Royal Ransomware: Qbot and Cobalt Strike Target Windows Domains
Royal ransomware has emerged as a major threat to organisations by leveraging Qbot and Cobalt Strike to swiftly compromise Windows domains. This campaign, first identified in late 2023 and continuing into 2024, turns basic phishing attacks into full-scale enterprise incidents within hours.
Detailed Timeline and Attack Flow
Spearphishing Delivers Qbot Malware
The attack campaign begins with targeted spearphishing emails sent to employees across various sectors. These emails typically include malicious attachments engineered to bypass basic email security controls. Once an employee opens the attachment, Qbot (also known as QakBot) is executed through the Windows command shell, granting attackers an initial foothold inside the corporate network.
- When: Incidents observed from late 2023 through early 2024
- Where: Primarily targets Windows domains in enterprise environments
- Method: Spearphishing emails with malicious attachments
- Malware Used: Qbot (QakBot)
Qbot’s role in these attacks is crucial. It is a modular banking trojan with functionality for credential theft, lateral movement and delivery of further payloads. In the Royal ransomware campaign, Qbot is used to establish persistent access and facilitate rapid escalation across the Windows domain.
Rapid Domain Compromise with Cobalt Strike
After Qbot secures an initial presence, Royal ransomware operators deploy Cobalt Strike—a legitimate penetration testing tool frequently abused by threat actors. Cobalt Strike’s beacons enable attackers to move laterally, escalate privileges and map out the domain environment with alarming speed.
- Qbot establishes command and control (C2) communications
- Attackers deploy Cobalt Strike beacons across the network
- Privilege escalation and credential harvesting occur
- Attackers gain control over key servers and Active Directory
This phase allows attackers to bypass segmentation and traverse the domain, compromising multiple endpoints and critical infrastructure within minutes to hours. The use of Cobalt Strike makes detection challenging, as its capabilities mimic legitimate administrative activity and use encrypted communications.
Encryption and Impact
Once the attackers have achieved sufficient control, they deploy the Royal ransomware payload. Encryption is triggered in a coordinated manner, targeting files across endpoints and servers. The impact is immediate: business operations are disrupted, and data access is blocked. Victims are left with ransom notes demanding payment for decryption keys.
According to incident responders, the entire process—from initial phishing email to full domain encryption—can unfold in less than a day. This compressed timeline leaves little room for traditional detection and response.
Technical Details and Exploitation Status
Products and Versions Affected
The Royal ransomware campaign specifically targets Windows domain environments. There are no vendor-specific vulnerabilities involved; rather, attackers exploit weak email security, unmonitored endpoints and insufficient Active Directory monitoring. All supported and unsupported Windows versions are at risk if basic security controls are lacking.
- Windows Server (all supported and legacy versions)
- Windows 10, Windows 11 endpoints
- Active Directory environments
Qbot is delivered via phishing and does not rely on a specific software vulnerability, making all organisations with exposed email users potential targets. Cobalt Strike is used post-compromise and requires only that attackers have already achieved some level of access.
Current Exploitation and Detection
Royal ransomware operations remain active as of 2024. Security researchers continue to observe new intrusions using this technique, and both Qbot and Cobalt Strike are frequently updated to evade detection. There are no public indicators that the threat actors have slowed their targeting of enterprise Windows domains. The campaign’s success relies on rapid lateral movement and the ability to escalate privileges without triggering conventional alerts.
Why This Matters
This campaign is significant because it demonstrates how a combination of social engineering, commodity malware and abuse of legitimate tools can enable rapid enterprise compromise. Royal ransomware’s use of Qbot and Cobalt Strike means that even a single successful phishing email can quickly result in full domain takeover and encryption, outpacing traditional detection and response measures.
Recommended Actions for Organisations
- Strengthen email security to block spearphishing attachments before delivery.
- Deploy advanced EDR solutions capable of detecting Qbot and Cobalt Strike behaviours.
- Monitor Active Directory for suspicious privilege escalation and lateral movement.
- Ensure incident response plans account for rapid ransomware deployment scenarios.
While no single control can guarantee protection, layered defences and proactive monitoring are critical to slowing or stopping these rapid attacks.
Originally reported by cybersecuritynews.com.




