🇷🇺Royal
🇷🇺 Royal is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 7 detection use cases to this actor across 12 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-30 to 2026-07-30.
crit 1
7Use cases
1Articles
12Techniques
5IOCs
Known aliases
Royal RansomwareDEV-0569
Top techniques
All other tracked techniques
Detection use cases (7)
Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard PowerShell encoded / obfuscated command Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Network connections to article IPs / domainsThreat-intel articles (1)
Tracked indicators
Domains (5)
corp-connect.top scan-security.top sequrityupdate.top supportsoft.top system-connect.top