A US city government suffered a ransomware-related disruption later claimed by the Royal ransomware group, with emergency services remaining available but computerized dispatch systems affected and some operational impacts reportedly lasting into early June. Researchers linked the incident to infrastructure and behaviors associated with Royal, a closed ransomware operation reportedly tied to former Conti members and known for targeting organizations through phishing, malvertising, and commodity malware.
SecurityScorecard said its review of NetFlow data and VirusTotal artifacts from March through early May found activity consistent with Royal tradecraft, including a malicious HTML lure resembling callback phishing, communications with QakBot-linked IP addresses, spam-associated infrastructure, and extensive connections to LogMeIn remote-access services. Separate analysis of Royal ransomware has described the group’s broader tactics, techniques, and procedures, including use of initial-access malware such as BATLOADER and QakBot, helping place the city attack within a wider pattern of Royal intrusions and ransomware deployment.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
A malicious HTML file containing JavaScript and an image from the city government domain appeared in VirusTotal. Researchers said the city-branded image suggested an impersonation attempt, and some detections linked the file to callback-phishing-like behavior.
A city mailserver IP address communicated seven times with spam-linked IP addresses across two days. SecurityScorecard cited this as part of the activity surrounding the incident.
The group rebranded from Zeon to Royal. The report also notes Royal is reportedly composed of former Conti members and is considered a closed group rather than a ransomware-as-a-service operation.
The ransomware group later known as Royal first surfaced under the name Zeon. The report describes this as the group's initial appearance before its later rebrand.
Some operational impacts from the city government ransomware incident appear to have lasted until June 5. Emergency services remained available despite the disruption to computerized dispatching systems.
City spokespeople confirmed reports of the ransomware-related attack. The ransom note reportedly claimed data theft and threatened publication of the stolen data.
Local media reported that a city government suffered a disruption from an attack claimed by the Royal ransomware group. The incident affected computerized dispatching systems, though emergency services remained available.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.