OAK — OnChain Attack Knowledge

Software · OAK-S28 · ransomware

OAK-S28 — Royal / BlackSuit ransomware

Type
ransomware
Aliases
Royal (the operator-side and leak-site-branded name from the brand's September 2022 debut through mid-2023); BlackSuit (the rebranded operator-and-encryptor identity from June 2023 onward); industry-side cross-attribution labels include DEV-0569 / Storm-0569 (early Microsoft Threat Intelligence naming for the operator cluster prior to the BlackSuit rebrand), the informal "Royal/BlackSuit" conjoined naming used in CISA AA23-061A and the November 2023 / August 2024 update advisories, and the "Zeon" naming used in earlier 2022 Conti-successor-brand reporting that documented the encryptor's lineage to Conti's Zeon variant. The brand-rotation event from Royal to BlackSuit in mid-2023 is widely read by Mandiant, Microsoft, and CISA as a brand-toxicity-management response to attribution-graph tracking — an attempt to shed the Royal-name accumulation of attributable victim count and U.S.-government advisory surface (CISA AA23-061A specifically) and continue operations under a fresh brand identity. The encryptor-codebase, leak-site infrastructure, and operator-cohort were continuous across the rebrand at the wallet-cluster and tradecraft-fingerprint levels.
Active
active — BlackSuit-branded operations continued through 2024 and into 2025 with the OFAC December 2023 designation surface providing institutional pressure but not operational disruption; the brand had not been formally sunset as of v0.1 and remains an active-detection target. Brand-attributable extortion volume placed BlackSuit in the top-five ransomware brands by leak-site postings through 2024 per Recorded Future / Coveware tracking.
First observed
2022-09 (Royal-branded operations debuted September 2022; the Royal encryptor was forked from Conti's Zeon variant per Mandiant and Microsoft attribution work, providing direct codebase continuity to the Conti-cohort dispersal network); brand rebrand to BlackSuit in June 2023.
Used by Groups
defunct-operator (no current OAK-G entry). Tracked under "Royal/BlackSuit operator" cluster classification with Conti-cohort operator continuity documented at the personnel level by Mandiant and Microsoft; the brand's senior leadership had not been named-defendant-indicted as of v0.1 and the operator cohort is therefore tracked at cluster-level rather than as a named-individual operator. The OFAC December 2023 sanctions designation surface ([ofac2023royalblacksuit]) provides institutional confirmed-grade attribution to the cluster without naming individuals, structurally parallel to the OFAC institutional attribution architecture used for the Russian-speaking-RaaS-cohort umbrella (Evil Corp 2019, Garantex 2022, Sungatov / Kondratyev 2024). Future OAK-G entries (in the v0.x Group catalog expansion) will likely include a separate Group entry for the Royal/BlackSuit operator cluster with reference back to OAK-S28 as the encryptor-codebase anchor.
Host platforms
Windows (primary, all enterprise-server variants); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in early 2023, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks). The Windows codebase's lineage to Conti's Zeon variant is the cleanest documented case of direct Conti-codebase fork as a successor-brand encryptor — Royal forked from Zeon rather than being a clean rewrite, distinguishing it from the Black Basta lineage where the Conti v3 codebase was substantively rewritten before redeployment.
Observed Techniques
OAK-T7.001 (mixer-routed-hop, the dominant Royal/BlackSuit-affiliate ransom-laundering route 2022–2023 with Sinbad pre-takedown the principal venue per Chainalysis tracking); OAK-T7.002 (CEX deposit-address layering, the post-2023 default with Garantex (OAK-G03) named in industry-forensic reporting as a recurring Royal/BlackSuit-affiliate off-ramp consistent with the broader Conti-successor-brand-network laundering pattern); OAK-T8.001 (common-funder cluster reuse, the load-bearing Technique for Royal-to-BlackSuit operator-cohort-continuity tracking across the rebrand event — wallet-cluster persistence is the principal forensic signature that allowed Mandiant, Microsoft, and CISA to identify the brand-rotation as continuity rather than dispersal).

Description

Royal / BlackSuit is the ransomware encryptor codebase and brand maintained by a Conti-successor operator cohort from September 2022 onward, with the Royal-to-BlackSuit rebrand event of June 2023 representing one of the cleanest documented cases of brand-toxicity-management rebrand as continuity-disruption tooling in the modern RaaS sector. The encryptor was forked directly from Conti's Zeon variant — a short-lived Conti-cohort branch from late 2021 / early 2022 — with the fork providing direct codebase continuity to the Conti-cohort dispersal network described in OAK-S26. From a defender perspective the family occupies the same encryption-and-extortion functional role that Conti occupied 2020–2022, with a particular targeting profile concentrated on U.S. healthcare, education, and critical-infrastructure sectors that mirrors the Conti operating-model targeting profile.

The encryptor's distinguishing technical features include partial-encryption mode (a Conti-Zeon-inherited speed-versus-stealth tradeoff), a callback-phishing initial-access vector that became a defining Royal-affiliate fingerprint (operators send fake subscription-renewal emails with a phone number; victim calls the number; operator under a fabricated technical-support persona walks the victim through installing remote-access tooling that establishes the operator's foothold), and a dedicated VMware ESXi variant for hypervisor-level deployments. The callback-phishing vector is structurally distinct from the Qakbot-and-Cobalt-Strike intrusion chains that defined Black Basta's tradecraft, and is the principal behavioural signature that distinguishes Royal/BlackSuit-affiliate intrusions from other Conti-successor-brand-network intrusions at the pre-encryption layer.

The June 2023 Royal-to-BlackSuit rebrand event is widely read by Mandiant, Microsoft, and CISA as a brand-toxicity-management response to the November 2022 CISA #StopRansomware advisory campaign that named Royal explicitly and to CISA AA23-061A which expanded the U.S.-government-advisory surface against the brand. The rebrand involved leak-site domain rotation, encryptor build identification rotation (the BlackSuit builds carry version-string and ransom-note variants distinguishing them from Royal builds), and brand-naming rotation in operator-side affiliate communications, but did not involve operator-cohort dispersal, encryptor-codebase rewrite, or affiliate-roster reorganisation; the wallet-cluster persistence (OAK-T8.001) and tradecraft-fingerprint persistence are the principal forensic signatures that allowed industry and U.S. government attribution work to identify the rebrand as continuity rather than dispersal. The OFAC December 2023 designation surface and the August 2024 CISA AA24-228A advisory update reflect the U.S. government's recognition that the brand-rotation was operationally a continuity event.

The brand's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding the Conti-successor-brand-network laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader Conti-successor-brand-network laundering pattern documented for Black Basta. The November 2023 Dallas Cowboys / Dallas city-government incident is the brand's highest-profile single deployment in the public record and a canonical case of Royal/BlackSuit-affiliate targeting of U.S. municipal-and-civic infrastructure.

Observed examples

  • Dallas City Government incident (May 2023, multi-week municipal-services disruption). Royal-branded deployment against the City of Dallas's IT infrastructure disrupted municipal services across police, courts, utilities, and emergency-response systems for weeks; the city refused ransom payment; data was subsequently published on the Royal leak site. The incident is widely cited as a canonical case of Royal/BlackSuit-affiliate targeting of U.S. municipal-and-civic infrastructure and is named in the August 2024 CISA AA24-228A advisory update as part of the brand's documented victim-pattern. Confirmed-grade attribution per the City of Dallas's own incident-disclosure and CISA advisory.
  • CISA AA23-061A and AA24-228A campaign cohort (through 2024). The original CISA AA23-061A (March 2023, on Royal) and the August 2024 update AA24-228A (rebadged for BlackSuit and documenting the Royal-to-BlackSuit continuity reading) collectively document over 350 named-and-unnamed Royal/BlackSuit victim organisations across U.S. critical-infrastructure sectors with healthcare, education, manufacturing, and government / municipal verticals prominently called out. Confirmed-grade aggregate.
  • U.S. healthcare and education sector targeting cohort (2023–2024). Multiple ransomware incidents against U.S. healthcare systems and school districts attributed to Royal/BlackSuit through industry-forensic reporting and CISA advisory work; the targeting profile mirrors the Conti operating-model targeting profile and is distinct in vertical concentration from the broader cross-sector Black Basta targeting profile. Confirmed-grade aggregate per CISA advisories.
  • OFAC December 2023 designation surface ([ofac2023royalblacksuit]). OFAC press release providing institutional confirmed-grade attribution to the Royal/BlackSuit operator cluster; structurally parallel to the OFAC institutional attribution architecture used for the broader Russian-speaking-RaaS-cohort umbrella; provides the SDN-screening surface for affiliate-attributable wallet addresses without naming individual operators.
  • OAK on-chain example surface. No OAK examples/ entry exists for Royal/BlackSuit-binary specifically as of v0.1; the Royal/BlackSuit-to-Garantex chain documented in industry-forensic reporting is the strongest candidate for a future OAK example entry showing the OAK-S28-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti-to-Garantex and Black-Basta-to-Garantex chains.

Detection / attribution signals

Defenders should treat Royal/BlackSuit detection at the host-layer + on-chain-layer joint level with the callback-phishing initial-access vector as the most-distinctive pre-encryption tradecraft fingerprint:

  • Host-layer process-tree fingerprints — characteristic file-extension changes (.royal extension on Royal-era encrypted files; .blacksuit on BlackSuit-era files); ransom-note filenames (README.txt per-folder); C++-Windows-binary signature with direct Conti-Zeon-fork lineage documented by Mandiant and Microsoft; partial-encryption mode signature inherited from Conti-Zeon; ESXi-variant invokes the standard esxcli VM-shutdown sequence shared across Conti-successor brands.
  • Pre-encryption tradecraft (the distinguishing Royal/BlackSuit fingerprint)callback-phishing initial-access vector is the principal behavioural signature: fabricated subscription-renewal / customer-support emails with operator-controlled phone numbers, victim-side phone calls handled by operator under fabricated technical-support persona, walk-through installation of remote-access tooling (AnyDesk, Atera, ScreenConnect, or similar) that establishes the operator's foothold without requiring exploit-payload delivery. This vector is documented in CISA AA23-061A and in continuous industry-forensic reporting from Microsoft and Sophos as a defining Royal/BlackSuit-affiliate tradecraft fingerprint distinguishing it from Qakbot-loader-chain Black-Basta-affiliate tradecraft.
  • Network-layer telemetry — Cobalt Strike post-exploitation deployment after callback-phishing-established foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns.
  • On-chain-layer signatures (the OAK-relevant signal) — Royal-to-BlackSuit wallet-cluster persistence (OAK-T8.001) is the principal forensic signature for the brand-rotation-as-continuity reading; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; common-funder cluster reuse with broader Conti-successor-brand-network affiliate clusters is the cross-cluster signature.
  • CTI vendor coverage — Mandiant (Royal/BlackSuit cluster tracking and the Conti-Zeon-fork lineage attribution work), Microsoft Threat Intelligence (DEV-0569 / Storm-0569 naming and continuous tracking), Sophos (sustained "State of Ransomware" reporting and per-incident write-ups), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained Royal/BlackSuit reporting), Coveware (incident-response-side payment and negotiation-pattern reporting), Chainalysis and TRM Labs (on-chain operator-cohort-continuity tracking across the brand-rotation).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA23-061A and AA24-228A and live CTI-vendor feeds named above.

Citations

  • [cisaaa23061a] — CISA / FBI joint advisory AA23-061A on Royal ransomware, March 2023. (Already cited in OAK-S24 BlackCat / ALPHV — note: the same advisory ID is shared between Royal and ALPHV documents; check the citations.bib entry to disambiguate.)
  • [cisaaa24228a] — CISA / FBI joint advisory AA24-228A on BlackSuit ransomware (Royal rebrand update), August 2024. (NEW citation — see summary.)
  • [ofac2023royalblacksuit] — Treasury OFAC designation press release on the Royal/BlackSuit operator cluster, December 2023. (NEW citation — see summary.)
  • [mandiantroyalblacksuit2023] — Mandiant Royal-to-BlackSuit rebrand attribution and Conti-Zeon-fork lineage analysis. (NEW citation — see summary.)
  • [microsoftstorm0569] — Microsoft Threat Intelligence DEV-0569 / Storm-0569 / Royal-BlackSuit analysis. (NEW citation — see summary.)
  • [sophosroyalblacksuit2023] — Sophos Royal/BlackSuit tradecraft and callback-phishing-vector analysis. (NEW citation — see summary.)
  • [trendmicroroyalblacksuit2023] — Trend Micro Royal/BlackSuit version-by-version analysis. (NEW citation — see summary.)
  • [chainalysisroyalblacksuit2024] — Chainalysis Royal/BlackSuit-attributable ransom-payment-volume tracking and brand-rotation wallet-cluster analysis. (NEW citation — see summary.)
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the Royal/BlackSuit volume distribution.

Discussion

On lineage as the central framing. OAK-S28's principal value as a Software entry is as the cleanest documented case of direct Conti-codebase fork as a successor-brand encryptor in the Conti-cohort dispersal network (see OAK-S26 Discussion). Where Black Basta (OAK-S27) is a Conti-codebase-derivative-with-substantive-rewrites lineage, Royal/BlackSuit is a direct Conti-Zeon-fork lineage; the architectural differences between the two cases provide a useful comparative reference for understanding the spectrum of codebase-reuse-versus-rewrite tactics available to a successor-brand operator cohort. The June 2023 Royal-to-BlackSuit rebrand event is the canonical worked example of brand-toxicity-management rebrand as continuity-disruption tooling, structurally parallel to but distinct from the Conti-cohort dispersal-into-multiple-brands pattern.

On predecessors. Royal's direct predecessor at the encryptor-codebase level is Conti's Zeon variant (a short-lived Conti-cohort branch from late 2021 / early 2022); the operator-cohort-level predecessor is the broader Conti / Wizard Spider cohort (2020–2022, OAK-S26). BlackSuit's direct predecessor is Royal at both the codebase and the operator-cohort levels — the rebrand is continuity rather than succession.

On the brand-rotation pattern. The Royal-to-BlackSuit rebrand of June 2023 sits within a broader sector pattern of brand-rotation-as-continuity-tooling that includes also DarkSide → BlackMatter (2021), and Conti's ongoing post-2022 sub-brand experimentation (Quantum, Zeon, Karakurt). The pattern is structurally distinct from both codebase-version-rotation (LockBit 1.0 → 2.0 → 3.0 → Green) and cohort-dispersal-into-multiple-brands (Conti → Black Basta + Royal/BlackSuit + Karakurt + BlackByte + Quantum/Zeon); from a defender perspective the three patterns require structurally different attribution-graph maintenance approaches and produce structurally different downstream affiliate-cohort-tracking signatures.

On the OAK Software-vs-Group split for a brand-rotation case. OAK-S28 (this entry) is the Royal/BlackSuit encryptor codebase across both brand identities; the conjoined naming reflects the continuity reading at the codebase level. There is no current OAK-G entry for the Royal/BlackSuit operator cluster as of v0.1; future OAK-G entries (in the v0.x Group catalog expansion) will likely include a separate Group entry for the cluster with reference back to OAK-S28 as the encryptor-codebase anchor. The OFAC December 2023 designation surface provides institutional confirmed-grade attribution at the cluster level; the absence of named-defendant-indictment as of v0.1 distinguishes this attribution architecture from the LockBit / Khoroshev architecture (named-defendant indictment) and aligns it with the Garantex / Conti / broader-Russian-speaking-RaaS-cohort architecture (institutional cluster designation without named individuals).

On takedown / disruption history. Royal/BlackSuit has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action; the OFAC December 2023 designation surface and the CISA advisory campaign provide institutional pressure but not operational disruption. The brand's continued operations through 2024 and into 2025 reflect the structural challenge of disrupting a Russian-jurisdiction-based operator cohort without the equivalent of the Khoroshev-naming and SDN-architecture surface that drove the LockBit collapse.

Techniques observed (3)