Royal is a financially motivated ransomware operation active since approximately September 2022 and associated with large-scale double-extortion intrusions against organizations in the United States and internationally. The group is known for stealing data before encrypting systems and threatening publication on a leak site if victims do not pay. U.S. government reporting has linked Royal to hundreds of victims worldwide and ransom demands totaling hundreds of millions of dollars. Royal has also been assessed as having evolved from earlier activity involving the Zeon loader, and later reporting noted coding similarities between Royal and BlackSuit, suggesting a rebrand or spinoff relationship. Royal commonly gains initial access through phishing, including malicious documents and malvertising, and has also been observed using compromised RDP access, exploitation of public-facing applications, and access obtained through brokers using stolen VPN credentials. After access, the operators use legitimate remote administration and tunneling tools, conduct lateral movement with RDP and PsExec, and establish persistence through remote monitoring and management software. They have used valid accounts in some cases, including administrative access to domain controllers. The group demonstrates mature post-compromise tradecraft. Royal operators disable or weaken defenses, including modifying Group Policy to deactivate antivirus protections, delete logs, and inhibit recovery by removing shadow copies. They exfiltrate data with repurposed offensive tooling and then deploy a custom ransomware encryptor that supports partial encryption to accelerate impact and reduce the chance of early detection. Victim communications are handled through anonymity-network infrastructure rather than embedding full payment instructions in the initial ransom note. Royal has targeted multiple sectors, including manufacturing, communications, healthcare, and education, and has been associated with attacks against critical infrastructure organizations. Known aliases and related designations include DEV-0569, while BlackSuit has been reported to share coding characteristics with Royal.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.