Royal

MITRE ATT&CK: S1073 View on attack.mitre.org

Aliases: Royal

First seen
2022-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows, esxi
Related IoCs
3 (2 malicious)
Last IoC activity
2026-08-15 14:42:34
Profile updated
2026-07-07 13:10:41

Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing government-and-public-sector technology-and-telecommunications

Context

Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023. Royal employs partial encryption and multiple threads to evade detection and speed encryption. Royal has been used in attacks against multiple industries worldwide--including critical infrastructure. Security researchers have identified similarities in the encryption routines and TTPs used in Royal and Conti attacks and noted a possible connection between their operators.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Royal (S1073). The 2 most recently updated:

Detection coverage

  • 3 YARA rules
  • 213 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Service Stop (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Hypervisor CLI (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Phishing (attack-pattern)
  • Process Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Detection rules

  • SIGNATURE_BASE_MAL_EXE_Royalransomware (yara-rule)
  • MALPEDIA_Win_Royal_Ransom_Auto (yara-rule)
  • MALPEDIA_Win_Royal_Dns_Auto (yara-rule)

Reports & references

  • Microsoft — Dev 0569 Finds New Ways To Deliver Royal Ransomware Various Payloads (report)
  • ransomlook.io — Royal (report)
  • Trend Micro — Royal Ransomware Expands Attacks By Targeting Linux Esxi Servers (report)
  • CISA — Aa23 061A (report)
  • kroll.com — Royal Ransomware Deep Dive (report)
  • cybereason.com — Royal Ransomware Analysis (report)
  • MITRE ATT&CK — S1073 (report)

External references