Royal Ransom (Powershell)
- First seen
- 2022-09-01 00:00:00
- Malware type
- downloader, ransomware
- Profile updated
- 2026-07-07 14:22:39
Targeted industries: healthcare-and-pharmaceutical financial-services technology-and-telecommunications government-and-public-sector
Context
Toolkit downloader used by Royal Ransomware group, involving GnuPG for decryption.
Reports & references
- redsense.com — Royal Blacksuit How Ransomware Rebrand Reshaped Them (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Royal Ransom (report)
- CISA — Aa23 061A (report)