Royal is a private double-extortion ransomware operation first observed in 2022 and widely assessed to include former Conti-linked operators. It has targeted organizations globally, with notable impact on critical infrastructure and sectors including healthcare, manufacturing, education, government, and information technology. The group is commonly described as operating as a closed organization rather than a conventional ransomware-as-a-service program.
Royal conducts data theft prior to encryption and threatens to leak stolen information to pressure victims into paying. Reported initial access methods include callback phishing, malvertising and SEO-poisoning lures, malicious software downloads masquerading as legitimate installers, exploitation of exposed or unpatched services, compromised credentials, and phishing links delivered through website contact forms. Intrusion chains associated with Royal have frequently involved BATLOADER and QakBot, often followed by Cobalt Strike or legitimate remote-management tooling.
Post-compromise activity attributed to Royal includes reconnaissance, Active Directory discovery, lateral movement with remote administration utilities, abuse of PowerShell, and exfiltration to cloud storage services. Operators have also used tools intended to disable or tamper with security products and have deleted shadow copies to inhibit recovery. On Windows, Royal encrypts local drives and network shares and uses hybrid cryptography based on AES with RSA-protected key material. Royal has also developed a Linux encryptor aimed at Linux and VMware ESXi environments, reflecting the group’s interest in virtualized enterprise infrastructure.
Royal has been linked in reporting to the earlier Zeon name and has also been discussed as closely related to, or a predecessor of, BlackSuit, though the exact relationship is not fully settled in all reporting. Security vendors and government agencies have consistently treated Royal as a significant ransomware threat because of its aggressive extortion model, varied access methods, and repeated targeting of high-impact organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On May 1, local media reported that a city government had suffered a disruption resulting from an attack claimed by the Royal ransomware group.
Executive Summary Royal ransomware has been involved in high-profile attacks against critical infrastructure, especially healthcare, since it was first observed in September 2022.
We have also seen Batloader being a key enabler for Royal ransomware, the second-most prevalent ransomware family we have been observing recently.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
Rapid7 disclosed that the initial infiltration strategy used by BlackBasta after the February 2025 internal chat leak was identified in the BlackSuit ransomware group: email bombing followed by impersonating helpdesk staff and contacting them via Microsoft Teams and voice calls to trick them into installing remote access tools such as Quick Assist, AnyDesk, and ScreenConnect.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
one of the most common infection chains for Linux is exploiting a vulnerability in some exposed service of the victim’s servers. This is also true for vulnerabilities in ESXi, but there are also other cases, such as IceFire which exploits a vulnerability in an IBM technology (CVE-2022-47986)
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1057 ... Process Discovery
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
This group is known to perform double-extortion, where data is exfiltrated prior to encryption, and stolen data is publicly released via a leak site if an extortion demand is not met. | CDK Global ... experienced a significant operational disruption due to a ransomware attack executed by the BlackSuit ransomware group.
When the parameter “-vmsyslog” is passed, the ransomware is designed to terminate the “vmsyslog” service in the targeted machine.
BlackSuit ransomware also deletes shadow copies using the following command: "%System%\vssadmin.exe" Delete Shadows /All /Quiet
file1.bat : a batch file designed to set up the system with autologon as the newly-created administrative user AdminBac, reboot into Safe Mode ... file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
123 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware gang/family linked via former members to the Chaos ransomware-as-a-service operation.
Ransomware used in enterprise intrusions that rapidly expands from an initial phishing-based foothold to domain-wide compromise before deploying encryption, and also exfiltrates data prior to encryption.
Ransomware family mentioned as a customer of sanctioned hosting infrastructure.
Ransomware family identified as using the sanctioned bulletproof hosting provider infrastructure for extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.