logo

Inside the Infamous Royal Ransomware Group: Unveiling Their Reign of Cyber Chaos

ID: af752b61-06e1-5438-8207-3af9708629f7

STIX ID: report--af752b61-06e1-5438-8207-3af9708629f7

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2023-06-04

Date Updated: 2026-04-27

...
...

This report profiles the Royal ransomware group (active since mid‑2022), documenting its growth, high-impact attacks (including a reported 249+ TB of leaked data), common intrusion methods (phishing, RDP compromise, public-facing app exploitation and broker-assisted access), multi-million-dollar ransom demands, regional victim distribution (predominantly the United States), provided IOCs (file names, IPs, domains, hashes, and onion payment sites), and recommended mitigations for organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.