Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1059

Royal Ransomware

Qu'est-ce que Royal Ransomware ?

Royal RansomwareA high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack.


Royal Ransomware appeared in early 2022 and quickly became one of the highest-impact private (non-affiliate-driven) ransomware operations of 2022–2023, attributed to former members of the Conti syndicate. It used a custom C++ encryptor with intermittent encryption (encrypting only a configurable percentage of each file for speed) and AES + RSA, leaving the `.royal` extension and a `README.TXT` note. The actor was reported to have hit over 350 victims globally, with U.S. CISA/FBI advisories highlighting its targeting of healthcare, education, manufacturing, and government — including the May 2023 attack on the City of Dallas, Texas, which disrupted public-safety services for weeks. Following intense law-enforcement attention, the operation rebranded in mid-2023 as 'BlackSuit', retaining the same encryptor lineage and TTPs (Cobalt Strike, BloodHound, ESXi-targeting Linux variant, double extortion via a leak site, initial access via callback-phishing and stolen credentials). U.S. CISA's #StopRansomware advisory in late 2023 published joint Royal/BlackSuit IOCs and TTPs.

Exemples

  1. 01

    Royal's May 2023 attack on the City of Dallas encrypted servers used by police, fire, and city-court systems and triggered a multi-week emergency response.

  2. 02

    A post-2023 BlackSuit intrusion follows the familiar pattern: callback-phishing pretext, BazarCall-style call-back, Cobalt Strike beacon, BloodHound, ESXi encryption, leak-site listing.

Questions fréquentes

Qu'est-ce que Royal Ransomware ?

A high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack. Cette notion relève de la catégorie Logiciels malveillants en cybersécurité.

Que signifie Royal Ransomware ?

A high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack.

Comment fonctionne Royal Ransomware ?

Royal Ransomware appeared in early 2022 and quickly became one of the highest-impact private (non-affiliate-driven) ransomware operations of 2022–2023, attributed to former members of the Conti syndicate. It used a custom C++ encryptor with intermittent encryption (encrypting only a configurable percentage of each file for speed) and AES + RSA, leaving the `.royal` extension and a `README.TXT` note. The actor was reported to have hit over 350 victims globally, with U.S. CISA/FBI advisories highlighting its targeting of healthcare, education, manufacturing, and government — including the May 2023 attack on the City of Dallas, Texas, which disrupted public-safety services for weeks. Following intense law-enforcement attention, the operation rebranded in mid-2023 as 'BlackSuit', retaining the same encryptor lineage and TTPs (Cobalt Strike, BloodHound, ESXi-targeting Linux variant, double extortion via a leak site, initial access via callback-phishing and stolen credentials). U.S. CISA's #StopRansomware advisory in late 2023 published joint Royal/BlackSuit IOCs and TTPs.

Comment se défendre contre Royal Ransomware ?

Les défenses contre Royal Ransomware combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.

Quels sont les autres noms de Royal Ransomware ?

Noms alternatifs courants : Royal, BlackSuit.

Termes liés