The US Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory alert system. Royal Ransomware Group.
The document, which is part of the agency’s #StopRansomware campaign, was released Thursday in collaboration with the FBI and describes the Tactics, Techniques, and Procedures (TTP) along with the Indications of Compromise (IOC) associated with the Royal ransomware variant. I’m here.
The Joint Cybersecurity Advisory (CSA) states that recent malicious activity by attackers using specific malware variants has been observed since September 2022.
“The FBI and CISA believe this variant, which uses its own custom file encryption program, has evolved from previous iterations using Zeon as a loader,” reads Advisory.
After gaining initial network access via phishing, Remote Desktop Protocol (RDP, and other techniques), attackers can disable antivirus software on victim machines and exfiltrate large amounts of data. Observed. They eventually deployed ransomware and encrypted systems.
“Royal attackers demanded ransoms ranging from approximately $1 million to $11 million in Bitcoin,” wrote CISA.
At the same time, authorities revealed that in the observed incident, the royal actor did not include any ransom or payment instructions as part of the ransom note.
“Instead, the note that appears after encryption requires the victim to interact directly with the attacker via a .onion URL (reachable from the Tor browser).”
At the time of writing, CISA wrote that Royal attackers are targeting several critical infrastructure sectors, including manufacturing, telecommunications, education, and healthcare.
like any other #StopRansomware AdvisoryCISA also included a set of recommendations to reduce the likelihood and impact of ransomware incidents.
This includes requiring all accounts using password logins to follow National Institute for Standards and Technology (NIST) standards, keeping all systems up to date, and performing network segmentation wherever possible. It is included.
The CISA advisory comes months after a new threat actor known as DEV-0569 was discovered by Microsoft. Development of new tools Delivers Royal ransomware.