Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

US HHS warns healthcare orgs of Royal Ransomware attacksSecurity Affairs

Altszn.com by Altszn.com
December 10, 2022
in Dark Web
0
US HHS warns healthcare orgs of Royal Ransomware attacksSecurity Affairs
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


The US Department of Health and Human Services (HHS) warns healthcare organizations of Royal ransomware attacks.

The human-operated Royal ransomware first appeared on the threat landscape in September 2022, it has demanded ransoms up to millions of dollars.

The Health and Human Services (HHS) is aware of attacks against the Healthcare and Public Healthcare (HPH) sector.

Unlike other ransomware operations, Royal doesn’t offer Ransomware-as-a-Service, it appears to be a private group without a network of affiliates.

“Royal is a human-operated ransomware that was first observed in 2022 and has increased in appearance. It has demanded ransoms up to millions of dollars. Since its appearance, HC3 is aware of attacks against the Healthcare and Public Healthcare (HPH) sector. Due to the historical nature of ransomware victimizing the healthcare community, Royal should be considered a threat to the HPH sector.” reads the report published by HHS.

Once compromised a victim’s network, the threat actors deploy the post-exploitation tool Cobalt Strike to maintain persistence and perform lateral movements.

Originally, the ransomware operation used BlackCat’s encryptor, but later it started using Zeon. The ransom notes (README.TXT) include a link to the victim’s private negotiation page. Starting from September 2022, the note was changed to Royal.

The Royal ransomware is written in C++, it infected Windows systems and deletes all Volume Shadow Copies to prevent data recovery. The ransomware encrypts the network shares, that are found on the local network and the local drives, with the AES algorithm.

The Royal ransomware can either fully or partially encrypt a file depending on its size and the ‘-ep’
parameter. The malware changes the extension of the encrypted files to ‘.royal’.

In November, researchers from the Microsoft Security Threat Intelligence team warned that a threat actor, tracked as DEV-0569, is using Google Ads to distribute various payloads, including the recently discovered Royal ransomware. The DEV-0569 group carries out malvertising campaigns to spread links to a signed malware downloader posing as software installers or fake updates embedded in spam messages, fake forum pages, and blog comments.

HC3 added that threat actors continue to use multiple attack vectors associated with this ransomware, including phishing, Remote Desktop Protocol (RDP) compromises and credential abuse, compromises of exploited vulnerabilities, such as VPN servers, and compromises in other known vulnerabilities” HHS notes.

“Royal is a newer ransomware, and less is known about the malware and operators than others. Additionally, on previous Royal compromises that have impacted the HPH sector, they have primarily appeared to be focused on organizations in the United States. In each of these events, the threat actor has claimed to have published 100% of the data that was allegedly extracted from the victim.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)











Share On








Read More: news.google.com

Tags: affairsattacksSecuritydark webDarknetHealthcareHHSorgsransomwareRoyalWarns
ADVERTISEMENT

Recent

Puffverse Joins Gate.io Launchpad, Expanding The Frontiers Of 3D Metaverse GameFi

Puffverse Joins Gate.io Launchpad, Expanding The Frontiers Of 3D Metaverse GameFi

May 12, 2025
Demand for Censorship-Resistant ‘Dark Stablecoins’ May Rise Amid Regulatory Crackdown

Demand for Censorship-Resistant ‘Dark Stablecoins’ May Rise Amid Regulatory Crackdown

May 12, 2025
MEXC Lists 160 Tokens in April, Delivers Over 800% Returns Across Top Gainers

MEXC Lists 160 Tokens in April, Delivers Over 800% Returns Across Top Gainers

May 12, 2025

Categories

  • Bitcoin (4,897)
  • Blockchain (11,517)
  • Crypto (9,458)
  • Dark Web (554)
  • DeFi (8,444)
  • Ethereum (4,964)
  • Metaverse (7,662)
  • Monero (292)
  • NFT (1,549)
  • Solana (5,072)
  • Web3 (20,867)
  • Zcash (507)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Puffverse Joins Gate.io Launchpad, Expanding The Frontiers Of 3D Metaverse GameFi

    Puffverse Joins Gate.io Launchpad, Expanding The Frontiers Of 3D Metaverse GameFi

    May 12, 2025
    Demand for Censorship-Resistant ‘Dark Stablecoins’ May Rise Amid Regulatory Crackdown

    Demand for Censorship-Resistant ‘Dark Stablecoins’ May Rise Amid Regulatory Crackdown

    May 12, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 102,984.00
    • ethereumEthereum (ETH) $ 2,504.76
    • xrpXRP (XRP) $ 2.60
    • tetherTether (USDT) $ 1.00
    • bnbBNB (BNB) $ 669.20
    • solanaSolana (SOL) $ 176.24
    • usd-coinUSDC (USDC) $ 0.999976
    • dogecoinDogecoin (DOGE) $ 0.235988
    • cardanoCardano (ADA) $ 0.829460
    • tronTRON (TRX) $ 0.274733
    • staked-etherLido Staked Ether (STETH) $ 2,500.61
    • suiSui (SUI) $ 3.99
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,920.00
    • chainlinkChainlink (LINK) $ 16.95
    • avalanche-2Avalanche (AVAX) $ 25.06
    • wrapped-stethWrapped stETH (WSTETH) $ 3,007.89
    • stellarStellar (XLM) $ 0.322469
    • shiba-inuShiba Inu (SHIB) $ 0.000016
    • hedera-hashgraphHedera (HBAR) $ 0.222015
    • the-open-networkToncoin (TON) $ 3.45
    • pi-networkPi Network (PI) $ 1.15
    • bitcoin-cashBitcoin Cash (BCH) $ 413.67
    • hyperliquidHyperliquid (HYPE) $ 24.67
    • polkadotPolkadot (DOT) $ 5.17
    • leo-tokenLEO Token (LEO) $ 8.49
    • litecoinLitecoin (LTC) $ 101.76
    • usdsUSDS (USDS) $ 0.999953
    • wethWETH (WETH) $ 2,502.85
    • moneroMonero (XMR) $ 337.26
    • pepePepe (PEPE) $ 0.000014
    • wrapped-eethWrapped eETH (WEETH) $ 2,671.27
    • bitget-tokenBitget Token (BGB) $ 4.76
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998613
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,977.00
    • whitebitWhiteBIT Coin (WBT) $ 30.25
    • uniswapUniswap (UNI) $ 6.97
    • bittensorBittensor (TAO) $ 458.55
    • nearNEAR Protocol (NEAR) $ 3.18
    • aptosAptos (APT) $ 5.96
    • daiDai (DAI) $ 0.999555
    • aaveAave (AAVE) $ 222.39
    • ondo-financeOndo (ONDO) $ 1.04
    • okbOKB (OKB) $ 54.46
    • kaspaKaspa (KAS) $ 0.120168
    • internet-computerInternet Computer (ICP) $ 5.87
    • ethereum-classicEthereum Classic (ETC) $ 19.94
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.101763
    • tokenize-xchangeTokenize Xchange (TKX) $ 34.64
    • bitcoinBitcoin (BTC) $ 102,984.00
    • ethereumEthereum (ETH) $ 2,504.76
    • xrpXRP (XRP) $ 2.60
    • tetherTether (USDT) $ 1.00
    • bnbBNB (BNB) $ 669.20
    • solanaSolana (SOL) $ 176.24
    • usd-coinUSDC (USDC) $ 0.999976
    • dogecoinDogecoin (DOGE) $ 0.235988
    • cardanoCardano (ADA) $ 0.829460
    • tronTRON (TRX) $ 0.274733
    • staked-etherLido Staked Ether (STETH) $ 2,500.61
    • suiSui (SUI) $ 3.99
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,920.00
    • chainlinkChainlink (LINK) $ 16.95
    • avalanche-2Avalanche (AVAX) $ 25.06
    • wrapped-stethWrapped stETH (WSTETH) $ 3,007.89
    • stellarStellar (XLM) $ 0.322469
    • shiba-inuShiba Inu (SHIB) $ 0.000016
    • hedera-hashgraphHedera (HBAR) $ 0.222015
    • the-open-networkToncoin (TON) $ 3.45
    • pi-networkPi Network (PI) $ 1.15
    • bitcoin-cashBitcoin Cash (BCH) $ 413.67
    • hyperliquidHyperliquid (HYPE) $ 24.67
    • polkadotPolkadot (DOT) $ 5.17
    • leo-tokenLEO Token (LEO) $ 8.49
    • litecoinLitecoin (LTC) $ 101.76
    • usdsUSDS (USDS) $ 0.999953
    • wethWETH (WETH) $ 2,502.85
    • moneroMonero (XMR) $ 337.26
    • pepePepe (PEPE) $ 0.000014
    • wrapped-eethWrapped eETH (WEETH) $ 2,671.27
    • bitget-tokenBitget Token (BGB) $ 4.76
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998613
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,977.00
    • whitebitWhiteBIT Coin (WBT) $ 30.25
    • uniswapUniswap (UNI) $ 6.97
    • bittensorBittensor (TAO) $ 458.55
    • nearNEAR Protocol (NEAR) $ 3.18
    • aptosAptos (APT) $ 5.96
    • daiDai (DAI) $ 0.999555
    • aaveAave (AAVE) $ 222.39
    • ondo-financeOndo (ONDO) $ 1.04
    • okbOKB (OKB) $ 54.46
    • kaspaKaspa (KAS) $ 0.120168
    • internet-computerInternet Computer (ICP) $ 5.87
    • ethereum-classicEthereum Classic (ETC) $ 19.94
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.101763
    • tokenize-xchangeTokenize Xchange (TKX) $ 34.64