How to safeguard against royal ransomware increase

Royal ransomware entered the stage in 2022 and quickly became a nuisance for cyber analysts. Logpoint's research team has investigated the ransomware to uncover how analysts can detect and respond to the developing threat.

Logpoint's investigation revealed that Royal stops services and kills processes to set up a precondition for the ransomware to detonate. Adversaries use scheduled task functionality to facilitate single or repetitive execution of malicious codes, launching the ransomware. The malware enumerates shared resources on the network to encrypt the shared folder and deletes volumes of shadow copies of the drives to prevent recovery from them.

Doron Davidson, VP Logpoint Global Services said, "royal stands out as a ransomware provider because it doesn't have affiliates. The ransomware uses various tactics and techniques to reach its goal, like redirecting users using Google ads, sending phishing emails, and personal interactions based on callback phishing. Despite the many ways to gain initial access, the ransomware deploys in later stages, providing organisations with an opportunity to detect it before it wreaks havoc."

To protect your organisation against Royal ransomware, Logpoint recommends monitoring the infrastructure for stopped services and killed processes, monitoring for the creation of scheduled tasks and related events using the schtasks binary, and monitoring for access to multiple share folders in a short span from the same user and hosts

Doron added, "it's important that organisations have the right cybersecurity resources in place. Leveraging the technological advancements in cybersecurity can accelerate threat detection, investigation, and response. For example, automatic incident detection and response can improve cyber intelligence and reduce cyber risk. Investing in advance in Penetration Testing and similar cybersecurity services will reduce the need to pay for Royal’s Pentesting services."

More News
12 hours ago
Abacus Group appoints new Chief Financial Officer
Abacus Group, a Managed Security Services Provider (MSSP) to alternative investment firms, has appointed Jesse Sanders as Chief Financial Officer (CFO).
13 hours ago
SYNAXON Project Support helping to accelerate partner growth
SYNAXON has launched its Project Support service in the UK, providing partners with a way to deliver complex infrastructure solutions without having to make additional investments in highly skilled technical personnel.
1 day ago
Nureva joins GPA’s Global Partner Program as audio partner
AV integrator, GPA has announced that Nureva has joined the GPA Global Partner Program.
1 day ago
New Head of Marketing appointed at Banner & evo
Karen Child has been appointed Head of Marketing for evo and Banner. With 21 years of experience in B2B marketing and 15 years of experience as a senior marketer at evo, Karen brings a breadth and depth of experience to the role.
1 day ago
Recently acquired PPS adds to team
UK sales agency, Product Promotion Services (PPS) is under new ownership and looking to drive growth through partnership across the UK Business Supplies & Workplace Solutions industry.
1 day ago
Integra celebrates 25 years of Initiative with Antalis
Integra, in conjunction with Antalis and Navigator, is giving members the opportunity to win an all-expenses paid trip to Portugal to celebrate 25 years of own brand, Initiative.
2 days ago
8x8 appoints Kevin Kraus as Chief Financial Officer
8x8, experts in unified communications and contact centre solutions, has announced the appointment of Kevin Kraus as Chief Financial Officer (CFO).
2 days ago
Avocor incorporates Rise Vision digital signage software
Avocor, a provider of collaboration solutions, has announced a strategic partnership with Rise Vision, AUO Display Plus (ADP) subsidiary, and digital signage software experts.
2 days ago
Westcon-Comstor targets 100% renewable electricity globally by 2030
Westcon-Comstor, a technology provider and specialist distributor, has announced a target to meet 100 per cent of its electricity needs worldwide through renewable sources by 2030.
2 days ago
Telehouse Europe announces series of senior appointments
Global colocation provider, Telehouse International Corporation of Europe, has strengthened its operational and customer experience excellence with a restructuring of its operations department and five new appointments, including two new members to the Board of Directors.

Login / Sign up

xxx