ATT&CKReferencesTrend Micro Royal Linux ESXi February 2023

Trend Micro Royal Linux ESXi February 2023

Morales, N. et al. (2023, February 20). Royal Ransomware Expands Attacks by Targeting Linux ESXi Servers. Retrieved March 30, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1059.012
Hypervisor CLI
MalwareRoyal

Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.

T1082
System Information Discovery
MalwareRoyal

Royal can use `GetNativeSystemInfo` to enumerate system processors.

T1083
File and Directory Discovery
MalwareRoyal

Royal can identify specific files and directories to exclude from the encryption process.

T1486
Data Encrypted for Impact
MalwareRoyal

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1680
Local Storage Discovery
MalwareRoyal

Royal can use `GetLogicalDrives` to enumerate logical drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.