Actores similares

blackbastaransomware · 523blackbyteransomware · 147BlackBastaactor · 2blackbyte-cruxactor · 1blacksuitransomware · 184blacknevasransomware · 16blackwaterransomware · 11black-xactor · 8blackshrantacransomware · 8blackoutransomware · 5

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknown7ypnbv3snejqmgce4kbewwvym4cm5j6lkzf2hra2hyhtsvwjaxwipkyd.oniondiavol
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: diavol
Tecnicas MITRE
T1486, T1047, T1027, T1041
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

IndiaRussian FederationUkraineUnited States

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersManufacturingConstructionPublic AdministrationEducational ServicesEnergy & Utilities InsurancePeriodical PublishersData Processing, Hosting, and Related Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com