ATT&CKReferencesKroll Royal Deep Dive February 2023

Kroll Royal Deep Dive February 2023

Iacono, L. and Green, S. (2023, February 13). Royal Ransomware Deep Dive. Retrieved March 30, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareRoyal

Royal can identify specific files and directories to exclude from the encryption process.

T1486
Data Encrypted for Impact
MalwareRoyal

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1490
Inhibit System Recovery
MalwareRoyal

Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.

T1566
Phishing
MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.