Frequently Asked Questions

Product Information & Threat Coverage

What is Cymulate and how does it help organizations defend against threats like Royal ransomware?

Cymulate is an AI-powered cyber defense engineering platform that enables organizations to prove, prioritize, and improve their cyber defenses against real threats and exposures. It continuously validates security controls, simulates real-world attacks—including phishing, ransomware, and malware—and provides actionable insights to reduce risk. Cymulate's platform can help organizations assess their exposure to tactics used by groups like Royal ransomware, such as callback phishing and remote access tool deployment. Note: Cymulate validates exposures and provides remediation guidance but does not directly block attacks. Learn more.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios, such as those used by Royal ransomware (e.g., callback phishing and remote access tool deployment), to ensure comprehensive security validation. Note: Cymulate does not prevent attacks but helps organizations identify and remediate exposures. Source.

How does Cymulate help organizations assess their exposure to phishing and social engineering attacks?

Cymulate simulates phishing and social engineering attacks, including callback phishing tactics used by threat actors like Royal ransomware. By running these simulations, organizations can identify weaknesses in user awareness, email gateway configurations, and endpoint protections. The platform provides actionable remediation guidance to address identified gaps. Note: Effectiveness depends on regular testing and user engagement; Cymulate does not provide user training modules. Source.

What tools and techniques used by Royal ransomware can Cymulate simulate?

Cymulate can simulate the use of malware and open-source tools commonly leveraged by threat actors, including QakBot, Cobalt Strike, and techniques involving remote access software. This allows organizations to validate their defenses against the same tactics observed in Royal ransomware campaigns. Note: Cymulate does not deploy actual malware but uses safe simulations to test controls. Source.

Features & Capabilities

What is Cymulate's immediate threats module and how does it benefit users?

The immediate threats module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The module provides assessment and guidance, not direct threat blocking. Source.

How does Cymulate's exposure validation feature work?

Cymulate's exposure validation automates continuous testing to validate threats, security controls, and exposures. It identifies what is exploitable in your environment and drives exposure mitigation through actionable insights. This helps organizations prioritize remediation efforts and reduce risk faster. Note: Effectiveness depends on regular use and integration with existing workflows. Source.

Use Cases & Benefits

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, Vulnerability Management Teams, GRC/Compliance Teams, and IT/Infrastructure/Cloud Teams. It is suitable for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Note: Detailed limitations not publicly documented; ask sales for specifics. Source.

What business impact can customers expect from using Cymulate?

Organizations using Cymulate report an average 30% increase in threat prevention, 90% improvement in threat detection, 52% reduction in critical exposures, and a 60% boost in operational efficiency. Threat validation is 40X faster than manual methods, and customers have achieved measurable ROI, such as an 81% reduction in cyber risk within four months (see Hertz Israel case study). Note: Results may vary based on implementation and organizational maturity. Source.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, operating in an agentless mode that eliminates the need for additional hardware or complex configurations. Users can start running simulations almost immediately, with only basic infrastructure and internet connectivity required. Customers consistently praise its intuitive dashboard and ease of use. Note: Effectiveness depends on ongoing engagement and regular testing. Source.

Security & Compliance

What security and compliance certifications does Cymulate have?

Cymulate holds SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These attest to Cymulate's compliance with security, privacy, and cloud service standards. Note: Certification scope and coverage may vary; consult Cymulate for details. Source.

What product security features does Cymulate offer?

Cymulate offers 2-Factor Authentication (2FA), Single Sign-On (SSO), role-based access controls (RBAC), and data encryption in transit and at rest. The platform also supports GDPR compliance through secure development practices and oversight by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Note: Feature availability may depend on subscription tier; confirm with Cymulate for specifics. Source.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model, with fees determined by the package selected, number of assets covered, and chosen scenarios and features. Pricing is customized to fit each organization's needs. For a detailed quote, schedule a demo with Cymulate's team. Note: Exact pricing is not publicly listed; contact Cymulate for specifics. Source.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate provides AI-driven, actionable remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. Cymulate is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may offer different integrations and reporting features. Choose Cymulate for rapid, AI-powered validation and remediation; choose AttackIQ if you require features not listed here. Note: Cymulate's platform may not cover all integrations available in AttackIQ. Source.

How does Cymulate compare to Mandiant Security Validation?

Cymulate offers AI-powered automation, rapid deployment, and a comprehensive attack library with daily updates. It is recognized as a grid leader in exposure management. Mandiant Security Validation may provide different integration options and reporting capabilities. Choose Cymulate for ease of use and continuous innovation; choose Mandiant if you need features not covered by Cymulate. Note: Cymulate may not support all integrations available in Mandiant. Source.

How does Cymulate compare to Pentera?

Cymulate combines breach simulation, automated red teaming, and deep security control integrations. It allows custom attack chains from a library of over 100,000 actions and delivers daily threat updates. Pentera may offer different automation or reporting features. Choose Cymulate for continuous, customizable assessments; choose Pentera if you need features not listed here. Note: Cymulate may not replicate all Pentera capabilities. Source.

Technical Documentation & Resources

Where can I find technical documentation and resources about Cymulate?

Cymulate provides a resource hub with industry reports, whitepapers, case studies, and technical guides. Notable resources include the Threat Studio data sheet and the Detection Engineering Automation Guide. Access these at the resource hub. Note: Some resources may require registration or contact with Cymulate.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Royal Ransomware Uses Callback Phishing To Carry Out Attacks

December 22, 2022

The group behind the Royal ransomware family was discovered targeting entities across multiple countries with most infections occurring in the United States, Brazil, and Mexico.
Phishing emails along with social engineering were used to convince victims to install remote access software allowing the threat actor to gain control of the system.
Various malware and open-source tools were used during the attacks including QakBot, Cobalt Strike, PCHunter, PowerTool, GMER, and Process Hacker.