HackerFeeds
All ransomware groups

royal

211 tracked victims
·first seen 2022-11-04·last activity 2023-07-19

Group profile

According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1566.001Phishing: Spearphishing Attachment

    A spearphishing email was sent to employees.

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    Cobalt Strike was executed through encoded PowerShell commands.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    Qbot was launched through the Windows Command Shell with cmd.exe.

TA0003

Persistence

  • T1543.003Create or Modify System Process: Windows Service

    Cobalt Strike was installed as a Windows service on multiple systems.

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    Qbot DLL was added to HKCUEY_CURRENT_USER \Software \Microsoft \Windows \CurrentVersion \Run.

TA0004

Privilege Escalation

  • T1078.002Domain Accounts

    Royal ransomware operators used (privileged) domain accounts for lateral movement.

  • T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control

    Royal ransomware operations executed a known UAC bypass that abuses a default scheduled task to launch PowerShell with escalated privileges.

TA0005

Defense Evasion

  • T1027.006Obfuscated Files or Information: HTML Smuggling

    Password protected file containing an ISO file with a hidden file used in combination with an LNK file to execute Qbot.

  • T1055Process Injection

    Qbot and Cobalt Strike were both injected into legitimate Windows processes.

  • T1078.002Domain Accounts

    Royal ransomware operators used domain accounts for lateral movement.

TA0007

Discovery

  • T1087.001Account Discovery: Local Account

    The FindLocalAdmin PowerSploit script was used to find local administrator accounts on workstations/servers.

  • T1087.002Account Discovery: Domain Account

    Users and groups were enumerated with built-in Windows utilities and with AdFind software.

  • T1135Network Share Discovery

    Network shares were enumerated with PowerSploit software.

  • T1482Domain Trust Discovery

    Domain trust was enumerated with built-in Windows utilities.

TA0008

Lateral Movement

  • T1021.002Remote Services: SMB/Windows Admin Shares

    Remote admin shares C$ were mounted from the Patient 0 workstation.

  • T1078.002Valid Accounts: Domain Accounts

    Several (privileged) domain accounts were used during the attack for lateral movement and deployment of ransomware.

  • T1550.002Use Alternate Authentication Material: Pass the Hash

    The Royal ransomware operators leveraged credential hashes from privileged accounts to perform lateral movement.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Royal ransomware operators used Mega Cloud Storage and Dropbox to exfiltrate data from multiple hosts.

TA0011

Command and Control

  • T1071Application Layer Protocol

    Cobalt Strike uses peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol.

  • T1071.001Application Layer Protocol: Web Protocols

    Qbot and Cobalt Strike used HTTPS traffic for their C2 communication.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Royal ransomware encrypted files on systems with the .royal extension.

Recent victims

showing 50 of 211
DateWebsite / victimSectorCountry
2023-07-19
braintreema.gov
Braintree Public Schoolsbraintreema.gov
EducationUS
2023-06-11
tachi-s.com
Tachi-S Engineering USAtachi-s.com
Manufacturing
2023-06-09
penncrest.org
PENNCREST School Districtpenncrest.org
Education
2023-05-26
sovitrat.fr
Groupe Sovitrat Interim and Recrutementsovitrat.fr
Business ServicesFR
2023-05-26
bmprecision.com
BM Precisionbmprecision.com
Manufacturing
2023-05-26
directviz.com
DirectViz Solutionsdirectviz.com
Technology
2023-05-26
thebestconnection.co.uk
The Best Connectionthebestconnection.co.uk
Business ServicesGB
2023-05-26
mitutoyo.ch
Mitutoyomitutoyo.ch
ManufacturingCH
2023-05-26
afgholdings.com
AFG Holdingsafgholdings.com
Manufacturing
2023-05-26Business ServicesUS
2023-05-26ManufacturingZA
2023-05-26
haworthtompkins.com
Haworth Tompkinshaworthtompkins.com
Business Services
2023-05-26
co-pack.co.uk
Grange Packing Solutionsco-pack.co.uk
ManufacturingGB
2023-05-23Public SectorUS
2023-05-23
dotcomdist.com
Dotcom Distributiondotcomdist.com
Transportation/Logistics
2023-05-22Not Found
2023-05-22
tasupply.com
TA Supplytasupply.com
Business ServicesUS
2023-05-22
trinityexploration.com
Trinity Exploration and Productiontrinityexploration.com
Energy
2023-05-22
agostini.com
Agostini Insurance Brokersagostini.com
Financial ServicesTT
2023-05-22
atlascommodities.com
Atlas Commoditiesatlascommodities.com
Financial Services
2023-05-22
morrishospital.org
Morris Hospitalmorrishospital.org
Healthcare
2023-05-22
utahyamas.com
Utah-Yamas Controlsutahyamas.com
Manufacturing
2023-05-19
dallascityhall.com
City of Dallasdallascityhall.com
Public Sector
2023-05-18
nashua.edu
NASHUA SCHOOL DISTRICTnashua.edu
EducationUS
2023-05-15Energy
2023-04-01
meadetractor.com
Meade Tractormeadetractor.com
Agriculture and Food Production
2023-05-01
midwesttruck.com
Midwest Truckmidwesttruck.com
Transportation/Logistics
2023-05-03
southernwv.edu
Southern West Virginia Community and Technical Collegesouthernwv.edu
EducationUS
2023-05-03
zbw.eu
ZBW Newszbw.eu
EducationUA
2023-04-29
gfcmsu.edu
Great Falls College of Technologygfcmsu.edu
EducationUS
2023-04-29
montana.edu
Montana State Universitymontana.edu
EducationUS
2023-04-26
edisonlearning.com
EdisonLearningedisonlearning.com
Education
2023-04-21
encompassgroup.com
Encompass Groupencompassgroup.com
ManufacturingUS
2023-04-18
ldisd.net
Lake Dallas Independent School Districtldisd.net
Education
2023-04-18
mwcomponents.com
MW Componentsmwcomponents.com
Manufacturing
2023-04-20
clarkehosp.org
Clarke County Hospitalclarkehosp.org
Healthcare
2023-04-21
gks-hydraulik.com
GKS Hydraulikgks-hydraulik.com
ManufacturingDE
2023-03-09
mainstream-engr.com
Mainstream Engineeringmainstream-engr.com
Manufacturing
2023-04-14
ballwin.mo.us
City of Ballwinballwin.mo.us
Public SectorUS
2023-04-13
swansongroup.biz
Swanson Groupswansongroup.biz
Manufacturing
2023-04-13
mooncapital.com
Moon Capitalmooncapital.com
Financial Services
2023-04-12
talonoutdoor.com
Talon Outdoortalonoutdoor.com
Business Services
2023-04-12Technology
2023-03-30
einhaus-gruppe.de
einhaus-gruppeeinhaus-gruppe.de
Business ServicesDE
2023-04-10
stanleyelectricus.com
Stanley Electric U.S.stanleyelectricus.com
Manufacturing
2023-04-10
naturespath.com
Nature Path Foodsnaturespath.com
Agriculture and Food ProductionCA
2023-04-10TechnologyUS
2023-04-10
bigassfans.com
Big Ass Fansbigassfans.com
Manufacturing
2023-04-10
tomduffy.com
Tom Duffy Companytomduffy.com
ConstructionUS
2023-04-03
beghelliusa.com
Beghelli USAbeghelliusa.com
Manufacturing