Ransomware group profile · #29 by claimed victims
Royal / BlackSuit ransomwarealso BlackSuit, Quantum, Zeon
Successor lineage to Conti, later rebranded as BlackSuit. Distinguished by callback phishing, where the mail contains no link or attachment at all, only a phone number.
Victimology
Who Royal / BlackSuit claims to have breached, from 211 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Braintree Public Schools braintreema.gov | Education | US | 19 Jul 2023 |
| Tachi-S Engineering USA tachi-s.com | Manufacturing | — | 11 Jun 2023 |
| PENNCREST School District penncrest.org | Education | — | 9 Jun 2023 |
| Groupe Sovitrat Interim and Recrutement sovitrat.fr | Professional Services | FR | 26 May 2023 |
| BM Precision bmprecision.com | Manufacturing | — | 26 May 2023 |
| DirectViz Solutions directviz.com | Technology | — | 26 May 2023 |
| The Best Connection thebestconnection.co.uk | Professional Services | GB | 26 May 2023 |
| Mitutoyo mitutoyo.ch | Manufacturing | CH | 26 May 2023 |
| AFG Holdings afgholdings.com | Manufacturing | — | 26 May 2023 |
| Volt volt.com | Professional Services | US | 26 May 2023 |
| Colrich colrich.com | Manufacturing | ZA | 26 May 2023 |
| Haworth Tompkins haworthtompkins.com | Professional Services | — | 26 May 2023 |
All 211 Royal / BlackSuit victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
5 MITRE ATT&CK techniques mapped to Royal / BlackSuit from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1566.003 Spearphishing via Service | Callback phishing: an email claims a subscription is about to renew and gives only a telephone number. The victim calls, and is talked through installing remote… | Confirmed |
| Lateral Movement | T1021.002 SMB/Windows Admin Shares | PsExec and SMB, with NSudo used to run as SYSTEM. | Confirmed |
| Command and Control | T1572 Protocol Tunneling | Chisel tunnelled over HTTP to give inbound reach through the perimeter. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | Rclone to cloud storage. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | Partial encryption with an attacker-chosen percentage per file, trading thoroughness for speed. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Royal / BlackSuit intrusion unfolds, section by section.
Social engineering
Phishing with nothing to detonate — Callback phishing removes every artefact a mail security product inspects. The only content is text and a phone number, so detection has to be either linguistic or procedural.
Frequently asked
Is Royal / BlackSuit ransomware still active?
How many victims has Royal / BlackSuit claimed?
Which industries does Royal / BlackSuit target?
Which countries are most affected by Royal / BlackSuit?
Where does VULONE get Royal / BlackSuit victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| #StopRansomware: Royal Ransomware (AA23-061A) | CISA / FBI | 2 Mar 2023 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].