logo

Royal Ransomware Publishes Nearly 60 Victims in Two Months as Attacks Accelerate

ID: 63bc9610-f26e-5949-950d-bd7bec6fbd8b

STIX ID: report--63bc9610-f26e-5949-950d-bd7bec6fbd8b

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Varshini

...
...

Royal ransomware sharply escalated operations in late 2022, listing nearly 60 victims on its leak site over two months and using aggressive, multi-stage TTPs: phishing/HTML-smuggling to deliver Qbot/IcedID, ISO/LNK launchers, Cobalt Strike for post‑exploitation, rapid lateral movement via credential abuse and SMB, data exfiltration to cloud services, and a double‑extortion model with Tor‑based negotiation portals. The report highlights persistence mechanisms (Qbot DLLs, services), discovery and lateral tools (PowerSploit, AdFind, native Windows tooling), process injection, a UAC bypass, and the group's preference for speed over stealth, emphasizing the need for proactive detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.