Royal ransomware appending .royal extension to the files it encrypts WRITING THE RANSOM NOTE During the entire Royal ransomware process, the ransomware creates an additional thread to retrieve the logical drives using the API call GetLogicalDrives. It then writes the ransom note with the name “REA...