Royal is a financially motivated ransomware family and criminal operation linked to former Conti members. It initially operated under the Zeon name in January 2022 and adopted the Royal name in September 2022. The operation subsequently rebranded as BlackSuit in May 2023. Royal has been characterized as a closed, internally controlled operation rather than an openly available ransomware-as-a-service program.
Royal and BlackSuit conduct double-extortion attacks, stealing sensitive information before encrypting systems and threatening disclosure to pressure victims into paying. BlackSuit payloads target Windows and Linux and use a customized encryptor incorporating OpenSSL's AES implementation. Intrusions have involved phishing, callback phishing, malvertising, exploitation of public-facing applications, and access through exposed VPN or RDP services using compromised credentials. Royal-associated delivery chains have used BATLOADER and QakBot before ransomware deployment.
Operators abuse legitimate remote monitoring and management tools, including SimpleHelp and ScreenConnect, to maintain access and evade detection. Documented BlackSuit attacks have used Kerberoasting and AS-REP roasting to compromise accounts, privileged accounts to extract Active Directory credentials, and PsExec, SMB, and Windows Management Instrumentation to distribute and execute ransomware across enterprise hosts. Data has been staged with compression tools and exfiltrated using WinSCP over FTP.
Victims include large enterprises, smaller businesses, and public-sector organizations, with documented attacks affecting education, industrial goods and services, construction, media, and automotive technology providers. Attacks have caused substantial operational disruption. BlackSuit infrastructure was seized by the U.S. Department of Justice in July 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Data from our scans, information gleaned from claims data, and other intelligence gathered by our Cyber Research team point to the Citrix vulnerability CVE-2022-27510 as the initial point of access utilized by the Royal ransomware group to launch a recent ransomware attack.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Case Study: Service Account Takeover Leads to BlackSuit Ransomware Deployment
Also worked as an affiliate for “BlackSuit” (aka Royal) ransomware, another spinoff of Conti.
ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."
On May 1, local media reported that a city government had suffered a disruption resulting from an attack claimed by the Royal ransomware group.
Executive Summary Royal ransomware has been involved in high-profile attacks against critical infrastructure, especially healthcare, since it was first observed in September 2022.
We have also seen Batloader being a key enabler for Royal ransomware, the second-most prevalent ransomware family we have been observing recently.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
one of the most common infection chains for Linux is exploiting a vulnerability in some exposed service of the victim’s servers. This is also true for vulnerabilities in ESXi, but there are also other cases, such as IceFire which exploits a vulnerability in an IBM technology (CVE-2022-47986)
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Discovery T1057 ... Process Discovery
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1082 ... System Information Discovery
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... T1083 ... File and Directory Discovery
This group is known to perform double-extortion, where data is exfiltrated prior to encryption, and stolen data is publicly released via a leak site if an extortion demand is not met. | CDK Global ... experienced a significant operational disruption due to a ransomware attack executed by the BlackSuit ransomware group.
When the parameter “-vmsyslog” is passed, the ransomware is designed to terminate the “vmsyslog” service in the targeted machine.
BlackSuit ransomware also deletes shadow copies using the following command: "%System%\vssadmin.exe" Delete Shadows /All /Quiet
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
141 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware responsible for 10% of successful attacks investigated by Coveware in the second quarter of 2023. Its associated group reportedly organized the competition involving Akira and BlackSuit and continued borrowing BlackCat's loader.
Named as a ransomware gang/family linked via former members to the Chaos ransomware-as-a-service operation.
Ransomware used in enterprise intrusions that rapidly expands from an initial phishing-based foothold to domain-wide compromise before deploying encryption, and also exfiltrates data prior to encryption.
Ransomware family mentioned as a customer of sanctioned hosting infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.