Royal Ransomware Uses Qbot and Cobalt Strike on Windows

Royal Ransomware: Qbot and Cobalt Strike Target Windows Domains

Royal ransomware has emerged as a major threat to organisations by leveraging Qbot and Cobalt Strike to swiftly compromise Windows domains. This campaign, first identified in late 2023 and continuing into 2024, turns basic phishing attacks into full-scale enterprise incidents within hours.

Detailed Timeline and Attack Flow

Spearphishing Delivers Qbot Malware

The attack campaign begins with targeted spearphishing emails sent to employees across various sectors. These emails typically include malicious attachments engineered to bypass basic email security controls. Once an employee opens the attachment, Qbot (also known as QakBot) is executed through the Windows command shell, granting attackers an initial foothold inside the corporate network.

  • When: Incidents observed from late 2023 through early 2024
  • Where: Primarily targets Windows domains in enterprise environments
  • Method: Spearphishing emails with malicious attachments
  • Malware Used: Qbot (QakBot)

Qbot’s role in these attacks is crucial. It is a modular banking trojan with functionality for credential theft, lateral movement and delivery of further payloads. In the Royal ransomware campaign, Qbot is used to establish persistent access and facilitate rapid escalation across the Windows domain.

Rapid Domain Compromise with Cobalt Strike

After Qbot secures an initial presence, Royal ransomware operators deploy Cobalt Strike—a legitimate penetration testing tool frequently abused by threat actors. Cobalt Strike’s beacons enable attackers to move laterally, escalate privileges and map out the domain environment with alarming speed.

  • Qbot establishes command and control (C2) communications
  • Attackers deploy Cobalt Strike beacons across the network
  • Privilege escalation and credential harvesting occur
  • Attackers gain control over key servers and Active Directory

This phase allows attackers to bypass segmentation and traverse the domain, compromising multiple endpoints and critical infrastructure within minutes to hours. The use of Cobalt Strike makes detection challenging, as its capabilities mimic legitimate administrative activity and use encrypted communications.

Encryption and Impact

Once the attackers have achieved sufficient control, they deploy the Royal ransomware payload. Encryption is triggered in a coordinated manner, targeting files across endpoints and servers. The impact is immediate: business operations are disrupted, and data access is blocked. Victims are left with ransom notes demanding payment for decryption keys.

According to incident responders, the entire process—from initial phishing email to full domain encryption—can unfold in less than a day. This compressed timeline leaves little room for traditional detection and response.

Technical Details and Exploitation Status

Products and Versions Affected

The Royal ransomware campaign specifically targets Windows domain environments. There are no vendor-specific vulnerabilities involved; rather, attackers exploit weak email security, unmonitored endpoints and insufficient Active Directory monitoring. All supported and unsupported Windows versions are at risk if basic security controls are lacking.

  • Windows Server (all supported and legacy versions)
  • Windows 10, Windows 11 endpoints
  • Active Directory environments

Qbot is delivered via phishing and does not rely on a specific software vulnerability, making all organisations with exposed email users potential targets. Cobalt Strike is used post-compromise and requires only that attackers have already achieved some level of access.

Current Exploitation and Detection

Royal ransomware operations remain active as of 2024. Security researchers continue to observe new intrusions using this technique, and both Qbot and Cobalt Strike are frequently updated to evade detection. There are no public indicators that the threat actors have slowed their targeting of enterprise Windows domains. The campaign’s success relies on rapid lateral movement and the ability to escalate privileges without triggering conventional alerts.

Why This Matters

This campaign is significant because it demonstrates how a combination of social engineering, commodity malware and abuse of legitimate tools can enable rapid enterprise compromise. Royal ransomware’s use of Qbot and Cobalt Strike means that even a single successful phishing email can quickly result in full domain takeover and encryption, outpacing traditional detection and response measures.

Recommended Actions for Organisations

  • Strengthen email security to block spearphishing attachments before delivery.
  • Deploy advanced EDR solutions capable of detecting Qbot and Cobalt Strike behaviours.
  • Monitor Active Directory for suspicious privilege escalation and lateral movement.
  • Ensure incident response plans account for rapid ransomware deployment scenarios.

While no single control can guarantee protection, layered defences and proactive monitoring are critical to slowing or stopping these rapid attacks.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call