Royal

S1073

Malware.View on attack.mitre.org

About this malware

Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023. Royal employs partial encryption and multiple threads to evade detection and speed encryption. Royal has been used in attacks against multiple industries worldwide--including critical infrastructure. Security researchers have identified similarities in the encryption routines and TTPs used in Royal and Conti attacks and noted a possible connection between their operators.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1016
System Network Configuration Discovery

Royal can enumerate IP addresses using `GetIpAddrTable`.

T1021.002
SMB/Windows Admin Shares

Royal can use SMB to connect to move laterally.

T1046
Network Service Discovery

Royal can scan the network interfaces of targeted systems.

T1057
Process Discovery

Royal can use `GetCurrentProcess` to enumerate processes.

T1059.012
Hypervisor CLI

Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.

T1082
System Information Discovery

Royal can use `GetNativeSystemInfo` to enumerate system processors.

T1083
File and Directory Discovery

Royal can identify specific files and directories to exclude from the encryption process.

T1095
Non-Application Layer Protocol

Royal establishes a TCP socket for C2 communication using the API `WSASocketW`.

T1106
Native API

Royal can use multiple APIs for discovery, communication, and execution.

T1135
Network Share Discovery

Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.

T1486
Data Encrypted for Impact

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1489
Service Stop

Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption.

T1490
Inhibit System Recovery

Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.

T1566
Phishing

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

T1680
Local Storage Discovery

Royal can use `GetLogicalDrives` to enumerate logical drives.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. CISA Royal AA23-061A March 2023 Open source
    CISA. (2023, March 2). #StopRansomware: Royal Ransomware. Retrieved March 31, 2023.
  2. Cybereason Royal December 2022 Open source
    Cybereason Global SOC and Cybereason Security Research Teams. (2022, December 14). Royal Rumble: Analysis of Royal Ransomware. Retrieved March 30, 2023.
  3. Kroll Royal Deep Dive February 2023 Open source
    Iacono, L. and Green, S. (2023, February 13). Royal Ransomware Deep Dive. Retrieved March 30, 2023.
  4. Microsoft Royal ransomware November 2022 Open source
    MSTIC. (2022, November 17). DEV-0569 finds new ways to deliver Royal ransomware, various payloads. Retrieved March 30, 2023.
  5. Trend Micro Royal Linux ESXi February 2023 Open source
    Morales, N. et al. (2023, February 20). Royal Ransomware Expands Attacks by Targeting Linux ESXi Servers. Retrieved March 30, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.