The FBI’s warning about Diavol ransomware is a historical advisory, not evidence that the malware is active today. In a January 19, 2022, FLASH coordinated with DHS/CISA, the FBI described Diavol’s behavior, possible indicators, and steps organizations could take to reduce ransomware risk. It said it first learned of Diavol in October 2021 and associated the malware’s developers with the Trickbot Group.
What the FBI’s Diavol advisory reported
The FBI’s five-page FLASH CU-000161-MW, “Indicators of Compromise Associated with Diavol Ransomware”, is dated January 19, 2022. Its findings describe what the agency had observed at that time; they do not establish Diavol’s present-day prevalence or activity.
The advisory says Diavol encrypts files using an RSA key and can prioritize file types using an extension list configured by the attacker. It appends .lock64 to encrypted files. The malware can also terminate processes and services, and uses Microsoft CryptoAPI functions, according to the FBI.
For identification and communication, the malware was reported to create a system or bot identifier based on a hostname, username, Windows version, and a 32-character string. It attempts to contact a hardcoded command-and-control address and, after successful registration, requests updated configuration.
#1 Best Overall
What symptoms may point to Diavol—and their limits
- Encrypted files ending in
.lock64. - A black desktop background and a ransom note named
README-FOR-DECRYPT.txt; the note directs victims to a Tor site. - Other directories, filenames, whitelisted extensions and paths, or a PDB path listed in the dated FBI advisory.
These are clues, not a complete detection rule or proof of compromise. The FBI cautions that indicators—particularly nondeterministic or short-lived ones such as filenames or IP addresses—may not be indicative of compromise on their own. Assess them alongside the organization’s full security picture and have incident responders investigate suspicious activity.
What the FBI said about demands and data theft
The FBI reported ransom demands ranging from $10,000 to $500,000 in its January 2022 advisory and said actors had negotiated lower payments. That range is a report of demands observed at the time, not a typical or current price. The agency had not observed Diavol actors leak victim data as of that advisory, although ransom notes threatened disclosure.
Rank #2
How organizations can reduce ransomware risk
The advisory recommends layered measures that limit an attacker’s ability to reach systems and backups, and help organizations recover. In particular, backup copies should be separate from production systems and protected against modification or deletion.
- Keep protected, separated backups. Maintain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location. The FBI gives hard drives, storage devices, and cloud storage as examples. Keep offline backups, password-protect offline copies, and ensure critical copies cannot be modified or deleted from the systems holding the data.
- Limit the spread of an intrusion. Segment networks, disable unused ports, and apply least privilege to accounts and systems.
- Keep systems maintained. Install and regularly update antivirus software, enable real-time detection, and promptly patch operating systems, software, and firmware.
- Review access and accounts. Check domain controllers, servers, workstations, and Active Directory for new or unrecognized accounts. Audit administrative privileges.
- Strengthen user and email defenses. Use multifactor authentication where possible, provide cybersecurity awareness training, consider external-email banners, and disable hyperlinks in received email, as the advisory recommends.
An external hard drive can be one medium for an offline backup, but it is not a Diavol blocker or a complete backup plan. Organizations still need appropriate separation, access controls, capacity, recovery procedures, and restore validation; the FBI advisory does not specify product models or comparative performance.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
What to do if Diavol is suspected
- Escalate through your incident-response process. Preserve relevant evidence and assess activity across the environment rather than relying on one filename, address, or ransom note.
- Contact the local FBI field office. The FBI requested reports whether or not a victim paid. When available, include the date, time, location, type of activity, people and equipment involved, organization name, and a point of contact.
- Preserve requested artifacts where safe and feasible. The advisory asks for boundary logs showing communications to and from foreign IP addresses, Bitcoin wallet information, the decryptor file, and/or a benign sample of an encrypted file.
What the FBI said about paying a ransom
The advisory states, “The FBI does not encourage paying ransoms.” It explains that payment cannot guarantee recovery and may embolden or fund criminal actors. The FBI acknowledges that organizations facing operational paralysis may weigh difficult options, and urges reporting to a local field office regardless of the payment decision.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

