Black Kingdom Ransomware Admin Charged by U.S. for Microsoft Exchange Hacks

Black Kingdom Ransomware Admin Charged by U.S. for Microsoft Exchange Hacks

Yemeni Hacker Accused of Orchestrating Global Ransomware Assault Using Black Kingdom Malware

Federal prosecutors have unsealed an indictment against 36-year-old Rami Khaled Ahmed, a Yemeni national, accused of launching a widespread cyber-extortion campaign that exploited Microsoft Exchange vulnerabilities and disrupted organizations across multiple sectors. The charges were announced by the U.S. Department of Justice in California’s Central District.

According to authorities, between March 2021 and June 2023, Ahmed allegedly infiltrated approximately 1,500 systems both in the United States and abroad. By deploying the Python-based Black Kingdom ransomware, he reportedly encrypted data, crippled infrastructure, and demanded Bitcoin payments from victims.

The malware leveraged weaknesses in Microsoft Exchange Server software to implant web shells—tools enabling remote control and script execution. Among the impacted were a healthcare billing firm in Encino, California, a recreational resort in Oregon, a school district in Pennsylvania, and a medical clinic in Wisconsin.

Inside Black Kingdom’s Code: Simplicity with Malicious Impact

Black Kingdom stands out from more sophisticated ransomware variants by its use of Python 3.7 code compiled into executables via PyInstaller. The core logic resided in a file dubbed 0xfff.py. Despite its rudimentary build, it wreaked havoc by encrypting files with extensions like “.DEMON” and “.black_kingdom” and distributing ransom notes that demanded $10,000 in Bitcoin.

These digital extortion notes warned victims that their data would be exposed online if payments weren’t sent to a designated cryptocurrency address. In one case, a $9,400 payment was recorded.

Security analysts observed inconsistent behavior in the malware: some versions re-encrypted files multiple times, while others didn’t encrypt anything at all—relying instead on scare tactics to induce panic and payment. In rare cases, a hardcoded decryption key made it possible to recover files without paying the ransom.

Campaign Tactics and Evolution

Initially targeting Pulse Secure VPN flaws in 2020, Black Kingdom later pivoted in 2021 to exploit Microsoft Exchange vulnerabilities. The campaign often began by executing scripts via planted web shells that downloaded and launched ransomware payloads. While the ransomware typically avoided critical system directories, it lacked robust safeguards, increasing the risk of unintended data corruption.

The attacker also attempted to erase event logs, a tactic aimed at concealing the breach and hindering forensic investigations. Demands ranged from 0.052 to 0.19 BTC—roughly $500 to $10,000—with relatively few transactions recorded, indicating a limited payout success.

Legal Fallout and Ongoing Manhunt

Ahmed faces multiple charges, including conspiracy to damage protected computers and transmitting threats related to those attacks. If convicted, he could serve up to 15 years in prison.

He is currently believed to be residing in Yemen, and efforts to locate and extradite him are active. The FBI’s Los Angeles Field Office spearheaded the investigation, with law enforcement agencies emphasizing the importance of timely patching, system monitoring, and data backups in the fight against ransomware threats.

More Articles & Posts