Description
Royal is a ransomware operation staffed by experienced affiliates, some from the Conti network, that gained attention through high value extortion demands. Its operators favor callback phishing to establish contact, deploy custom tooling, and encrypt Windows and Linux systems, and they added support for VMware ESXi virtual machines as their campaigns matured. The brand later rebranded, illustrating how ransomware crews rotate names while preserving infrastructure and tactics.
Stats
- First seen
- November 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
15 techniques across 6 tactics.
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.Ransom.Royal.CMD.A.FFFFFFFE |
| Dump:Generic.Ransom.Royal.CMD.A.FFFFFFFE |
| Gen:Variant.Linux.Ransom.Royal.1 |
| Gen:Variant.Ransom.Royal.1 |
| Gen:Variant.Ransom.Royal.13 |
| Gen:Variant.Ransom.Royal.6 |
| Linux.Ransomware.Royal |
| Trojan.Linux.Ransom.Royal.AF |
| Trojan.Linux.Ransom.Royal.EA |
| Trojan.Ransom.Royal.A |





