← All ransomware groups

Ransomware group profile · #29 by claimed victims

Royal / BlackSuit ransomwarealso BlackSuit, Quantum, Zeon

Successor lineage to Conti, later rebranded as BlackSuit. Distinguished by callback phishing, where the mail contains no link or attachment at all, only a phone number.

Active Russia First seen Sep 2022 ATT&CK G1042 AES with RSA wrapped key, with a configurable partial encryption percentage Russian
211Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
20Countries hit
5Leak-site URLs tracked, 0 online
19 Jul 2023Latest claim recorded

Victimology

Who Royal / BlackSuit claims to have breached, from 211 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing57
Professional Services33
Education19
Healthcare14
Retail & E-Commerce13
Technology12
Government & Defense12
Energy & Utilities11

Top countries

United States24
Germany8
United Kingdom6
France4
Brazil4
Canada4
Australia3
Portugal2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Braintree Public Schools braintreema.gov Education US 19 Jul 2023
Tachi-S Engineering USA tachi-s.com Manufacturing 11 Jun 2023
PENNCREST School District penncrest.org Education 9 Jun 2023
Groupe Sovitrat Interim and Recrutement sovitrat.fr Professional Services FR 26 May 2023
BM Precision bmprecision.com Manufacturing 26 May 2023
DirectViz Solutions directviz.com Technology 26 May 2023
The Best Connection thebestconnection.co.uk Professional Services GB 26 May 2023
Mitutoyo mitutoyo.ch Manufacturing CH 26 May 2023
AFG Holdings afgholdings.com Manufacturing 26 May 2023
Volt volt.com Professional Services US 26 May 2023
Colrich colrich.com Manufacturing ZA 26 May 2023
Haworth Tompkins haworthtompkins.com Professional Services 26 May 2023

All 211 Royal / BlackSuit victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

5 MITRE ATT&CK techniques mapped to Royal / BlackSuit from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1566.003 Spearphishing via Service Callback phishing: an email claims a subscription is about to renew and gives only a telephone number. The victim calls, and is talked through installing remote… Confirmed
Lateral Movement T1021.002 SMB/Windows Admin Shares PsExec and SMB, with NSudo used to run as SYSTEM. Confirmed
Command and Control T1572 Protocol Tunneling Chisel tunnelled over HTTP to give inbound reach through the perimeter. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage Rclone to cloud storage. Confirmed
Impact T1486 Data Encrypted for Impact Partial encryption with an attacker-chosen percentage per file, trading thoroughness for speed. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Royal / BlackSuit intrusion unfolds, section by section.

Social engineering

Phishing with nothing to detonate — Callback phishing removes every artefact a mail security product inspects. The only content is text and a phone number, so detection has to be either linguistic or procedural.

Frequently asked

Is Royal / BlackSuit ransomware still active?
Royal / BlackSuit is tracked as active. The most recent leak-site claim VULONE recorded is dated 19 July 2023.
How many victims has Royal / BlackSuit claimed?
VULONE has recorded 211 leak-site victim claims attributed to Royal / BlackSuit since November 2022, across 20 countries and 14 sectors.
Which industries does Royal / BlackSuit target?
The sectors most often named on the Royal / BlackSuit leak site are Manufacturing, Professional Services, Education.
Which countries are most affected by Royal / BlackSuit?
Most Royal / BlackSuit victims recorded by VULONE are located in United States, Germany, United Kingdom.
Where does VULONE get Royal / BlackSuit victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
#StopRansomware: Royal Ransomware (AA23-061A)CISA / FBI2 Mar 2023

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].