Ransomware

CISA and FBI warn of Royal ransomware attacks

0

CISA and the FBI have issued a joint advisory highlighting the increasing threat behind ongoing Royal ransomware attacks targeting many U.S. critical infrastructure sectors, including healthcare, communications, and education.

The human-operated Royal ransomware which first emerged in September 2022 has demanded ransoms up to millions of dollars.

Unlike other ransomware operations, Royal doesn’t offer Ransomware-as-a-Service, instead it appears to be a private group without a network of affiliates.

Once compromised a victim’s network, threat actors deploy the post-exploitation tool Cobalt Strike to maintain persistence and perform lateral movements.

The Royal ransomware is written in C++, it infected Windows systems and deletes all Volume Shadow Copies to prevent data recovery. The ransomware encrypts the network shares, that are found on the local network and the local drives, with the AES algorithm.

The FBI and the CISA released a joint Cybersecurity Advisory (CSA) to provide organizations, tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with this ransomware family.

According to government experts, the Royal ransomware attacks targeted numerous critical infrastructure sectors including, manufacturing, communications, healthcare and public healthcare (HPH), and education.

The new variant, which uses its own custom-made file encryption program, is believed to have evolved from earlier iterations that used “Zeon” as a loader. After gaining access to victims’ networks, Royal actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting the systems.

Royal operators have demanded ransom ranging from approximately $1 million to $11 million USD worth of Bitcoin.

The Royal ransomware can either fully or partially encrypt a file depending on its size and the ‘-ep’ parameter. The malware changes the extension of the encrypted files to ‘.royal’.

The operators have recently been observed using the Chisel tunneling tool for C2 communication. FBI has observed multiple Qakbot C2s used in Royal ransomware attacks, but it is still unclear if Royal ransomware exclusively uses Qakbot C2s.

FBI also observed Royal actors using remote monitoring and management (RMM) software, such as AnyDesk, LogMeIn, and Atera, to maintain persistence in the victim’s network.

Image Credits : Bleeping Computer

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

LastPass reveals second data breach of encrypted password vaults

Previous article

HDFC Bank denies data leak claim

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *