Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

Royal ransomware turned ordinary Windows compromises into enterprise-wide crises by pairing a phishing foothold with fast domain takeover.

In incidents reviewed by responders, the operators used Qbot to gain a presence and then expanded their reach before deploying encryption.

The result was a disruptive attack that could spread faster than many defenders expected.

The campaign began with spearphishing emails sent to employees, often carrying a malicious attachment. Once a victim opened it, Qbot ran through the Windows command shell and helped the attackers establish control.

Similar delivery methods have made Qbot a frequent concern in business email attacks, as seen in QBot malware hijacking business emails.

Analysts from Invictus identified the activity while assisting organizations affected by ransomware. 

Invictus said in a report shared with Cyber Security News (CSN) that their investigation showed that Royal relied on speed, using multiple tools and trusted Windows features to move from one infected computer to a much wider network compromise.

Royal was highly active during late 2022, when its leak site listed almost 60 victims across November and December alone.

Incident responders warned that this was likely an incomplete picture because not every victim appeared on the site. Earlier reporting also documented Royal’s multimillion-dollar ransom demands in Royal ransomware profit reports.

Royal Ransomware Uses Qbot and Cobalt Strike

The attackers used Qbot as the first backdoor and then launched Cobalt Strike through encoded PowerShell commands.

Qbot was configured for persistence through a Windows Registry Run key, while Cobalt Strike was installed as a Windows service on several systems. This gave the operators more than one route back into the victim environment.

The two tools were also injected into legitimate Windows processes, making malicious activity harder to spot during a rushed investigation.

Infection chain (Source – Invictus)

Cobalt Strike used peer-to-peer communication over Windows named pipes, while both tools communicated with their controllers through HTTPS traffic. Attackers have repeatedly adapted Cobalt Strike for Windows intrusion chains, including Cobalt Strike injection on Windows.

After gaining privileged domain accounts, the group used them to move through the network.

It mounted remote administrative shares from the first infected workstation and used stolen credential hashes to access additional systems. The operators also used built-in Windows utilities to list users, groups, domain trusts, and available network shares.

PowerSploit and AdFind supported the reconnaissance phase by helping the group identify local administrators and map the domain.

The investigation found that Royal favored a direct approach over stealth, accepting that some security alerts might fire if it meant reaching full domain control quickly. That pace left little time for defenders to contain the intrusion.

Detection Steps for Defenders

The response guidance centers on Windows logging and early investigation of suspicious activity.

Security teams should review scheduled tasks in the Application Event Log, examine PowerShell activity, and investigate unexpected Windows service installations. These events can reveal persistence mechanisms before ransomware is deployed across the network.

Centralizing service-installation records is particularly useful because Cobalt Strike commonly uses services to remain active.

Recent research on Windows event log ransomware detection similarly recommends collecting Event ID 7045 and building detections for suspicious service creation.

Organizations should also treat unusual PowerShell activity as a priority, especially encoded commands, unexpected script execution, and PowerShell launched after a phishing event.

Royal used PowerShell throughout several attack stages, including the execution of Cobalt Strike and a user account control bypass involving a default scheduled task.

The group also exfiltrated data to cloud storage services before encryption, using Dropbox and MegaSync applications in observed cases.

Defenders should therefore monitor for unauthorized cloud-transfer tools, protect privileged accounts, and isolate infected hosts quickly.

Fast action matters because Royal’s operators were able to turn a single compromised workstation into a domain-wide emergency.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.