Royal ransomware has rapidly intensified its operations, publishing nearly 60 victims on its leak site in just two months and using aggressive, multi-stage TTPs that combine Qbot, Cobalt Strike, fast lateral movement, and double extortion.
Royal emerged in early 2022 and quickly evolved into one of the more prolific enterprise-targeting ransomware operations, regularly hitting organizations across critical sectors.
Analysis of its Tor leak site shows that in November and December 2022 alone, the group listed almost 60 victims, indicating a sharp acceleration in successful compromises within a short window.
Incident responders note that not all impacted organizations appear on the leak site, meaning the true victim count in that period is likely significantly higher.
Royal follows a classic double-extortion model, combining data encryption with data theft and public shaming to increase pressure on victims to pay.
Ransom demands for Royal typically range from hundreds of thousands of dollars to several million, with negotiations conducted through a Tor-based portal referenced in README.txt ransom notes dropped across encrypted systems.
Royal Ransomware Attack Surge
Royal’s attack chains commonly begin with phishing or spearphishing emails that deliver an initial access malware family such as Qbot, IcedID, or other loaders.
In observed incidents, spearphishing attachments or HTML-smuggling techniques deliver password-protected archives containing ISO images and hidden payloads that are launched via LNK files, ultimately executing Qbot on victim hosts.
Once initial access is established, operators use the Windows command shell and encoded PowerShell to stage and run Cobalt Strike beacons, providing interactive control over compromised systems.

For persistence, Royal affiliates add Qbot DLLs into registry run keys and install Cobalt Strike as Windows services across multiple systems, ensuring that access survives reboots and basic remediation attempts.
They heavily abuse domain accounts and privileged credentials, including pass-the-hash techniques, to move laterally via SMB and administrative shares such as C$.
Discovery of accounts, domain trusts, and network shares is often performed with PowerSploit, AdFind, and built-in Windows tools, allowing rapid mapping of the environment before mass encryption.
To evade defenses, Royal operators rely on process injection into legitimate Windows processes and extensive use of PowerShell, as well as a notable UAC bypass that abuses a default scheduled task to launch PowerShell with elevated privileges.
They also use multiple backdoors and C2 channels, including HTTPS for Qbot and Cobalt Strike, and SMB-named pipes for peer-to-peer communication.
Before triggering the final stage, data is exfiltrated to cloud storage platforms such as Dropbox and Mega, enabling follow-up extortion threats even if victims attempt recovery from backups, invictus said.
Royal’s operators favor speed over stealth, often moving from initial access to full domain compromise in a compressed timeline, which makes proactive detection and tight monitoring essential.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.