Royal Ransomware Publishes Nearly 60 Victims in Two Months as Attacks Accelerate
ID: 63bc9610-f26e-5949-950d-bd7bec6fbd8b
STIX ID: report--63bc9610-f26e-5949-950d-bd7bec6fbd8b
Feed Name: Cyber Press
Royal ransomware sharply escalated operations in late 2022, listing nearly 60 victims on its leak site over two months and using aggressive, multi-stage TTPs: phishing/HTML-smuggling to deliver Qbot/IcedID, ISO/LNK launchers, Cobalt Strike for post‑exploitation, rapid lateral movement via credential abuse and SMB, data exfiltration to cloud services, and a double‑extortion model with Tor‑based negotiation portals. The report highlights persistence mechanisms (Qbot DLLs, services), discovery and lateral tools (PowerSploit, AdFind, native Windows tooling), process injection, a UAC bypass, and the group's preference for speed over stealth, emphasizing the need for proactive detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
