ATT&CKReferencesCISA Royal AA23-061A March 2023

CISA Royal AA23-061A March 2023

CISA. (2023, March 2). #StopRansomware: Royal Ransomware. Retrieved March 31, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1490
Inhibit System Recovery
MalwareRoyal

Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.

T1566
Phishing
MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.