Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Case Study: Credit Union Boosts Threat Prevention & Detection with Cymulate
Learn More
New Research: Cymulate Research Labs Discovers Token Validation Flaw
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

Royal Ransomware Uses Callback Phishing To Carry Out Attacks

December 22, 2022

The group behind the Royal ransomware family was discovered targeting entities across multiple countries with most infections occurring in the United States, Brazil, and Mexico.
Phishing emails along with social engineering were used to convince victims to install remote access software allowing the threat actor to gain control of the system.
Various malware and open-source tools were used during the attacks including QakBot, Cobalt Strike, PCHunter, PowerTool, GMER, and Process Hacker.