Netskope Threat Labs

Royal

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Royal is a ransomware operation staffed by experienced affiliates, some from the Conti network, that gained attention through high value extortion demands. Its operators favor callback phishing to establish contact, deploy custom tooling, and encrypt Windows and Linux systems, and they added support for VMware ESXi virtual machines as their campaigns matured. The brand later rebranded, illustrating how ransomware crews rotate names while preserving infrastructure and tactics.

First seen
November 2022
Last seen
October 2026

15 techniques across 6 tactics.

TA0001 Initial Access

TA0002 Execution

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1046Network Service Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1135Network Share Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

TA0011 Command and Control

  • T1095Non-Application Layer Protocol

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery
Alert Name
DeepScan:Generic.Ransom.Royal.CMD.A.FFFFFFFE
Dump:Generic.Ransom.Royal.CMD.A.FFFFFFFE
Gen:Variant.Linux.Ransom.Royal.1
Gen:Variant.Ransom.Royal.1
Gen:Variant.Ransom.Royal.13
Gen:Variant.Ransom.Royal.6
Linux.Ransomware.Royal
Trojan.Linux.Ransom.Royal.AF
Trojan.Linux.Ransom.Royal.EA
Trojan.Ransom.Royal.A