Royal
MITRE ATT&CK: S1073 View on attack.mitre.org
Aliases: Royal
- First seen
- 2022-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows, esxi
- Related IoCs
- 3 (2 malicious)
- Last IoC activity
- 2026-08-15 14:42:34
- Profile updated
- 2026-07-07 13:10:41
Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing government-and-public-sector technology-and-telecommunications
Context
Royal is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed in February 2023. Royal employs partial encryption and multiple threads to evade detection and speed encryption. Royal has been used in attacks against multiple industries worldwide--including critical infrastructure. Security researchers have identified similarities in the encryption routines and TTPs used in Royal and Conti attacks and noted a possible connection between their operators.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Royal (S1073). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | https://www.x2ydevs.xyz/products/x2y-av-ultimate | 2026-08-15 | 1 |
| file sample | 09a79e5e20fa4f5aae610c8ce3fe954029a91972b56c6576035ff7e0ec4c1d14.elf | 2025-07-25 | 2 |
Detection coverage
- 3 YARA rules
- 213 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Service Stop (attack-pattern)
- System Information Discovery (attack-pattern)
- Hypervisor CLI (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Network Service Discovery (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Native API (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Phishing (attack-pattern)
- Process Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
Detection rules
- SIGNATURE_BASE_MAL_EXE_Royalransomware (yara-rule)
- MALPEDIA_Win_Royal_Ransom_Auto (yara-rule)
- MALPEDIA_Win_Royal_Dns_Auto (yara-rule)
Reports & references
- Microsoft — Dev 0569 Finds New Ways To Deliver Royal Ransomware Various Payloads (report)
- ransomlook.io — Royal (report)
- Trend Micro — Royal Ransomware Expands Attacks By Targeting Linux Esxi Servers (report)
- CISA — Aa23 061A (report)
- kroll.com — Royal Ransomware Deep Dive (report)
- cybereason.com — Royal Ransomware Analysis (report)
- MITRE ATT&CK — S1073 (report)