Credential Theft
- AccountRestore
- Mimikatz
- NirSoft Dialupass
- NirSoft IEPassView (iepv)
- NirSoft MailPassView
- NirSoft Netpass
- NirSoft RouterPassView
Royal is a private double-extortion ransomware operation first observed in 2022 and widely assessed to include former Conti-linked operators.
Profile source: Mallory opens in a new tabRoyal
Royal is a private double-extortion ransomware operation first observed in 2022 and widely assessed to include former Conti-linked operators. It has targeted organizations globally, with notable impact on critical infrastructure and sectors including healthcare, manufacturing, education, government, and information technology. The group is commonly described as operating as a closed organization rather than a conventional ransomware-as-a-service program.
Royal conducts data theft prior to encryption and threatens to leak stolen information to pressure victims into paying. Reported initial access methods include callback phishing, malvertising and SEO-poisoning lures, malicious software downloads masquerading as legitimate installers, exploitation of exposed or unpatched services, compromised credentials, and phishing links delivered through website contact forms. Intrusion chains associated with Royal have frequently involved BATLOADER and QakBot, often followed by Cobalt Strike or legitimate remote-management tooling.
Post-compromise activity attributed to Royal includes reconnaissance, Active Directory discovery, lateral movement with remote administration utilities, abuse of PowerShell, and exfiltration to cloud storage services. Operators have also used tools intended to disable or tamper with security products and have deleted shadow copies to inhibit recovery. On Windows, Royal encrypts local drives and network shares and uses hybrid cryptography based on AES with RSA-protected key material. Royal has also developed a Linux encryptor aimed at Linux and VMware ESXi environments, reflecting the group’s interest in virtualized enterprise infrastructure.
Royal has been linked in reporting to the earlier Zeon name and has also been discussed as closely related to, or a predecessor of, BlackSuit, though the exact relationship is not fully settled in all reporting. Security vendors and government agencies have consistently treated Royal as a significant ransomware threat because of its aggressive extortion model, varied access methods, and repeated targeting of high-impact organizations.
104.244.75.168Reported operators
On May 1, local media reported that a city government had suffered a disruption resulting from an attack claimed by the Royal ransomware group.
Executive Summary Royal ransomware has been involved in high-profile attacks against critical infrastructure, especially healthcare, since it was first observed in September 2022.
We have also seen Batloader being a key enabler for Royal ransomware, the second-most prevalent ransomware family we have been observing recently.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
Blacksuit ransomware as reported on December 2023 by DFIR report.
Rapid7 disclosed that the initial infiltration strategy used by BlackBasta after the February 2025 internal chat leak was identified in the BlackSuit ransomware group: email bombing followed by impersonating helpdesk staff and contacting them via Microsoft Teams and voice calls to trick them into installing remote access tools such as Quick Assist, AnyDesk, and ScreenConnect.
A threat actor group that Microsoft designated as DEV-0569 (now Storm-0569) used a very similar technique in late 2022 to deploy Royal ransomware.
"Royal ransomware is following in the same path, a new variant targeting Linux systems emerged... Royal’s Linux counterpart also targets ESXi servers"; "In its early campaigns, Royal deployed BlackCat’s encryptor, but later shifted to its own called Zeon".
...BlackSuite Ransomware Gang...
“…BlackSuit ransomware actors breached CDK Global… strongly suggesting it is rebranding of Royal ransomware.”
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
MITRE ATT&CK
Reporting
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.