The Government of India issued a warning through the Indian Computer Emergency Response Team (CERT-In) after the discovery of a new type of ransomware that spreads via email. The ransomware targets Windows computers and once the payload is delivered it locks the computer remotely and demands money from the user. For those who are unaware, ransomware is a type of advanced malware that locks the entire system or critical files and then extorts users to pay a ransom (via Bitcoins). If the user does not pay the ransom, the files are usually deleted or the computer may become unusable.
See also: Report: Increase in attacks by ransomware group PYSA, double extortion technique and new tactics

CERT-In in its latest advisory warned about the ransomware called Diavol. According to the advisory, the ransomware has been compiled with the Microsoft Visual C/C++ Compiler.
See also: Windows 10 21H2 also gains ransomware protection
According to CERT-In, the Diavol malware spreads via email, which includes a link to OneDrive. The OneDrive link directs the user to download a compressed file that includes an ISO file containing an LNK file and a DLL file. Once opened (attached) on the users' system, the LNK file masquerading as a Document lures the user to click. Once the user executes the LNK file, the infection will start from the malware.
What happens after the Diavol ransomware infects a computer
After the Diavol malware infects a computer, it performs pre-processing on the victim's system, including registering the victim's device with a remote server, terminating running processes, finding local drives and files on the system for encryption, and preventing recovery by deleting shadow copies. Files are then locked and the desktop wallpaper is changed with a ransom message.

How to stay safe from the ransomware Diavol
In order to stay safe from this ransomware, it is important that users update the software and operating systems with the latest code updates. Also, all incoming and outgoing email messages should be scanned to detect threats and filter executable files from reaching end users.
See also: TellYouThePass ransomware exploits Log4Shell vulnerability
Other methods include network segmentation and security zoning – these help protect sensitive information and critical services. Also helpful is separating the management network from business processes with physical controls and virtual LANs.
Information source: news18.com
