Royal — Malware Profile
Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023. Royal employs partial encryption and multiple threads to evade detection and speed encryption. Royal has been used in attacks against multiple industries worldwide--including critical infrastructure. Security researchers have identified similarities in the encryption routines and TTPs used in Royal and Conti attacks and noted a possible connection between their operators.
MITRE ATT&CK techniques (15)
- T1016 System Network Configuration Discovery
- T1021.002 SMB/Windows Admin Shares
- T1046 Network Service Discovery
- T1057 Process Discovery
- T1059.012 Hypervisor CLI
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1095 Non-Application Layer Protocol
- T1106 Native API
- T1135 Network Share Discovery
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1566 Phishing
- T1680 Local Storage Discovery