Ransomware Group intelligence
Royal
InactiveTrack Royal with 212 published victims and 2 known leak locations in a single intelligence view.
Overview
Royal is tracked by Breach House as a ransomware group with 212 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | royal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid.onion |
| Leak location 2 | Onion service | Down checked 2h ago | royal4ezp7xrbakkus3oofjw6gszrohpodmdnfbe5e4w3og5sm7vb3qd.onion |
Top Activity Sectors (16)
- Not identified 64
- Communication / Marketing 33
- Finance / Legal / Insurance 22
- Services 18
- Education 16
- Manufacturing / Engineering 13
- Healthcare / Pharma 10
- Construction / Real Estate 7
- Public Sector 6
- IT 5
- Retail / E-commerce 5
- Agriculture / Food 4
- Energy 3
- NGOs / Associations 1
- Transportation / Travel / Logistics 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (15)
▼How Royal typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Royal.
-
T1566 Phishing Initial Access
What they do: Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.
What that means: Adversaries may send phishing messages to gain access to victim systems.
-
T1059.012 Hypervisor CLI Execution
What they do: Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.
What that means: Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
-
T1106 Native API Execution
What they do: Royal can use multiple APIs for discovery, communication, and execution.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1016 System Network Configuration Discovery Discovery
What they do: Royal can enumerate IP addresses using `GetIpAddrTable`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1046 Network Service Discovery Discovery
What they do: Royal can scan the network interfaces of targeted systems.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Royal can use `GetCurrentProcess` to enumerate processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Royal can use `GetNativeSystemInfo` to enumerate system processors.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Royal can identify specific files and directories to exclude from the encryption process.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1680 Local Storage Discovery Discovery
What they do: Royal can use `GetLogicalDrives` to enumerate logical drives.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Royal can use SMB to connect to move laterally.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1095 Non-Application Layer Protocol Command and Control
What they do: Royal establishes a TCP socket for C2 communication using the API `WSASocketW`.
What that means: Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.
-
T1486 Data Encrypted for Impact Impact
What they do: Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (26)
▼Software Royal has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
royal.txt
Hello! If you are reading this, it means that your system were hit by Royal ransomware. Please contact us via : http://royal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid.onion/[snip] In the meantime, let us explain this case.It may seem complicated, but it is not! Most likely what happened was that you decided to save some money on your security infrastructure. Alas, as a result your critical data was not only encrypted but also copied from your systems on a secure server. From there it can be published online.Then anyone on the internet from darknet criminals, ACLU journalists, Chinese government(different names for the same thing), and even your employees will be able to see your internal documentation: personal data, HR reviews, internal lawsuitsand complains, financial reports, accounting, intellectual property, and more! Fortunately we got you covered! Royal offers you a unique deal.For a modest royalty(got it; got it ? ) for our pentesting services we will not only provide you with an amazing risk mitigation service, covering you from reputational, legal, financial, regulatory, and insurance risks, but will also provide you with a security review for your systems. To put it simply, your files will be decrypted, your data restoredand kept confidential, and your systems will remain secure. Try Royal today and enter the new era of data security! We are looking to hearing from you soon!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (212)
Search, filter and paginate the victim timeline for Royal. Showing 201–212 of 212.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | https://orthoexperts.com id4510 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | https://www.mmemed.com id4509 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | https://www.infocision.com id4508 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.wiseyes.net id4507 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.royalimaging.com id4506 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | https://www.whitneyoilco.com id4505 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.pandafunds.com id4504 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.veroni.it id4503 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.pressco.com id4502 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | http://www.cymax.com id4501 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | https://fishmans.ca id4500 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | https://quantumplastics.com id4499 View details | Other | — | ||
|
No additional victim description available. |
|||||