Royal Ransomware

Description Summary

Royal ransomware was first observed in September 2022, formed by experienced operators with prior ties to Conti Team 1. It uses partial (intermittent) encryption — encrypting only a configurable percentage of file content for speed. Royal does not operate a public affiliate program. The group is widely believed to have rebranded to BlackSuit in mid-2023.

Threat Actor

Closed group of former Conti members. Initial access via callback phishing (BazarCall-style), RDP, and exposed services.

Technical Indicators

Encryption Extension
.royal / .royal_w
Encryption Algorithm
AES-256 + RSA-2048 (intermittent/partial encryption)
Ransom Note Name
README.TXT
Targeted Industries
Healthcare, Manufacturing, Communications, Education, Critical infrastructure
First Seen
September 2022
Last Seen
Mid-2023 (rebranded to BlackSuit)
Geographical Location
United States, Brazil, North America, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1566 Phishing (Callback / BazarCall)
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Partial Encryption