Royal ransomware emerged as a major threat after first being observed in September 2022, with intrusions linked to likely Russian-speaking cybercrime actors and possible overlap with former Conti members. The group has hit organizations globally, including multiple Australian victims and critical infrastructure, with a concentration of cases in the United States and Canada across healthcare, manufacturing, education, and government. Royal operators steal data before encrypting systems, then pressure victims through leak-site exposure and, in some cases, social media harassment; reported ransom demands have reached $25 million in bitcoin. Analysts also identified infrastructure and tooling overlaps between Royal activity, FRwL / UAC-0118, and earlier ex-Conti-linked operations, including shared IPs and a Cobalt Strike watermark associated with related campaigns.
Investigations show Royal gains initial access through callback phishing, SEO poisoning, malicious downloads, phishing links sent via website contact forms, exploitation of unpatched vulnerabilities, exposed RDP, and compromised credentials. After entry, the actors have used BATLOADER, Qakbot, Bokbot, Cobalt Strike, PsExec, PowerShell, AdFind, NetScan, Chisel, Rclone, PCHunter, PowerTool, and Process Hacker to move laterally, evade defenses, exfiltrate data, and deploy ransomware on Windows as well as a Linux/ESXi ELF variant. Royal typically encrypts local drives and network shares, appends the .royal extension, deletes shadow copies, disables security services, and leaves README.txt ransom notes with Tor-based contact instructions. Defenders are urged to prioritize software patching, multifactor authentication, network segmentation, traffic filtering, application allowlisting, privileged account controls, and offline encrypted backups to reduce exposure to the exploitation and credential abuse techniques seen in Royal intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
As of 10 January 2023, Royal actors claimed to have compromised at least 70 organizations worldwide. ACSC cited this as part of the group's expanding global activity.
Unit 42 reported that Royal later publicized attacks on 26 additional manufacturing organizations in 2023. The report also said Royal's leak site had claimed 157 victim organizations since 2022.
The U.S. Department of Health and Human Services warned about the threat Royal poses to the healthcare sector in January 2023. Unit 42 said the group had already impacted multiple healthcare organizations since its emergence.
The IP address 94.232.41.105 was identified as a Royal tool repository in December 2022. Analysis said it hosted separate Cobalt Strike instances tied to softloadup.com and later sombrat.com, both using watermark 206546002.
A CISA cybersecurity advisory on Royal included indicators of compromise and technical details, including IP address 139.60.161.213 associated with activity in November 2022. The same IP was also listed by CERT-UA in its FRwL/UAC-0118 advisory.
Royal ransomware was first observed in September 2022. Reporting also linked the group to the earlier Zeon ransomware family and described it as operating privately rather than as a RaaS model.
Royal's leak site listed 14 manufacturing organizations as impacted during 2022. Unit 42 cited this as evidence of the group's focus on critical infrastructure sectors.
In 2022, Royal ransomware actors targeted Australian critical infrastructure, including an educational institute. ACSC also noted increased domestic and global Royal activity during 2022.
Palo Alto Networks Unit 42 published a threat assessment describing Royal's tradecraft, victim sectors, extortion methods, and Linux/ESXi ELF variant. The report said responders had handled 15 Royal-related cases in the prior nine months.
Walmart Global Tech published analysis highlighting overlaps between Royal ransomware activity and CERT-UA's UAC-0118/FRwL cluster, including shared IPs and Cobalt Strike watermark 206546002. The article also assessed Somnia as a wiper rather than recoverable ransomware.
Australia's ACSC published an advisory profiling Royal ransomware, describing its victimology, double-extortion tactics, initial access methods, tooling, and recommended mitigations. The advisory said Royal activity seen in 2022 was continuing into 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcemedium.com
Open sourcecyber.gov.au
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.