Uptime Hamster: 10d 18h 22mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza royal

royal

2 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-07-09
Aliases: Royal Hacking Group, Zeon, Hellsing, Cycldek, Conimes Team, China1937CN Team, otros mencionados en fuentes OSINT verificadas, apt 27, apt27, bronze union, cycldek, emissary panda, goblin panda, group 35, iron tiger, luckymouse, temp, Ke3chang
Ver en IntelTracker → APTTrail →
Royal is a financially motivated cybercriminal ransomware organization that emerged in early 2022, initially operating under the name Zeon before rebranding to Royal in September 2022. Assessed with high confidence to be of Russian origin, the group is composed of experienced individuals, many believed to be former members of the Conti ransomware operation. Unlike many contemporary ransomware groups, Royal operates as a closed, private team rather than utilizing a Ransomware-as-a-Service (RaaS) model with affiliates, which contributes to its consistent tradecraft and tighter operational security. This structure also allowed the group to adapt quickly to new tactics. Royal is known for its aggressive targeting, high ransom demands, and its unique approach to encryption, employing partial encryption to evade detection and accelerate the process. The group ceased operations under the Royal name around June 2023, subsequently rebranding to BlackSuit.

Aliases del actor

Royal Hacking GroupZeonHellsingCycldekConimes TeamChina1937CN Teamotros mencionados en fuentes OSINT verificadasapt 27apt27bronze unioncycldekemissary pandagoblin pandagroup 35iron tigerluckymousetempKe3changMiragePlayful DragonRoyal APTVixen Pandaapt15DEV-0569ContiQuantumBlack ByteDiavolBlack BastaRyuk (como FIN12)

Actores similares

APT27 (Emissary Panda)actor · 1Temper Pandaapt · 0GOBLIN PANDAapt · 0Union Pandaapt · 0Mustang Pandaapt · 1Putter Pandaapt · 1Stone Pandaapt · 0Vicious Pandaapt · 0Pitty Pandaapt · 0Hurricane Pandaapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionuproyal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid.onionroyal
DLS / onionuproyal4ezp7xrbakkus3oofjw6gszrohpodmdnfbe5e4w3og5sm7vb3qd.onionroyal
DLS / onionup72u5vd67xdff354hhge6wjuvsixxwo3c6bvrdlqstgmjfptpbzwrsmad.onionroyal
DLS / onionupk6s24pz55gtvtzzpg4riv7zb74vts425bl42zrpmice5ud3a65itj6ad.onionroyal
DLS / onionupyef4xoqj2jq554rqetf2ikmpdtewdlbnx5xrtjtjqaotvfw77ipb6pad.onionroyal
DLS / leak siteunknownwww.breachsense.comroyalmtc.ca - Conti Data Breach
DLS / leak siteunknowngetbootstrap.comroyalmtc.ca - Conti Data Breach
Repositoriounknowngithub.comroyalmtc.ca - Conti Data Breach
Repositoriounknowngithub.comroyalmtc.ca - Conti Data Breach
DLS / leak sitedownwww.cbc.caRansomware News: Mount Royal University responding to cyber attack, website down | CBC News
DLS / leak siteunknownwww.tvlux.beRansomware News: L'Athénée Royal d'Izel victime d'un piratage informatique
Tecnicas MITRE
T1021, T1055, T1068, T1027, T1486, T1490
CVEs relacionadas
CVE-2023-36036, CVE-2023-36033, CVE-2023-3284, CVE-2023-23583, CVE-2023-20592
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Russia (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaBelgiumBrazilCanadaSwitzerlandChinaCosta RicaGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation

Victimas (1)

Royal (Russia)9 Jul 2026
Reference Russia
Que es Royal es un actor APT (Advanced Persistent Threat) asociado a Rusia, conocido por su actividad de ciberataque en múltiples sectores. Se identif…