Diamond ransomware: what it is and how to remove it
Diamond is ransomware-type malware that can result in detrimental results to any Windows computer user. It usually sneaks in without users' realizing what has happened, but the effects on the affected system are almost instantaneous, and it is quickly too late to stop the spread of the virus.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Make sure nothing will rename more files to .diamond: an automatic scan checks the PC first.
Do it yourself · free Remove Diamond ransomware yourself 6 steps, about 18 minutes, no software needed.
Start the steps
Diamond ransomware: summary
| Name | Diamond ransomware |
|---|---|
| Type | Ransomware, file-locking malware |
| File extension | .diamond |
| Ransom note | HOW TO RECOVER ENCRYPTED FILES.TXT; the text is quoted in full below |
| Contact | diamondprotonmail.com@proton.me |
| File Recovery | Data backups are the only way to retrieve data. If you do not have access to such, or if it has been encrypted, your options for recovery are extremely limited; nevertheless, we recommend attempting them |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 11 more facts
| Detection names | No Microsoft detection name is known |
|---|---|
| Encrypted file extension | .diamond |
| Decryptor | No free decryptor is known for this variant; check No More Ransom (nomoreransom.org) for updates |
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Symptoms | Files renamed with a new extension and a ransom note left in folders |
| Evidence | 4 write-ups by security sites; no sample analysed yet |
| Encrypted files | .diamond |
| Free decryptor | No free decryptor is known (checked 7 October 2026) |
| First seen | 29 September 2022 |
| Facts checked | 7 October 2026 |
- File extension:
.diamond - Note file:
the ransom note
From our report of Sep 2022 · not reviewed since
More from our earlier report on Diamond ransomware
- Disconnect your computer from the internet and network, then do a full system scan with security software
- Malware may corrupt numerous essential system files, resulting in crashes, errors, and other issues.
- PC repair is an excellent way to replace any damaged system files automatically
- Free Ransomware Decryptors by Kaspersky
How Diamond ransomware behaves
From our report of Sep 2022 · not reviewed since
Diamond ransomware is a computer virus that makes files inaccessible until a ransom is paid
Diamond is ransomware-type malware that can result in detrimental results to any Windows computer user.
It usually sneaks in without users' realizing what has happened, but the effects on the affected system are almost instantaneous, and it is quickly too late to stop the spread of the virus.
Upon entry, ransomware would immediately look for personal files and encrypt them using a powerful encryption algorithm such as RSA. Encrypted data would immediately lose their default icons, which would be replaced by the blanks, their names would be scrambled and replaced by random strings, with the .diamond extension added to each file.
Unsurprisingly, the data would no longer be openable or modifiable, users would simply receive an error from Windows, which claims that the file can't be opened.
In order to restore data, victims are asked to pay a ransom in bitcoin, the precise sum of which is not disclosed in the ransom note HOW TO RECOVER ENCRYPTED FILES.TXT. However, Diamond ransomware authors provide a contact email diamondprotonmail.com@proton.me, which is meant to be used for communication purposes.

From our report of Sep 2022 · not reviewed since
Do not pay the ransom
The Diamond virus is a unique ransomware strain that has not been linked to other types of ransomware.
However, new and experimental ransomware appears after certain members leave a larger cybercriminal organization in order to earn money through unlawful activities. New individuals within the cybercriminal underworld may also establish their own operations as well.
Regardless of whether it's a new or established ransomware, all of them always deliver a ransom note upon finishing data encryption. Without the note, users would not be able to know who they should contact, what they have to do to restore files, or how to pay for it. HOW TO RECOVER ENCRYPTED FILES.TXT is there to answer all these questions:
Within the note, crooks provide a contact email that users should write to if they want to restore their files. To convince people that their best option is to pay, they even provide a free service of decryption for a few files. While it may serve as proof that decryption is possible, it is never a guarantee that the decryptor will be actually provided.
By adding the 72-hour mark for the price doubling, cybercriminals are attempting to reassure users to pay the ransom as soon as possible, which some might do when running out of time. However, we strongly recommend reconsidering this decision, as it may cost you your files and money. Besides, malicious actors would be affirmed that their illegal business schemes work as intended and create more malware to infect more users.

From our report of Sep 2022 · not reviewed since
How to deal with a Diamond ransomware attack
Instead of interacting with cybercriminals, we propose trying to recover files and repair your computer in different ways.
The first step is to ensure that the malware and all of its components are completely eliminated from the system using , , or another strong antivirus software. It is recommended you disconnect your computer from the internet/network before proceeding with this step.
It is possible to delete ransomware manually, but it's not recommended because you need comprehensive IT skills. Also, if you don't remove all the components of ransomware, all the incoming data could be encrypted as well, and your system might get infected again. It is worth mentioning that ransomware is commonly spread in a bundle along with other computer threats - there could be a data-stealer hidden somewhere on your system.
Diamond ransomware may tamper with security software, preventing its removal. If that happens, you should access Safe Mode and perform a full system scan from there:
Windows 7 / Vista / XP
Windows 10 / Windows 8
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing the F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.
- Right-click on the Start button and select Settings.
- On the left side of the window, pick Recovery.
- Click Restart now.
- Select Troubleshoot.
- Go to Advanced options.
- Select Startup Settings.
- Click Restart.
- Press 5 or click 5) Enable Safe Mode with Networking.


From our report of Sep 2022 · not reviewed since
Data restoration
Although file encryption and ransomware infection are two separate processes, the latter cannot happen without the former.
Upon infiltration, the virus infects the system first, encrypting data afterward. During this time, a specially generated and unique user ID is created, which also impacts the decryption key. This sequence of randomly-generated alphanumeric characters is what's required to unlock files, and only cybercriminals have access to it.
It is a huge misconception that locked data would be restored to its normal condition after a security software scan - the files will remain locked. There are a few possibilities of data recovery without paying crooks, and we discuss them below.
Before proceeding, you should make copies of all the locked files and place them on a separate medium. Encrypted files do not hold any malicious code, so they are safe to transfer. If you fail to do this, you could permanently corrupt data, and decryption would not be possible even with a working recovery tool.
Diamond is a new ransomware strain for which no free decryption tool is available at the moment. However, programming mistakes or bugs can occur when building ransomware, allowing security experts to create a free decryptor, or, in other cases, law authorities might capture the criminals' servers containing the keys.
- Download .
- Double-click the installer to launch it.
- Follow on-screen instructions to install the software.
- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders which you want the files to be recovered from.
- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.
- Press Scan and wait till it is complete.
- You can now pick which folders/files to recover - don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.
- No More Ransom Project
- Free Ransomware Decryption Tools from Emsisoft


From our report of Sep 2022 · not reviewed since
Take care of system health
When malware is installed on a computer, its operating system is altered.
An infection, for example, might modify the Windows registry database, damage essential bootup files, and other aspects, delete or corrupt DLL files, and so forth. Once a system file has been damaged by malware, antivirus software is ineffective in repairing it. As a result, users might experience various performance and stability issues, including crashes, BSODs, etc.
As a result, we strongly advise utilizing repair's one-of-a-kind, patented technology. Not only may it fix virus damage after the infection, but it can also remove malware that has already entered the system - it employs various engines for that. In addition, because malware infections do not always cause Windows issues, the software may also fix various unrelated problems.
The Diamond ransomware note
ALL YOUR DATA IS ENCRYPTED MILITARY ENCRYPTION !
Your PERSONAL id
If you want to get a decoder, you need to pay !
We only accept bitcoins !
With your mail diamondprotonmail.com@proton.me
we can decrypt 2 files proof of !
send us the id that is written in the ransom letter !
write id which is listed in the ransom note !
The price will be doubled in 72 hours !
How to remove Diamond ransomware
Tools you'll need
All of these are free except where noted. Download them on a clean device if the infected PC is offline.
- A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
- Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
- Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
- ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
- No More Ransom: the free decryptors from police and security companies; check it again every few months.
- Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.
How to remove Diamond ransomware and get your files back
Work in this order.
Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.
Step 1: Disconnect the PC and unplug backup drives
Unplug the network cable or turn off Wi-Fi, and disconnect USB drives, external disks and network shares, so Diamond ransomware cannot reach more files. Pause OneDrive, Google Drive or Dropbox sync, because synced folders upload the encrypted copies over the good ones.
Leave the PC on but offline while you read the next steps, since a restart can let the ransomware run again. This applies to Windows 11 and Windows 10 alike.

Windows 11: turn off Wi-Fi to take the PC offline. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 2: Save the ransom note and confirm the family
Your files now end in
.diamondand the instructions are inthe ransom note. Save both to a USB stick, a copy of the note and two small encrypted files, before anything else.On another device, check them with ID Ransomware or Crypto Sheriff: the family name decides which decryptor, if any, can help. Keep the note's ID and contact line for your report.

Windows 11: the ransom note and encrypted files to copy for identification. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 3: Check for a free decryptor
Our last check found that for Diamond ransomware, no free decryptor is known (checked 7 October 2026). Look again yourself in the No More Ransom list and the free decryptor pages of Emsisoft, Avast and Kaspersky, which add new families every year.
A decryptor needs the ransomware gone first, or it encrypts the files again. Keep at least one copy of the encrypted files on an external drive, even if no tool works yet.
Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 4: Remove the ransomware before you restore or decrypt
Removing Diamond ransomware does not bring the files back, but it has to come first. Start with Defender's Full scan, then the offline scan from the same Scan options page, which checks the disk before Windows loads.
If the scan cannot start, use Safe Mode with Networking. Delete the ransom notes only after you have saved a copy, because removal tools sometimes leave them behind on Windows 11 and Windows 10.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Look for shadow copies of the files
Windows keeps shadow copies for restore points and backups, and some ransomware fails to delete them.
vssadmin list shadowsin an administrator Command Prompt tells you at once whether any exist.If they do, right-click the folder that held your files, open Properties > Previous Versions, select a version from before the attack, and click Open to check it before you Restore or copy the files out. Windows 11 and Windows 10 both have the tab.

Windows 11: vssadmin list shadows shows whether shadow copies exist. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 6: Restore the files from a backup or recover deleted originals
A backup made before the attack is the surest way back. Connect it only once the PC is clean, then restore from File History, Windows Backup, OneDrive's Restore your OneDrive or your own external copies.
Without a backup, try file recovery: the originals that Diamond ransomware deleted may still be on the disk until something overwrites them. Install nothing new on the drive you want to recover from on the Windows 11 or Windows 10 PC.
Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix
Report it and recover your files
Report it
Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.
- United States
- FBI IC3 · FTC ReportFraud
- United Kingdom
- Report Fraud (formerly Action Fraud) · NCSC
- Australia
- ReportCyber (ASD)
- EU countries
- Europol: national reporting sites
Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.
Backups: the 3-2-1 rule
Keep three copies of files that matter, on two kinds of storage, with one copy offline or off-site.
A disk that stays plugged in is reached by malware like Diamond ransomware together with the PC; one you connect only for the backup is not.
On Windows 11, File History keeps versions on an external drive, and OneDrive keeps earlier versions of synced files. Before restoring anything, make sure the PC no longer shows files that end in .diamond and no longer open.
Setting it up step by step: 3-2-1 backups on Windows 11 and 10.
Access your website securely from any location
When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.
If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.
Recover files after data-affecting malware attacks
While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.
More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.
Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.
Questions about Diamond ransomware
Is there a decryptor for .diamond files?
That depends on the family behind the .diamond extension, which this guide cannot confirm yet from the reports alone. Check No More Ransom and ID Ransomware with your ransom note and one encrypted file; they list families with free tools.
If none exists today, keep the encrypted files and a copy of the note on a separate drive, because decryptors are sometimes published months later after flaws are found or servers are seized. Never buy a decryptor from a website that is not the security company that made it.
How do I open .diamond files?
You cannot open them by renaming or by choosing another program. The .diamond ending shows that Diamond ransomware encrypted the content, and only the matching key can reverse it. Renaming a file back to .docx or .jpg changes nothing except the icon, and it can confuse a future decryptor, so leave the names as they are.
To get the content back, use a backup, an unencrypted copy elsewhere, or a decryptor listed on No More Ransom if one exists for Diamond ransomware. Store the encrypted files on an external disk until then.
Are ransomware recovery services legitimate?
Some are, but read the offer carefully. Genuine data-recovery firms recover deleted originals from disks or rebuild damaged files, and they say so. Others promise to "decrypt any ransomware" for a fixed price, which is impossible without the key; they quietly pay the attackers and keep a margin, sometimes without telling the victim.
Be especially careful with services that contact you after you post about the attack online. Ask for references, a written method and a no-result-no-fee clause, and check the free tools on No More Ransom first.
Should I pay the ransom?
We advise against it, and so do the FBI, Europol and national cyber agencies. Payment does not guarantee a working tool: some attackers never reply, some tools damage files, and some variants have no decryptor at all. Paying also funds further attacks and can make you a target again.
Before considering payment, try every recovery option in this guide and report the attack. Companies must involve their legal adviser and insurer, because payments to sanctioned groups can be illegal. If files are truly irreplaceable, store the encrypted copies and wait; decryptors sometimes appear later.
How did Diamond ransomware get on my computer?
The way Diamond ransomware spreads has not been documented yet, so look at your own recent activity. On home PCs, ransomware most often comes with cracked programs, game cheats, key generators and fake updates, or with an e-mail attachment that was opened. On business networks, attackers usually log in through Remote Desktop with a stolen or guessed password.
Think back to what was downloaded or installed in the days before files that end in .diamond and no longer open, and check the Downloads folder and Installed apps sorted by date. Keep anything suspicious for your report, but do not run it again.
Did Diamond ransomware steal my files or passwords?
We do not know yet. Nothing published so far shows data theft by Diamond ransomware, but the only confirmed sign is files that end in .diamond and no longer open, which says nothing about what happened before. Many current ransomware attacks copy files or run a password stealer first, so it is wise to act as if they did.
From a clean device, change the passwords that were saved in the browsers on this PC, starting with e-mail and banking, sign out of all sessions and turn on two-step verification. Watch bank statements and account activity for the next few weeks.
Is Diamond ransomware the same as other ransomware with a similar name?
Not necessarily. Ransomware names come from the file extension, the note or a word in the code, so unrelated families often end up with similar names, and one family can appear under several names. The difference matters: a decryptor or advice for one family does not fit another and can damage files.
Compare the ending added to your files and the exact name of the note with the summary table at the top of this guide, then upload the note and one encrypted file to ID Ransomware from a clean device. If the result names another family, follow the guide for that family instead.
Should I open the ransom note?
Reading it is fine if you open it in Notepad. A plain text the ransom note cannot harm the PC. Be careful with notes in HTA or HTML format: double-clicking those runs them in a window that can contain scripts, so right-click and choose Open with > Notepad instead.
The note tells you the contact addresses, the claimed amount and the deadline. Do not visit links or write to the addresses from this PC. Use the note to identify the family and check for a free decryptor first.
Will .diamond spread to my other drives?
It can. Ransomware encrypts every drive and network share it can reach while it runs, so external disks, USB sticks and shared folders connected during the attack may also have files ending in .diamond. Disconnect everything now, then check each device from a clean computer.
Do not plug a backup drive into the infected PC until the ransomware has been removed with an offline scan. Cloud folders such as OneDrive sync the encrypted versions, but they keep earlier versions you can usually restore.
Will Fortect remove Diamond ransomware?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Diamond ransomware, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Comparitech: What is RSA encryption and how does it work? (read October 7, 2026)
- Malwarebytes: Info stealers (read October 7, 2026)
- CISA: StopRansomware (read October 7, 2026)
- No More Ransom (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)