Royal is a private double-extortion ransomware family first observed in September 2022 and widely assessed to be linked to Russian-speaking cybercrime, with reporting frequently noting overlap with former Conti personnel or tradecraft. It has been used in attacks against organizations worldwide, including critical infrastructure, with healthcare, manufacturing, education, government, and other enterprise sectors repeatedly affected. Royal has also been associated with successor or closely related activity involving BlackSuit, although the exact relationship has not been conclusively established in all cases.
Royal operators commonly steal data before encryption and threaten to leak or sell it if victims do not pay. Observed intrusion chains show a mix of social engineering and opportunistic access methods, including callback phishing, phishing links delivered through website contact forms, malicious software downloads promoted through SEO poisoning and malvertising, exploitation of exposed remote access services, compromised credentials, and exploitation of known vulnerabilities or security misconfigurations. BATLOADER has repeatedly been identified as an important initial-access enabler in Royal intrusions, often preceding deployment of additional tooling such as Cobalt Strike.
Post-compromise activity includes reconnaissance, credential access, lateral movement, exfiltration, and defense evasion. Reported tooling and behaviors include Active Directory discovery, network scanning, abuse of remote administration and execution utilities, use of PowerShell, tunneling utilities, and exfiltration tools such as Rclone. Operators have also used utilities to disable or tamper with security products and to delete shadow copies in order to hinder recovery. Royal encrypts local drives and network shares on Windows systems and leaves ransom notes for victim communication over Tor-based infrastructure.
Royal also developed a Linux-targeting encryptor aimed at enterprise virtualization environments, particularly VMware ESXi. This variant reflects the broader shift of ransomware operators toward hypervisors, where encrypting a single host can disrupt many virtual machines and business services at once. Royal’s Linux/ESXi capability places it among the ransomware families that expanded beyond Windows to increase operational impact in enterprise environments.
Royal is generally described as operating independently rather than as a conventional ransomware-as-a-service platform, though affiliates or closely aligned intrusion partners may still play a role in access and deployment. The group has remained prominent in ransomware reporting since late 2022 and has been repeatedly tied to high-impact enterprise and critical-infrastructure incidents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Executive Summary Royal ransomware has been involved in high-profile attacks against critical infrastructure, especially healthcare, since it was first observed in September 2022.
We have also seen Batloader being a key enabler for Royal ransomware, the second-most prevalent ransomware family we have been observing recently.
It has demonstrated the use of multiple top tier Ransomware-as-a-Service (RaaS) brands such as AlphaV/Blackcat, Lockbit, Play, Royal, Cl0p, Cactus and Ransomhub.
Rapid7 disclosed that the initial infiltration strategy used by BlackBasta after the February 2025 internal chat leak was identified in the BlackSuit ransomware group: email bombing followed by impersonating helpdesk staff and contacting them via Microsoft Teams and voice calls to trick them into installing remote access tools such as Quick Assist, AnyDesk, and ScreenConnect.
A threat actor group that Microsoft designated as DEV-0569 (now Storm-0569) used a very similar technique in late 2022 to deploy Royal ransomware.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
one of the most common infection chains for Linux is exploiting a vulnerability in some exposed service of the victim’s servers. This is also true for vulnerabilities in ESXi, but there are also other cases, such as IceFire which exploits a vulnerability in an IBM technology (CVE-2022-47986)
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1057 ... Process Discovery
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name Impact T1486 ... Data Encrypted for Impact
When the parameter “-vmsyslog” is passed, the ransomware is designed to terminate the “vmsyslog” service in the targeted machine.
BlackSuit ransomware also deletes shadow copies using the following command: "%System%\vssadmin.exe" Delete Shadows /All /Quiet
Finally, it initiates a system shutdown with the “shutdown.exe” utility and the arguments “/r /t 0”, which will restart the system immediately.
He analyzed stolen data and used sensitive information to intensify extortion tactics. When the ransom demand was not met, he allegedly encouraged co-conspirators to leak or sell the data. Court documents reveal he distributed a bulk set of sensitive records to hundreds of patients, aiming to amplify fear and force compliance.
file1.bat : a batch file designed to set up the system with autologon as the newly-created administrative user AdminBac, reboot into Safe Mode ... file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
121 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware gang/family linked via former members to the Chaos ransomware-as-a-service operation.
Ransomware used in enterprise intrusions that rapidly expands from an initial phishing-based foothold to domain-wide compromise before deploying encryption, and also exfiltrates data prior to encryption.
Ransomware family mentioned as a customer of sanctioned hosting infrastructure.
Ransomware family identified as using the sanctioned bulletproof hosting provider infrastructure for extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.