Royal Ransomware
Что такое Royal Ransomware?
Royal RansomwareA high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack.
Royal Ransomware appeared in early 2022 and quickly became one of the highest-impact private (non-affiliate-driven) ransomware operations of 2022–2023, attributed to former members of the Conti syndicate. It used a custom C++ encryptor with intermittent encryption (encrypting only a configurable percentage of each file for speed) and AES + RSA, leaving the `.royal` extension and a `README.TXT` note. The actor was reported to have hit over 350 victims globally, with U.S. CISA/FBI advisories highlighting its targeting of healthcare, education, manufacturing, and government — including the May 2023 attack on the City of Dallas, Texas, which disrupted public-safety services for weeks. Following intense law-enforcement attention, the operation rebranded in mid-2023 as 'BlackSuit', retaining the same encryptor lineage and TTPs (Cobalt Strike, BloodHound, ESXi-targeting Linux variant, double extortion via a leak site, initial access via callback-phishing and stolen credentials). U.S. CISA's #StopRansomware advisory in late 2023 published joint Royal/BlackSuit IOCs and TTPs.
● Примеры
- 01
Royal's May 2023 attack on the City of Dallas encrypted servers used by police, fire, and city-court systems and triggered a multi-week emergency response.
- 02
A post-2023 BlackSuit intrusion follows the familiar pattern: callback-phishing pretext, BazarCall-style call-back, Cobalt Strike beacon, BloodHound, ESXi encryption, leak-site listing.
● Частые вопросы
Что такое Royal Ransomware?
A high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack. Относится к категории Вредоносное ПО в кибербезопасности.
Что означает Royal Ransomware?
A high-impact ransomware family that emerged from former Conti members in early 2022, hit hundreds of U.S. critical-infrastructure victims, and rebranded to BlackSuit in mid-2023 after the City of Dallas attack.
Как работает Royal Ransomware?
Royal Ransomware appeared in early 2022 and quickly became one of the highest-impact private (non-affiliate-driven) ransomware operations of 2022–2023, attributed to former members of the Conti syndicate. It used a custom C++ encryptor with intermittent encryption (encrypting only a configurable percentage of each file for speed) and AES + RSA, leaving the `.royal` extension and a `README.TXT` note. The actor was reported to have hit over 350 victims globally, with U.S. CISA/FBI advisories highlighting its targeting of healthcare, education, manufacturing, and government — including the May 2023 attack on the City of Dallas, Texas, which disrupted public-safety services for weeks. Following intense law-enforcement attention, the operation rebranded in mid-2023 as 'BlackSuit', retaining the same encryptor lineage and TTPs (Cobalt Strike, BloodHound, ESXi-targeting Linux variant, double extortion via a leak site, initial access via callback-phishing and stolen credentials). U.S. CISA's #StopRansomware advisory in late 2023 published joint Royal/BlackSuit IOCs and TTPs.
Как защититься от Royal Ransomware?
Защита от Royal Ransomware обычно сочетает технические меры и операционные практики, как описано в определении выше.
Какие есть другие названия Royal Ransomware?
Распространённые альтернативные названия: Royal, BlackSuit.
● Связанные термины
- malware№ 1004
Программа-вымогатель
Вредоносное ПО, которое шифрует данные жертвы или блокирует системы и требует выкуп за восстановление доступа.
- defense-ops№ 1005
Ransomware-группировка
Финансово мотивированная киберпреступная группа, разрабатывающая, эксплуатирующая или распространяющая шифровальщик ради вымогательства у организаций.
- defense-ops№ 238
Ransomware Conti
Русскоязычная ransomware-операция 2020—2022 годов, проводившая одну из самых массовых программ двойного вымогательства и распавшаяся после крупных внутренних утечек.
- defense-ops№ 695
LockBit
Русскоязычная ransomware-as-a-service группа, ставшая в 2022—2024 годах самой плодовитой по числу жертв и серьёзно подорванная операцией Cronos.
- defense-ops№ 115
BlackCat / ALPHV
Ransomware-as-a-service группа на Rust, активная с конца 2021 до 2024 года, известная кроссплатформенными шифровальщиками и агрессивным многоступенчатым вымогательством.
- attacks№ 307
Утечка данных (непреднамеренная)
Случайное или халатное раскрытие конфиденциальной информации, обычно из-за неправильной настройки или человеческой ошибки, а не активной атаки.