Ransomware

FBI links the Diavol ransomware to the TrickBot gang

0

The Federal Bureau of Investigation (FBI) linked the Diavol ransomware operation to the infamous TrickBot gang, the group which is behind the TrickBot banking trojan.

Diavol is associated with developers from the Trickbot Group, who are responsible for the Trickbot Banking Trojan. Diavol encrypts files solely using an RSA encryption key, and its code is capable of prioritizing file types to encrypt based on a pre-configured list of extensions defined by the attacker.

The gang’s ransom demands ranged from $10,000 to $500,000, but the threat actors have engaged victims in ransom negotiations and accept lower payments.

The FBI has not yet observed Diavol leak victim data, despite ransom notes including threats to leak stolen information.

TrickBot is a popular banking Trojan which was active since October 2016 and was continuously upgraded by implementing new features.

The developers continue to offer the botnet through a multi-purpose malware-as-a-service (MaaS) model. Threat actors leverage the botnet to distribute a broad range of malware including info-stealer and ransomware such as Conti and Ryuk.

The Trickbot botnet has already infected more than a million computers. The gang is also responsible for the development of the BazarBackdoor and Anchor backdoors.

In July, researchers from Fortinet first spotted the Diavol ransomware, and speculated it might have been developed by Wizard Spider, the cybercrime gang behind the TrickBot botnet.

Similarities between Diavol and Conti threats were spotted, but unlike Conti, Diavol doesn’t avoid infecting Russian victims.

IBM X-Force researchers conducted a new analysis of an old variant of the threat that appears to be a development version used for testing purposes.

The comparison of the two versions allowed the researchers to get insight into the development process of Diavol and of future versions of the malware.

The analysis conducted by IBM X-Force researchers reinforced the link between Diavol ransomware and the TrickBot malware.

FBI’s has now provided technical details about the Diavol Ransomware and its link to the TrickBot gang. The FBI’s advisory also contains indicators of compromise along with mitigations for Diavol.

The FBI encourages victims of the gang to report information concerning suspicious or criminal activity to their local FBI field office. They also urge all victims of the Diavol operation, to notify law enforcement of attacks.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Red Cross cyberattack exposes data of 515,000 people

Previous article

McAfee Agent bug exploited to gain Windows SYSTEM privileges

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *