Royal
High ConfidenceHigh ThreatDEV-0569 • Zeon
Royal ransomware was a ransomware operation active from September 2022 to mid-2023, believed to be composed of former Conti members. The group targeted organizations across healthcare, education, and manufacturing sectors, demanding ransoms ranging from $1 million to $11 million. Royal was notable for their callback phishing techniques and use of legitimate tools for lateral movement. The operation is believed to have rebranded as BlackSuit ransomware in 2023.
Royal ransomware was a ransomware operation active from September 2022 to mid-2023, believed to be composed of former Conti members. The group targeted organizations across healthcare, education, and manufacturing sectors, demanding ransoms ranging from $1 million to $11 million. Royal was notable for their callback phishing techniques and use of legitimate tools for lateral movement. The operation is believed to have rebranded as BlackSuit ransomware in 2023.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: High.
Future Outlook
Royal is expected to continue operations targeting Healthcare sectors.
First observed activity of Royal
Continued active operations