Software · OAK-S28 · ransomware
OAK-S28 — Royal / BlackSuit ransomware
Description
Royal / BlackSuit is the ransomware encryptor codebase and brand maintained by a Conti-successor operator cohort from September 2022 onward, with the Royal-to-BlackSuit rebrand event of June 2023 representing one of the cleanest documented cases of brand-toxicity-management rebrand as continuity-disruption tooling in the modern RaaS sector. The encryptor was forked directly from Conti's Zeon variant — a short-lived Conti-cohort branch from late 2021 / early 2022 — with the fork providing direct codebase continuity to the Conti-cohort dispersal network described in OAK-S26. From a defender perspective the family occupies the same encryption-and-extortion functional role that Conti occupied 2020–2022, with a particular targeting profile concentrated on U.S. healthcare, education, and critical-infrastructure sectors that mirrors the Conti operating-model targeting profile.
The encryptor's distinguishing technical features include partial-encryption mode (a Conti-Zeon-inherited speed-versus-stealth tradeoff), a callback-phishing initial-access vector that became a defining Royal-affiliate fingerprint (operators send fake subscription-renewal emails with a phone number; victim calls the number; operator under a fabricated technical-support persona walks the victim through installing remote-access tooling that establishes the operator's foothold), and a dedicated VMware ESXi variant for hypervisor-level deployments. The callback-phishing vector is structurally distinct from the Qakbot-and-Cobalt-Strike intrusion chains that defined Black Basta's tradecraft, and is the principal behavioural signature that distinguishes Royal/BlackSuit-affiliate intrusions from other Conti-successor-brand-network intrusions at the pre-encryption layer.
The June 2023 Royal-to-BlackSuit rebrand event is widely read by Mandiant, Microsoft, and CISA as a brand-toxicity-management response to the November 2022 CISA #StopRansomware advisory campaign that named Royal explicitly and to CISA AA23-061A which expanded the U.S.-government-advisory surface against the brand. The rebrand involved leak-site domain rotation, encryptor build identification rotation (the BlackSuit builds carry version-string and ransom-note variants distinguishing them from Royal builds), and brand-naming rotation in operator-side affiliate communications, but did not involve operator-cohort dispersal, encryptor-codebase rewrite, or affiliate-roster reorganisation; the wallet-cluster persistence (OAK-T8.001) and tradecraft-fingerprint persistence are the principal forensic signatures that allowed industry and U.S. government attribution work to identify the rebrand as continuity rather than dispersal. The OFAC December 2023 designation surface and the August 2024 CISA AA24-228A advisory update reflect the U.S. government's recognition that the brand-rotation was operationally a continuity event.
The brand's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding the Conti-successor-brand-network laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader Conti-successor-brand-network laundering pattern documented for Black Basta. The November 2023 Dallas Cowboys / Dallas city-government incident is the brand's highest-profile single deployment in the public record and a canonical case of Royal/BlackSuit-affiliate targeting of U.S. municipal-and-civic infrastructure.
Observed examples
- Dallas City Government incident (May 2023, multi-week municipal-services disruption). Royal-branded deployment against the City of Dallas's IT infrastructure disrupted municipal services across police, courts, utilities, and emergency-response systems for weeks; the city refused ransom payment; data was subsequently published on the Royal leak site. The incident is widely cited as a canonical case of Royal/BlackSuit-affiliate targeting of U.S. municipal-and-civic infrastructure and is named in the August 2024 CISA AA24-228A advisory update as part of the brand's documented victim-pattern. Confirmed-grade attribution per the City of Dallas's own incident-disclosure and CISA advisory.
- CISA AA23-061A and AA24-228A campaign cohort (through 2024). The original CISA AA23-061A (March 2023, on Royal) and the August 2024 update AA24-228A (rebadged for BlackSuit and documenting the Royal-to-BlackSuit continuity reading) collectively document over 350 named-and-unnamed Royal/BlackSuit victim organisations across U.S. critical-infrastructure sectors with healthcare, education, manufacturing, and government / municipal verticals prominently called out. Confirmed-grade aggregate.
- U.S. healthcare and education sector targeting cohort (2023–2024). Multiple ransomware incidents against U.S. healthcare systems and school districts attributed to Royal/BlackSuit through industry-forensic reporting and CISA advisory work; the targeting profile mirrors the Conti operating-model targeting profile and is distinct in vertical concentration from the broader cross-sector Black Basta targeting profile. Confirmed-grade aggregate per CISA advisories.
- OFAC December 2023 designation surface (
[ofac2023royalblacksuit]). OFAC press release providing institutional confirmed-grade attribution to the Royal/BlackSuit operator cluster; structurally parallel to the OFAC institutional attribution architecture used for the broader Russian-speaking-RaaS-cohort umbrella; provides the SDN-screening surface for affiliate-attributable wallet addresses without naming individual operators. - OAK on-chain example surface. No OAK
examples/entry exists for Royal/BlackSuit-binary specifically as of v0.1; the Royal/BlackSuit-to-Garantex chain documented in industry-forensic reporting is the strongest candidate for a future OAK example entry showing the OAK-S28-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti-to-Garantex and Black-Basta-to-Garantex chains.
Detection / attribution signals
Defenders should treat Royal/BlackSuit detection at the host-layer + on-chain-layer joint level with the callback-phishing initial-access vector as the most-distinctive pre-encryption tradecraft fingerprint:
- Host-layer process-tree fingerprints — characteristic file-extension changes (
.royalextension on Royal-era encrypted files;.blacksuiton BlackSuit-era files); ransom-note filenames (README.txtper-folder); C++-Windows-binary signature with direct Conti-Zeon-fork lineage documented by Mandiant and Microsoft; partial-encryption mode signature inherited from Conti-Zeon; ESXi-variant invokes the standardesxcliVM-shutdown sequence shared across Conti-successor brands. - Pre-encryption tradecraft (the distinguishing Royal/BlackSuit fingerprint) — callback-phishing initial-access vector is the principal behavioural signature: fabricated subscription-renewal / customer-support emails with operator-controlled phone numbers, victim-side phone calls handled by operator under fabricated technical-support persona, walk-through installation of remote-access tooling (AnyDesk, Atera, ScreenConnect, or similar) that establishes the operator's foothold without requiring exploit-payload delivery. This vector is documented in CISA AA23-061A and in continuous industry-forensic reporting from Microsoft and Sophos as a defining Royal/BlackSuit-affiliate tradecraft fingerprint distinguishing it from Qakbot-loader-chain Black-Basta-affiliate tradecraft.
- Network-layer telemetry — Cobalt Strike post-exploitation deployment after callback-phishing-established foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns.
- On-chain-layer signatures (the OAK-relevant signal) — Royal-to-BlackSuit wallet-cluster persistence (OAK-T8.001) is the principal forensic signature for the brand-rotation-as-continuity reading; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; common-funder cluster reuse with broader Conti-successor-brand-network affiliate clusters is the cross-cluster signature.
- CTI vendor coverage — Mandiant (Royal/BlackSuit cluster tracking and the Conti-Zeon-fork lineage attribution work), Microsoft Threat Intelligence (DEV-0569 / Storm-0569 naming and continuous tracking), Sophos (sustained "State of Ransomware" reporting and per-incident write-ups), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained Royal/BlackSuit reporting), Coveware (incident-response-side payment and negotiation-pattern reporting), Chainalysis and TRM Labs (on-chain operator-cohort-continuity tracking across the brand-rotation).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA23-061A and AA24-228A and live CTI-vendor feeds named above.
Citations
[cisaaa23061a]— CISA / FBI joint advisory AA23-061A on Royal ransomware, March 2023. (Already cited in OAK-S24 BlackCat / ALPHV — note: the same advisory ID is shared between Royal and ALPHV documents; check the citations.bib entry to disambiguate.)[cisaaa24228a]— CISA / FBI joint advisory AA24-228A on BlackSuit ransomware (Royal rebrand update), August 2024. (NEW citation — see summary.)[ofac2023royalblacksuit]— Treasury OFAC designation press release on the Royal/BlackSuit operator cluster, December 2023. (NEW citation — see summary.)[mandiantroyalblacksuit2023]— Mandiant Royal-to-BlackSuit rebrand attribution and Conti-Zeon-fork lineage analysis. (NEW citation — see summary.)[microsoftstorm0569]— Microsoft Threat Intelligence DEV-0569 / Storm-0569 / Royal-BlackSuit analysis. (NEW citation — see summary.)[sophosroyalblacksuit2023]— Sophos Royal/BlackSuit tradecraft and callback-phishing-vector analysis. (NEW citation — see summary.)[trendmicroroyalblacksuit2023]— Trend Micro Royal/BlackSuit version-by-version analysis. (NEW citation — see summary.)[chainalysisroyalblacksuit2024]— Chainalysis Royal/BlackSuit-attributable ransom-payment-volume tracking and brand-rotation wallet-cluster analysis. (NEW citation — see summary.)[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; cross-family context for the Royal/BlackSuit volume distribution.
Discussion
On lineage as the central framing. OAK-S28's principal value as a Software entry is as the cleanest documented case of direct Conti-codebase fork as a successor-brand encryptor in the Conti-cohort dispersal network (see OAK-S26 Discussion). Where Black Basta (OAK-S27) is a Conti-codebase-derivative-with-substantive-rewrites lineage, Royal/BlackSuit is a direct Conti-Zeon-fork lineage; the architectural differences between the two cases provide a useful comparative reference for understanding the spectrum of codebase-reuse-versus-rewrite tactics available to a successor-brand operator cohort. The June 2023 Royal-to-BlackSuit rebrand event is the canonical worked example of brand-toxicity-management rebrand as continuity-disruption tooling, structurally parallel to but distinct from the Conti-cohort dispersal-into-multiple-brands pattern.
On predecessors. Royal's direct predecessor at the encryptor-codebase level is Conti's Zeon variant (a short-lived Conti-cohort branch from late 2021 / early 2022); the operator-cohort-level predecessor is the broader Conti / Wizard Spider cohort (2020–2022, OAK-S26). BlackSuit's direct predecessor is Royal at both the codebase and the operator-cohort levels — the rebrand is continuity rather than succession.
On the brand-rotation pattern. The Royal-to-BlackSuit rebrand of June 2023 sits within a broader sector pattern of brand-rotation-as-continuity-tooling that includes also DarkSide → BlackMatter (2021), and Conti's ongoing post-2022 sub-brand experimentation (Quantum, Zeon, Karakurt). The pattern is structurally distinct from both codebase-version-rotation (LockBit 1.0 → 2.0 → 3.0 → Green) and cohort-dispersal-into-multiple-brands (Conti → Black Basta + Royal/BlackSuit + Karakurt + BlackByte + Quantum/Zeon); from a defender perspective the three patterns require structurally different attribution-graph maintenance approaches and produce structurally different downstream affiliate-cohort-tracking signatures.
On the OAK Software-vs-Group split for a brand-rotation case. OAK-S28 (this entry) is the Royal/BlackSuit encryptor codebase across both brand identities; the conjoined naming reflects the continuity reading at the codebase level. There is no current OAK-G entry for the Royal/BlackSuit operator cluster as of v0.1; future OAK-G entries (in the v0.x Group catalog expansion) will likely include a separate Group entry for the cluster with reference back to OAK-S28 as the encryptor-codebase anchor. The OFAC December 2023 designation surface provides institutional confirmed-grade attribution at the cluster level; the absence of named-defendant-indictment as of v0.1 distinguishes this attribution architecture from the LockBit / Khoroshev architecture (named-defendant indictment) and aligns it with the Garantex / Conti / broader-Russian-speaking-RaaS-cohort architecture (institutional cluster designation without named individuals).
On takedown / disruption history. Royal/BlackSuit has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action; the OFAC December 2023 designation surface and the CISA advisory campaign provide institutional pressure but not operational disruption. The brand's continued operations through 2024 and into 2025 reflect the structural challenge of disrupting a Russian-jurisdiction-based operator cohort without the equivalent of the Khoroshev-naming and SDN-architecture surface that drove the LockBit collapse.