Cyber Alert Issued Against 'Royal' Ransomware Virus That Targets Key Sectors, Seeks Bitcoin Payoffs

"Royal ransomware" virus attacks critical sectors like communications, healthcare, education, and even individuals.

Advertisement
By Press Trust of India | Updated: 4 May 2023 16:51 IST
Highlights
  • Royal ransomware got active sometime around September last year
  • It is targeting multiple crucial infrastructure sectors
  • The ransomware encrypts the files on a victim's system

Royal ransomware was first detected in January 2022

Photo Credit: Pexels

The Indian cyber security agency has issued a warning against the "Royal ransomware" virus that attacks critical sectors like communications, healthcare, education, and even individuals and seeks pay-off in Bitcoins for not leaking personal data in the public domain.

The Indian Computer Emergency Response Team or CERT-In has stated in the latest advisory that this Internet-spread ransomware sneaks in through phishing emails, malicious downloads, abusing RDP (remote desktop protocol), and other forms of social engineering. This ransomware, cyber experts told PTI, was first detected in January 2022 and it got active sometime around September last year even as the US authorities issued advisories against its spread.

“Royal ransomware is targeting multiple crucial infrastructure sectors, including manufacturing, communications, healthcare, education, etc., or individuals. The ransomware encrypts the files on a victim's system and attackers ask for a ransom payment in Bitcoin," the advisory said.

Advertisement

"Attackers also threaten to leak the data in the public domain if denied payment," the advisory said.

Advertisement

The CERT-In is the federal technology arm to combat cyber attacks and guard cyberspace against phishing and hacking assaults and similar online attacks.

The advisory said the "threat actors have followed many tactics to mislead victims into installing the remote access software as a part of callback phishing, where they pretend to be various service providers." The ransomware infects "using a specific approach to encrypt files depending on the size of the content." "It will divide the content into two segments i.e. encrypted and unencrypted. The malware may choose a small amount of data from a large file to encrypt so as to increase the chances of avoiding caution or detection. It adds 532 bytes at the end of the encrypted file for writing randomly generated encrypted key, the file size of the encrypted file, and encryption percentages parameter," the CERT-In said.

Advertisement

The lethality of this virus can be gauged from the fact that before starting encryption of the data it attacks, the ransomware checks the state of targeted files and deletes shadow copies to "prevent recovery" through service. After intruding into the network, the malware tries to make persistent and lateral movements in the network. Even after getting access to the domain controller, the ransomware disables anti-virus protocols. Moreover, the ransomware exfiltrates a large amount of data before encryption, the advisory said.

It has been observed, it said, that 'Royal ransomware' does not share information like the ransom amount, any instructions, etc. on a note like other ransomware, instead it connects with the victim directly via a .onion URL route (dark web browser).

Advertisement

The agency has suggested some counter-measures and Internet hygiene protocols to guard against this ransomware attack and others like it.

Maintain offline backup of data, and regularly maintain backup and restoration as this practice will ensure the organisation will not be severely interrupted and have irretrievable data.

It is also recommended to have all backup data encrypted, immutable (i.e., cannot be altered or deleted) covering the entire organisation's data infrastructure, it said.

The users should enable protected files in the Windows Operating System to prevent unauthorised changes to critical files and they should disable remote desktop connections, employ least-privileged accounts, and limit users who can log in using remote desktop parts from setting an account lockout policy. A number of other best practices have been suggested by the agency, including basic ones like having an updated anti-virus in the computer systems and not clicking on unsolicited emails from unknown links. 


The Vivo X90 Pro has finally made its debut in India, but is the company's flagship smartphone for 2023 equipped with enough upgrades over its predecessor? We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Also seeCryptocurrency Prices across Indian exchanges

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. Vivo X300 Series Launching Today: Everything You Need to Know
  3. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  4. Instagram Lets Some Users 'Tune' Their Reels Algorithm
  5. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  6. Microsoft Azure Outage: What Caused the Issue, How It Was Resolved
  7. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  8. Bitcoin's Price Continues to Fall as Markets React to US Fed Rate Cut
  9. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  10. Airtel Rs. 449 vs Jio Rs. 349 Postpaid Plans: Which One is Better?
  1. OpenAI Lays Groundwork for Juggernaut IPO at Up to $1 Trillion Valuation
  2. Lava Agni 4 Teased to Feature Metal Design and Flat Edges, Could Launch in India Soon
  3. Bitcoin’s Price Continues to Fall as Markets React to US Fed Rate Cut
  4. PS Plus Monthly Games for November Include Stray, EA Sports WRC 24 and Totally Accurate Battle Simulator
  5. Vivo S50 Pro Mini Key Specifications Tipped Ahead of China Launch; Could Debut Globally as Vivo X300 FE
  6. Google Confirms Gemini 3 AI Model Release Timeline: Tipped to Offer Improved Reasoning
  7. Google Brings Major Changes to Play Store Operations in the US After Epic Games Ruling
  8. Grammarly Rebrands to Superhuman, Introduces New Agentic AI Assistant
  9. Microsoft Azure Services Restored After Global Outage: What Caused the Issue, How It Was Resolved
  10. Microsoft CEO Satya Nadella Will Reportedly Visit India in December; Could Address Two AI Conferences
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.