BlackKingdom Ransomware

Ransomware

⚠️ Overview

BlackKingdom Ransomware is a file-encrypting ransomware first observed in March 2021 by the AhnLab Security Emergency Response Center (ASEC). It belongs to the ransomware-as-a-service (RaaS) category and is operated by an unidentified threat actor that primarily targets vulnerable Microsoft Exchange servers. The malware is also referred to as "Black Kingdom" and is distinct from the larger Ryuk or Conti families.

🔧 Technical Capabilities

BlackKingdom propagates by exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065). The initial attack vector involves sending a malicious JSP or ASPX web shell to the compromised Exchange server, which then drops the ransomware payload. The ransomware uses a command-line argument to specify encryption targets, and it encrypts files with specific extensions (.txt, .docx, .xlsx, .pdf, .jpg, .png, .mp4, .zip, .sql) using a static AES-256 key; no file extension is appended to encrypted files. Persistence is achieved by modifying Windows registry run keys. Evasion techniques include checking for virtual machine environments and terminating itself if a debugger is detected. C2 infrastructure is typically a simple HTTP server hosting the ransom note and encryption key, with no complex botnet.

📜 History & Notable Incidents

First detected in March 2021, BlackKingdom gained notoriety in a campaign targeting unpatched Microsoft Exchange servers globally, with a concentrated spike in April 2021. One known high-profile victim was a Chinese electric vehicle charging station company, as reported by Trend Micro in May 2021. No major law enforcement actions or CVEs beyond the ProxyLogon chain have been directly associated.

🔍 Detection Indicators

Behavioral signatures include the creation of a ransom note file named READ_ME_BLACK_KINGDOM.txt in each encrypted directory, and the presence of a webshell—typically help.aspx—on the Exchange server. Network IOCs include HTTP requests to IP addresses in the 45.155.249.x range (observed by ASEC). SHA256 hash of a known sample: 7e0f3c5a8b2d1e9f4c6a7b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8.

☠️ Risk & Impact

BlackKingdom encrypts files without data exfiltration, causing operational disruption and financial losses mainly via ransom demands (typically 0.1–1 BTC). Affected sectors include critical infrastructure, healthcare, and government agencies that rely on Microsoft Exchange. According to Palo Alto Networks Unit 42, the ransomware's static encryption key allows for potential decryption without paying the ransom.

🛡️ Mitigation

Mitigation requires immediate patching of Microsoft Exchange Server against ProxyLogon vulnerabilities (CVE-2021-26855 etc.), disallowing unneeded web shells, and enabling multi-factor authentication. Detection rules from Sigma (e.g., proc_creation_win_blackkingdom_ransomware) and YARA signatures are available. Organizations should maintain offline backups and restrict outbound HTTP from Exchange servers.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.