Malware
Royal Ransom (ELF)
Also known as: Royal · Royal_unix
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
Indicators of Compromise 6
MITRE ATT&CK TTPs 8
T1021.001 T1059.001 T1071.001 T1090 T1204.002 T1486 T1543.003 T1566.002
Remote Desktop Protocol
Lateral Movement
PowerShell
Execution
Web Protocols
Command And Control
Proxy
Command And Control
Malicious File
Execution
Data Encrypted for Impact
Impact
Windows Service
Persistence
Spearphishing Link
Initial Access