Back to Resources

SentinelOne Vs. Diavol Ransomware – Kill and Quarantine

⚔️ Watch how SentinelOne kills and quarantines Diavol ransomware. Diavol is a relatively new ransomware family, having been first seen in the wild around June-July 2021. The malware is ‘Trickbot-adjacent’ and believed to be the cybercrime organization responsible for the development and maintenance of Trickbot (often referred to as Wizard Spider).

Upon execution, Diavol (like Trickbot) will check-in to the controlling C2 server. A set of unique IDs is then created (Group/Bot) establishing the necessary relationships to the rest of the infected ecosystem. Diavol is capable of terminating processes, customized encryption targeting, and dynamic configuration changes/updates. In addition, attackers can pre-package/pre-configure specific paths or extension lists for encryption on the victims.

#Diavol #cybersecurity #infosec #ransomware #malware

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.