Skip to content

Royal

Royal is a private double-extortion ransomware operation first observed in 2022 and widely assessed to include former Conti-linked operators.

Profile source: Mallory opens in a new tab

Royal

Family profile

Royal is a private double-extortion ransomware operation first observed in 2022 and widely assessed to include former Conti-linked operators. It has targeted organizations globally, with notable impact on critical infrastructure and sectors including healthcare, manufacturing, education, government, and information technology. The group is commonly described as operating as a closed organization rather than a conventional ransomware-as-a-service program.

Royal conducts data theft prior to encryption and threatens to leak stolen information to pressure victims into paying. Reported initial access methods include callback phishing, malvertising and SEO-poisoning lures, malicious software downloads masquerading as legitimate installers, exploitation of exposed or unpatched services, compromised credentials, and phishing links delivered through website contact forms. Intrusion chains associated with Royal have frequently involved BATLOADER and QakBot, often followed by Cobalt Strike or legitimate remote-management tooling.

Post-compromise activity attributed to Royal includes reconnaissance, Active Directory discovery, lateral movement with remote administration utilities, abuse of PowerShell, and exfiltration to cloud storage services. Operators have also used tools intended to disable or tamper with security products and have deleted shadow copies to inhibit recovery. On Windows, Royal encrypts local drives and network shares and uses hybrid cryptography based on AES with RSA-protected key material. Royal has also developed a Linux encryptor aimed at Linux and VMware ESXi environments, reflecting the group’s interest in virtualized enterprise infrastructure.

Royal has been linked in reporting to the earlier Zeon name and has also been discussed as closely related to, or a predecessor of, BlackSuit, though the exact relationship is not fully settled in all reporting. Security vendors and government agencies have consistently treated Royal as a significant ransomware threat because of its aggressive extortion model, varied access methods, and repeated targeting of high-impact organizations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Credential Theft

  • Mimikatz
  • NirSoft Dialupass
  • NirSoft IEPassView (iepv)
  • NirSoft MailPassView
  • NirSoft Netpass
  • NirSoft RouterPassView

Defense Evasion

  • Eraser
  • GMER
  • NSudo
  • PowerTool

Discovery Enum

  • AdFind
  • Advanced IP Scanner
  • SharpShares
  • SoftPerfect NetScan

Exfiltration

  • RClone

LOLBAS

  • PsExec

Networking

  • Chisel
  • Cloudflared
  • OpenSSH

Offsec

  • Brute Ratel C4
  • Cobalt Strike

RMM Tools

  • AnyDesk
  • Atera
  • LogMeIn
  • MobaXterm
  • Syncro

Reported operators

Threat actors

11 named in public reporting
DEV-0569

On May 1, local media reported that a city government had suffered a disruption resulting from an attack claimed by the Royal ransomware group.

Team One

Executive Summary Royal ransomware has been involved in high-profile attacks against critical infrastructure, especially healthcare, since it was first observed in September 2022.

Water Minyades

We have also seen Batloader being a key enabler for Royal ransomware, the second-most prevalent ransomware family we have been observing recently.

ShadowSyndicate

It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.

INDRIK SPIDER

Blacksuit ransomware as reported on December 2023 by DFIR report.

Storm-1811

Rapid7 disclosed that the initial infiltration strategy used by BlackBasta after the February 2025 internal chat leak was identified in the BlackSuit ransomware group: email bombing followed by impersonating helpdesk staff and contacting them via Microsoft Teams and voice calls to trick them into installing remote access tools such as Quick Assist, AnyDesk, and ScreenConnect.

Storm-0569

A threat actor group that Microsoft designated as DEV-0569 (now Storm-0569) used a very similar technique in late 2022 to deploy Royal ransomware.

Conti

"Royal ransomware is following in the same path, a new variant targeting Linux systems emerged... Royal’s Linux counterpart also targets ESXi servers"; "In its early campaigns, Royal deployed BlackCat’s encryptor, but later shifted to its own called Zeon".

Black Suit

“…BlackSuit ransomware actors breached CDK Global… strongly suggesting it is rebranding of Royal ransomware.”

Stern

...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.

MITRE ATT&CK

Royal in ATT&CK

42 distinct techniques

Techniques

42 techniques
T1486 Data Encrypted for Impact T1657 Financial Theft T1021.002 SMB/Windows Admin Shares T1204 User Execution T1057 Process Discovery T1070.004 File Deletion T1059 Command and Scripting Interpreter T1135 Network Share Discovery T1490 Inhibit System Recovery T1082 System Information Discovery T1529 System Shutdown/Reboot T1083 File and Directory Discovery T1489 Service Stop T1190 Exploit Public-Facing Application T1016 System Network Configuration Discovery T1562.009 Safe Mode Boot T1059.003 Windows Command Shell T1567 Exfiltration Over Web Service T1046 Network Service Discovery T1105 Ingress Tool Transfer T1041 Exfiltration Over C2 Channel T1120 Peripheral Device Discovery T1059.012 Hypervisor CLI T1106 Native API T1680 Local Storage Discovery T1566 Phishing T1095 Non-Application Layer Protocol T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell T1543.003 Create or Modify System Process: Windows Service T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1078.002 Domain Accounts T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control T1027.006 Obfuscated Files or Information: HTML Smuggling T1055 Process Injection T1087.001 Account Discovery: Local Account T1087.002 Account Discovery: Domain Account T1482 Domain Trust Discovery T1550.002 Use Alternate Authentication Material: Pass the Hash T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage T1071 Application Layer Protocol T1071.001 Application Layer Protocol: Web Protocols

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.