Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) investigators believe this variant, which uses its own custom-made file encryption program, evolved from earlier iterations that used “Zeon” as a loader. That is why they issued this latest Cybersecurity Advisory (CSA) as part of an ongoing #StopRansomware effort to publish warnings for network defenders that detail various ransomware variants and threat actors.
After gaining access to victims’ networks, Royal actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting the systems, according to the CSA.
Royal attackers have made ransom demands ranging from $1 million to $11 million in Bitcoin. Royal actors do not include ransom amounts and payment instructions as part of the initial ransom note. Instead, the note, which appears after encryption, requires victims to directly interact with the threat actor via a .onion URL (reachable through the Tor browser).
Royal actors have targeted numerous critical infrastructure sectors including manufacturing, communications, healthcare and public healthcare (HPH), and education.
Royal ransomware uses a unique partial encryption approach that allows the threat actor to choose a specific percentage of data in a file to encrypt, according to the CSA. This approach allows the actor to lower the encryption percentage for larger files, which helps evade detection. In addition to encrypting files, Royal actors also engage in double extortion tactics in which they threaten to publicly release the encrypted data if the victim does not pay the ransom.
Royal actors gain initial access to victim networks in a number of ways including:
Phishing: Royal actors most commonly (in 66.7 percent of incidents) gain initial access to victim networks via successful phishing emails
Remote Desktop Protocol (RDP): The second most common vector Royal actors use (in 13.3 percent of incidents) for initial access is RDP compromise
Public-facing applications: FBI also observed Royal actors gain initial access through exploiting public-facing applications
Brokers: Reports from trusted third-party sources indicate Royal actors may leverage brokers to gain initial access and source traffic by harvesting virtual private network (VPN) credentials from stealer logs
Once Royal actors gain access to the network, they communicate with command and control (C2) infrastructure and download multiple tools, according to the CSA.
Legitimate Windows software is repurposed by Royal operators to strengthen their foothold in the victim’s network. Ransomware operators often use open-source projects to aid their intrusion activities; Royal operators have been observed using Chisel, a tunneling tool transported over HTTP and secured via SSH, to communicate with their C2 infrastructure. FBI has observed multiple Qakbot C2s used in Royal ransomware attacks, but has not yet determined if Royal ransomware exclusively uses Qakbot C2s.
In addition, Royal actors often use RDP to move laterally across the network. Microsoft Sysinternals tool PsExec has also been used to aid lateral movement, according to the CSA.
FBI has observed Royal actors using remote monitoring and management (RMM) software, such as AnyDesk, LogMeIn, and Atera, for persistence in the victim’s network. In some instances, the actors moved laterally to the domain controller. In one confirmed case, the actors used a legitimate admin account to remotely log on to the domain controller. Once on the domain controller, the threat actor deactivated antivirus protocols by modifying Group Policy Objects.
Royal actors exfiltrate data from victim networks by repurposing legitimate cyber pentesting tools, such as Cobalt Strike, and malware tools and derivatives, such as Ursnif/Gozi, for data aggregation and exfiltration, according to the CSA. Royal actors’ first hop in exfiltration and other operations is usually a U.S. IP address.
Click here for more on the Royal ransomware CSA.

