Royal Ransomware Surges with Aggressive Double-Extortion Attacks
Royal ransomware has significantly escalated its operations, listing nearly 60 victims on its leak site in November and December 2022 alone a sharp increase in successful compromises. Emerging in early 2022, the group has become one of the most active enterprise-targeting ransomware operations, frequently targeting critical sectors.
The group employs a double-extortion model, encrypting data while also stealing and threatening to leak sensitive information to pressure victims into paying ransoms. Demands typically range from hundreds of thousands to millions of dollars, with negotiations conducted via a Tor-based portal referenced in ransom notes.
Royal’s attack chains often begin with phishing or spearphishing emails delivering malware like Qbot or IcedID. Attackers use techniques such as HTML smuggling and password-protected archives containing ISO files with hidden payloads to execute Qbot on victim systems. Once inside, they deploy Cobalt Strike beacons for interactive control, leveraging encoded PowerShell and Windows command shell for persistence.
Lateral movement is achieved through credential abuse, including pass-the-hash techniques, while tools like PowerSploit and AdFind map the network for mass encryption. To evade detection, Royal operators inject malicious code into legitimate processes, bypass UAC via scheduled tasks, and use multiple backdoors, including HTTPS and SMB-named pipes for command-and-control (C2) communication.
Before encryption, data is exfiltrated to cloud storage platforms like Dropbox and Mega, ensuring extortion threats remain even if victims restore from backups. Royal’s operators prioritize speed, often achieving full domain compromise within a compressed timeline, making early detection and monitoring critical. The true number of victims is likely higher, as not all impacted organizations appear on the leak site.
Source: https://cyberpress.org/royal-ransomware-attack-surge/
Royal Central cybersecurity rating report: https://www.rankiteo.com/company/royal-central
"id": "ROY1784715914",
"linkid": "royal-central",
"type": "Ransomware",
"date": "11/2022",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'attack_vector': ['Phishing', 'Spearphishing'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive information'},
'description': 'Royal ransomware has significantly escalated its operations, '
'listing nearly 60 victims on its leak site in November and '
'December 2022 alone, a sharp increase in successful '
'compromises. The group employs a double-extortion model, '
'encrypting data while also stealing and threatening to leak '
'sensitive information to pressure victims into paying '
'ransoms. Demands typically range from hundreds of thousands '
'to millions of dollars, with negotiations conducted via a '
'Tor-based portal referenced in ransom notes.',
'impact': {'data_compromised': True, 'identity_theft_risk': True},
'initial_access_broker': {'backdoors_established': True,
'entry_point': ['Phishing', 'Spearphishing']},
'motivation': 'Financial gain',
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_demanded': ['Hundreds of thousands', 'Millions'],
'ransomware_strain': 'Royal'},
'references': [{'source': 'Cyber Incident Description'}],
'threat_actor': 'Royal Ransomware Group',
'title': 'Royal Ransomware Surges with Aggressive Double-Extortion Attacks',
'type': 'Ransomware'}