ATT&CKReferencesCybereason Royal December 2022

Cybereason Royal December 2022

Cybereason Global SOC and Cybereason Security Research Teams. (2022, December 14). Royal Rumble: Analysis of Royal Ransomware. Retrieved March 30, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRoyal

Royal can enumerate IP addresses using `GetIpAddrTable`.

T1021.002
SMB/Windows Admin Shares
MalwareRoyal

Royal can use SMB to connect to move laterally.

T1046
Network Service Discovery
MalwareRoyal

Royal can scan the network interfaces of targeted systems.

T1057
Process Discovery
MalwareRoyal

Royal can use `GetCurrentProcess` to enumerate processes.

T1082
System Information Discovery
MalwareRoyal

Royal can use `GetNativeSystemInfo` to enumerate system processors.

T1083
File and Directory Discovery
MalwareRoyal

Royal can identify specific files and directories to exclude from the encryption process.

T1095
Non-Application Layer Protocol
MalwareRoyal

Royal establishes a TCP socket for C2 communication using the API `WSASocketW`.

T1106
Native API
MalwareRoyal

Royal can use multiple APIs for discovery, communication, and execution.

T1135
Network Share Discovery
MalwareRoyal

Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.

T1486
Data Encrypted for Impact
MalwareRoyal

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1489
Service Stop
MalwareRoyal

Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption.

T1490
Inhibit System Recovery
MalwareRoyal

Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.

T1566
Phishing
MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

T1680
Local Storage Discovery
MalwareRoyal

Royal can use `GetLogicalDrives` to enumerate logical drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.