Royal Ransomware Group
A threat profile of Royal, a sophisticated ransomware group targeting critical infrastructure and enterprises with double extortion tactics, custom tooling, and high-pressure ransom negotiations.
SOC status:Duty analyst on shift
Insights
Research, detection engineering notes and plain-English explanations for the questions UK boards, IT managers and security leads actually ask. One substantial piece a week; a short threat brief in between.
Get the fortnightly briefing
A threat profile of Royal, a sophisticated ransomware group targeting critical infrastructure and enterprises with double extortion tactics, custom tooling, and high-pressure ransom negotiations.
A detailed threat profile of Rhysida, a politically ambiguous ransomware group known for public sector targeting, double extortion, and its highly visible dark web leak site.
A threat profile of RansomHouse, a data-focused extortion group known for avoiding encryption and instead exfiltrating and leaking sensitive data to pressure victims into ransom payments.
A threat profile of ProjectRelic, a low-visibility cyber threat group associated with opportunistic attacks on European infrastructure and research networks, operating with uncertain motives and unclear attribution.
A threat profile of Play, a fast-rising ransomware group known for aggressive targeting, double extortion tactics, and cross-platform ransomware with ESXi support.
A threat actor profile of Oilin, a stealthy ransomware group active since 2023, known for targeted attacks, double extortion, and links to experienced cybercriminal operators.
A threat profile of NoName057(16), a pro-Russian hacktivist group known for politically motivated DDoS campaigns targeting European governments, media, and infrastructure during the Ukraine conflict.
A threat profile of NoEscape, a ransomware group known for enterprise targeting, cross-platform payloads, and aggressive extortion tactics involving encryption and data theft.
A threat profile of Mustang Panda, a China-based cyber espionage group known for targeting government entities, NGOs, and think tanks across Europe and Asia using custom malware and socially engineered lures.
A detailed threat profile of MetaEncryptor, a ransomware group using advanced evasion techniques, double extortion, and targeted enterprise-level campaigns.
An in-depth threat profile of the Medusa ransomware group, known for destructive attacks, public leak extortion, and its fast-growing list of international victims.
A threat profile of MalasLocker, a ransomware and data extortion group known for exploiting Zimbra vulnerabilities, targeting email servers, and demanding charitable donations instead of ransom payments.
216 articles · page 15 of 18