royal logo

royal

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Royal Hacking Group, Zeon
Ver en IntelTracker → APTTrail →
Royal is a financially motivated cybercriminal ransomware organization that emerged in early 2022, initially operating under the name Zeon before rebranding to Royal in September 2022. Assessed with high confidence to be of Russian origin, the group is composed of experienced individuals, many believed to be former members of the Conti ransomware operation. Unlike many contemporary ransomware groups, Royal operates as a closed, private team rather than utilizing a Ransomware-as-a-Service (RaaS) model with affiliates, which contributes to its consistent tradecraft and tighter operational security. This structure also allowed the group to adapt quickly to new tactics. Royal is known for its aggressive targeting, high ransom demands, and its unique approach to encryption, employing partial encryption to evade detection and accelerate the process. The group ceased operations under the Royal name around June 2023, subsequently rebranding to BlackSuit.
Tecnicas MITRE
T1021, T1055, T1068, T1027, T1486, T1490
CVEs relacionadas
CVE-2023-36036, CVE-2023-36033, CVE-2023-3284, CVE-2023-23583, CVE-2023-20592

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaBelgiumBrazilCanadaSwitzerlandChinaCosta RicaGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com