← All actors

Royal / BlackSuit

Aliases: Royal ransomware, BlackSuit, Royal ransomware group

Source profile review date: 2026-06-01

Added to the source registry: 2022-11-04 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Locally generated translation; linguistic review is still pending.

Executive summary

Royal, later publicly linked to BlackSuit, is a double-extortion operation that combines phishing, remote access, legitimate tools and targeted encryption.

Royal and BlackSuit are particularly relevant because CISA/FBI link the operation to an adult attack chain with stolen access, living-off-the-land, data diode and use of legitimate software for deployment and management.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Royal should be read as a threat to organisations where identity, remote access and management rights are not sufficiently limited.CISA /FBI- advisory describes Royal ransomware and laterBlackSuit -double extortion activity: data is stolen, systems can be encrypted and publication printing used to enforce payment. For visitors, the main lesson is that Royal is not dependent on one exotic vulnerability. The group uses usable access, internal exploration and legitimate management tools to make the attack business efficient.

    Royal is also relevant in public reporting due to the possible relationship or transition to BlackSuit. For defense, that brand does not matter as much as its behaviour. An organization that only blocks an old Royal extension or a known hash lacks the larger pattern: phishing or compromised credentials, remote access, privilege building, data staging, use of tools that are also used by administrators, and then encryption or publication.

    The translation into decision-making is concrete.VPN ,EDR ,RMM- tooling, domain management and backups all with the same identity or accessible from the same network zones, Royal/BlackSuit a continuity risk. If those layers are separated, logged and tested, the same threat becomes much more manageable.

    Grouping and development

    Royal appeared after the disappearance of some large ransomware brands and is placed by multiple public sources in the wider criminal ransomware economy. The operation is known for high ransom demands, selective pressure on victims and use of double extortion. The CISA/99800FBI-update adds BlackSuit-IOCfus and TTPfusseries, indicating that defenders should not treat Royal and BlackSuit as completely loose files.

    Royal often uses common access paths. Think of phishing, compromised credentials, remote services and lateral management. The group or affiliates then use tools that are not automatically suspicious in business environments. This means basiclining is important: what is normal management, which RMM- tools are allowed, which accounts may do deployment and which systems can send data out?

    One important point is that Royal not only causes technical damage, but administrative pressure.A claim on a leak site, a ransom note or contact with negotiators should be linked to technical facts: has data been staged, is there exfiltration volume, which systems are encrypted, what accounts were involved and how reliable are backups?

    Attack pattern from public cases

    TheCISA /FBI- advisory describes Royal andBlackSuit -IOC . . . and calls legitimate software used by the actors, which fits with an attack chain in which the actor does not have to continuously drop malware.RMM- tools, command-line utilities,PowerShell , PsExec-like behaviour and deployment software can be enough to build control over a network.

    In the exploration phase, identity and file-share signals are especially important. Look for new admin rights, unusualVPN- logins,RDP- sessions between servers, domain exploration, share discovery and access to sensitive data outside normal patterns. Royal/BlackSuit only becomes truly harmful when that access is combined with data diode and deployment of encryption devices.

    In the impact phase, CISA for Royal mentions among others .royal as an encrypted extension and README.TXT as a ransom note. BlackSuit activity has its own artifacts, but the defense point remains the same: extension and ransom note confirm a late stage. The organization should react to credential error, tooling deployment and datataging rather than any other.

    Known IOCs and artifacts

    For Royal, CISA calls .royal as an encrypted file extension and README.TXT as a ransom note. These are useful confirmation indicators for incident response but they come late into the attack chain. Use them for scope determination and forensic timeline, not as only preventive detection.

    The advisory also containsIP- addresses, file indicators and lists of legitimate software provided by Royal/BlackSuit - Actors are used.CISA warns olderIP- addresses must be carefully validated before they are used for blocking. For defense it is stronger to detect using unknownRMM- tooling, deployment to many hosts at once,EDR- tamping and data compression.

    BlackSuit -IOC • In the case ofCISA- Update the profile to keep alive. An organization must retain older Royal indicators for retro-hunting, but in additionBlackSuit -behaviour in detection: remote services, lateral movement, credential access, file discovery, exfiltration and impact on backups.

    Victim pattern and lessons

    Royal and BlackSuit are relevant to a wide range of sectors because the model is not dependent on one branch. The actor seeks organisations where payment under pressure is likely: many sensitive data, high availability requirements, limited segmentation or weak recovery security, which makes a claim in a similar organisation directly usable as a scenario for own risk analysis.

    The most important lesson from victim patterns is that RMM and management layers are often the lever. When deployment tools, remote support and domain admin rights are too widely available, an actor can move quickly from one input to many systems. Security teams should therefore not only protect endpoints but also make the management chain hard.

    A second lesson is that publication pressure is independent of encryption damage. If data is stolen, file recovery is not enough. Contracts, customer communication, reporting obligations and reputation must be prepared simultaneously.

    How to arm yourself against Royal / BlackSuit

    Limit external access with MFA, conditional access, device binding and tight logging. Check dormant accounts, vendor access, old VPN- profiles and service accounts. Royal-like attacks often start with access that seems technically valid.

    Make RMM and deployment tools explicit. Only approved tools are allowed to run, with known owner, logging and change process. New remote agents on servers must be treated as high risk immediately. Monitor also mass deployment, simultaneous service changes and command lines that hit many hosts.

    Protect data and recovery. Detect archiving, datastaging, large outbound transfers and access to backup servers. Test recovery when the domain cannot be trusted. Separation backup management, hypervisor management and common domain admin permissions so that one compromised identity does not affect the entire continuity.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    extension.royalCISA AA23-061ARoyal encrypted file extension.
    filenameREADME.TXTCISA AA23-061ARoyal ransom note artifact.
    behavioruse of legitimate software and open-source toolsCISA AA23-061ARoyal/BlackSuit actors observed using legitimate tooling during operations.
    behaviordouble extortion with data theft and encryptionCISA AA23-061ACore operational model for pressure on victims.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.