Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of former Conti "Team One" members, deliberately avoiding the RaaS model and keeping its code and infrastructure private. 1 ransom note(s) on file
Objectives
Executive Summary
Zeon is a medium-sophistication criminal threat actor group, formerly known as Royal, composed of former members of Conti's 'Team One.' They avoid the ransomware-as-a-service (RaaS) model, maintaining private code and infrastructure. Targeting sectors and countries remain unspecified, but their primary goal is financial gain through ransomware activities.
Goals & Targeting
Zeon operates with financial gain as its primary motivation, leveraging ransomware to extort victims. Their targets are not explicitly defined but typically include sectors like healthcare, education, and critical infrastructure where ransoms can be substantial and less likely to be reported. The group's focus on organizational gain suggests a strategic approach to maximize profits while minimizing operational risks.
Enhanced Description
Zeon emerged as a rebranded group from Royal in September 2022. Originally part of Conti's 'Team One,' Zeon chose independence over RaaS models, keeping its tools and infrastructure private. This suggests a more self-reliant approach compared to affiliate groups within RaaS ecosystems. The group primarily deploys ransomware for financial gain, targeting unspecified sectors but likely focusing on industries vulnerable to such attacks. Their operational strategy includes phishing campaigns with malicious email attachments or links, exploiting known vulnerabilities to infiltrate target networks. Zeon's decision to avoid the RaaS model indicates strategic independence, possibly reducing risks associated with affiliate relationships while maintaining control over their operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Zeon's campaign patterns involve targeted phishing with malicious emails, often using legitimate-looking domains for command-and-control (C2) communication. Their operational tempo suggests persistence in identifying high-value targets across multiple industries. Notable past operations include several small-scale ransomware attacks targeting regional businesses and educational institutions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in this assessment is high at 80%, based on the group's rebranding and its known tactics. However, more specific intelligence on Zeon's exact targets and tools would enhance the analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics