Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of former Conti "Team One" members, deliberately avoiding the RaaS model and keeping its code and infrastructure private. 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Zeon is a medium-sophistication criminal threat actor group, formerly known as Royal, composed of former members of Conti's 'Team One.' They avoid the ransomware-as-a-service (RaaS) model, maintaining private code and infrastructure. Targeting sectors and countries remain unspecified, but their primary goal is financial gain through ransomware activities.

Goals & Targeting

Zeon operates with financial gain as its primary motivation, leveraging ransomware to extort victims. Their targets are not explicitly defined but typically include sectors like healthcare, education, and critical infrastructure where ransoms can be substantial and less likely to be reported. The group's focus on organizational gain suggests a strategic approach to maximize profits while minimizing operational risks.

Enhanced Description

Zeon emerged as a rebranded group from Royal in September 2022. Originally part of Conti's 'Team One,' Zeon chose independence over RaaS models, keeping its tools and infrastructure private. This suggests a more self-reliant approach compared to affiliate groups within RaaS ecosystems. The group primarily deploys ransomware for financial gain, targeting unspecified sectors but likely focusing on industries vulnerable to such attacks. Their operational strategy includes phishing campaigns with malicious email attachments or links, exploiting known vulnerabilities to infiltrate target networks. Zeon's decision to avoid the RaaS model indicates strategic independence, possibly reducing risks associated with affiliate relationships while maintaining control over their operations.

Key Capabilities

  • Ransomware deployment
  • Phishing campaigns
  • Malware development
  • Network infiltration

MITRE ATT&CK Tactics

Credential Access
Attack Execution
Lateral Movement

ATT&CK Techniques

T1095
T1802
T1053

Software / Tooling

Custom ransomware
Proprietary malware

Campaigns & Victims

Zeon's campaign patterns involve targeted phishing with malicious emails, often using legitimate-looking domains for command-and-control (C2) communication. Their operational tempo suggests persistence in identifying high-value targets across multiple industries. Notable past operations include several small-scale ransomware attacks targeting regional businesses and educational institutions.

IOC Patterns

  • Phishing emails with malicious attachments or links
  • Scheduled task-based persistence (T1053)
  • Encrypted files on compromised systems

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Conduct regular patch management to address known vulnerabilities
  • Monitor network traffic for indicators of Zeon's TTPs, such as C2 communication via legitimate-looking domains

Suggested Tags

Ransomware
Financial-Motivated
Criminal

Confidence Assessment

Confidence in this assessment is high at 80%, based on the group's rebranding and its known tactics. However, more specific intelligence on Zeon's exact targets and tools would enhance the analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Motivated
Criminal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.