Royal — Ransomware Profile
Royal ransomware emerged in 2022, believed to involve former Conti operators, targeting healthcare and critical infrastructure with highly personalized attacks.Also tracked as
DEV-0569, Royal ransomware gang, Storm-0569
Tools & malware
- AdFind Discovery tool
- BATLOADER Loader
- BlackSuit encryptor Ransomware
- Chisel Tunneling tool
- Cloudflared Tunneling tool
- Cobalt Strike C2 framework
- Mimikatz Credential theft
- PsExec Lateral movement
- Qakbot Loader/C2
- Rclone Exfiltration tool
- Royal encryptor Ransomware
- Ursnif Commodity malware/infostealer
- Vidar Infostealer
Vendor research
- #StopRansomware: BlackSuit (Royal) Ransomware (AA23-061A) CISA / FBI
- Investigating BlackSuit Ransomware's Similarities to Royal Trend Micro
- DEV-0569 finds new ways to deliver Royal ransomware, various payloads Microsoft
- Royal ransomware gang adds BlackSuit encryptor to their arsenal BleepingComputer
- CISA, FBI warn Royal ransomware gang may rebrand as 'BlackSuit' The Record (Recorded Future News)