Ransomware

U.S. indicts Black Kingdom Ransomware Operator for Microsoft Exchange Attacks

0

The United States has indicted 36-year-old Rami Khaled Ahmed, a Yemeni national, for allegedly developing and operating the Black Kingdom ransomware, which targeted Microsoft Exchange servers in over 1,500 attacks worldwide.

According to the U.S. Department of Justice (DoJ), between March 2021 and June 2023, Ahmed and unnamed co-conspirators infected systems belonging to numerous victims, including a medical billing firm in Encino, a ski resort in Oregon, a Pennsylvania school district, and a Wisconsin health clinic. Victims were instructed to pay $10,000 in Bitcoin and send proof of payment to a designated Black Kingdom email address.

The malware exploited a critical vulnerability in Microsoft Exchange servers, known as ProxyLogon, to gain initial access. First publicly disclosed in early 2021, the ProxyLogon vulnerabilities—CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065—allowed attackers to escalate privileges and deploy web shells on targeted servers. Security researcher Marcus Hutchins first reported evidence of Black Kingdom operators using these flaws in March 2021.

Microsoft later confirmed that Black Kingdom had compromised approximately 1,500 Exchange servers through these exploits.

Prior to these attacks, in mid-2020, the Black Kingdom group was also observed exploiting CVE-2019-11510, a critical flaw in Pulse Secure VPN, to infiltrate corporate networks and deploy their ransomware.

Ahmed now faces multiple federal charges, including conspiracy, intentional damage to protected computers, and threats to damage protected systems. If convicted, he could serve up to 15 years in U.S. federal prison—five years for each count.

U.S. authorities believe Ahmed is currently residing in Yemen.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

TikTok fined €530 M over unlawful data transfers to China

Previous article

NSO Group fined $168M for illegally spying on WhatsApp Users

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *