royal
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
Royal ransomware group is a seasoned cybercriminal gang from former Conti Team One members targeting critical infrastructure via targeted phishing.
The Royal ransomware group, active since September 2022, is composed of seasoned cybercriminals believed to be former members of Conti Team One. They primarily target large and medium-sized organizations, with a focus on critical infrastructure sectors. Their key TTPs include gaining initial access via targeted phishing emails and using tools like Cobalt Strike for lateral movement within the network. Defenders must urgently strengthen email security, verify network segmentation, and ensure functional offline backups of critical data.
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
The members of the Royal ransomware group are believed to be seasoned cybercriminals who used to be part of Conti Team One.
They primarily gain initial access via targeted phishing emails sent to individual victims.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.