Black Kingdom, also known as DEMON and DemonWare, is a Windows ransomware family first observed in 2019 and notably reused in 2021 opportunistic attacks against unpatched on-premises Microsoft Exchange servers vulnerable to ProxyLogon, including CVE-2021-27065. After server compromise, operators deployed ASPX webshells for remote command execution, then used PowerShell to download the ransomware and WMI to launch it. Observed tradecraft also included functionality to copy and execute the payload on other systems across the network.
The malware is a relatively unsophisticated Python-based ransomware packaged with PyInstaller, but it remains destructive. It encrypts files across local and reachable drives, attempts to stop SQL-related services to improve access to database files, deletes Windows event logs to hinder response, and can disable mouse and keyboard input while presenting a full-screen ransom interface with a countdown timer. Black Kingdom does not reliably check whether files were already encrypted, allowing repeated encryption and additional damage. It appends random suffixes to encrypted files rather than using a fixed extension and drops ransom notes to instruct victims on payment and contact.
Black Kingdom generates an encryption key and victim identifier and attempts to upload them to Mega. If that upload fails, it falls back to a hardcoded embedded key, a design weakness that has been noted as a potential recovery opportunity in some cases. The ransom messaging has included extortion claims involving alleged data theft and demanded payment in cryptocurrency. Reporting has linked Black Kingdom activity to exploitation of exposed enterprise infrastructure, including Microsoft Exchange and previously Pulse Secure systems, but public attribution to a specific established threat actor remains unconfirmed. The malware has been associated with attacks on internet-facing enterprise servers rather than a narrowly defined vertical, with observed victims including organizations in multiple countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor exploited the on-premises versions of Microsoft Exchange Server, abusing the remote code execution (RCE) vulnerability also known as ProxyLogon (CVE-2021-27065). | another ransomware gang has also started to target vulnerable Exchange servers with another ransomware, called Black KingDom... Sophos telemetry began detecting the ransomware on Thursday March 18 as it targeted Exchange servers that remain unpatched against the ProxyLogon vulnerabilities
another ransomware gang has also started to target vulnerable Exchange servers with another ransomware, called Black KingDom... Sophos telemetry began detecting the ransomware on Thursday March 18 as it targeted Exchange servers that remain unpatched against the ProxyLogon vulnerabilities
Black Kingdom is not a new player: it was observed in action following other vulnerability exploitations in 2020, such as CVE-2019-11510. Date CVE Product affected June 2020 CVE-2019-11510 Pulse Secure | Black Kingdom ransomware appeared on the scene back in 2019, but we observed some activity again in 2021. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
Black Kingdom ransomware appeared on the scene back in 2019, but we observed some activity again in 2021. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
Black Kingdom ransomware appeared on the scene back in 2019, but we observed some activity again in 2021. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The script executes the ransomware by invoking Win32_Process via WMI, (the Windows Management Interface).
Appendix II – MITRE ATT&CK Mapping ... Execution T1059 Command and Scripting Interpreter
sha256 62615438CF8F7DE6600D16A493C28BBBD3B052CCC4F9414DFE1CF031681E226F ChackPassPL.aspx webshell - not publicly released; sha256 800E036CF9DA316193BECABC6ACE688634709CD898AE81893E80B635DCAA06D0 ChackIdIO.aspx webshell - not publicly released
Appendix II – MITRE ATT&CK Mapping ... Privilege Escalation T1055 Process Injection
Appendix II – MITRE ATT&CK Mapping ... Privilege Escalation T1134 Access Token Manipulation
Appendix II – MITRE ATT&CK Mapping ... Privilege Escalation T1055 Process Injection
To further complicate and hinder incident response, the ransomware deletes the Windows Event logs
Appendix II – MITRE ATT&CK Mapping ... Privilege Escalation T1134 Access Token Manipulation
Appendix II – MITRE ATT&CK Mapping ... Discovery T1016 System Network Configuration Discovery
Appendix II – MITRE ATT&CK Mapping ... Discovery T1018 Remote System Discovery
Appendix II – MITRE ATT&CK Mapping ... Discovery T1057 Process Discovery
Black Kingdom allows reading a file in the same directory called target.txt, which will be used by the ransomware to recursively collect files for the collected directories specified in that file and then encrypt them. Black Kingdom will also enumerate various drive letters and encrypt them.
url hxxp://yuuuuu44[.]com/vpn-service/$(f1)/crunchyroll-vpn Where $(f1) is a randomly-generated 16-alphabetic character string
The file system behavior of the file encryption function is straightforward: Read (original) > Overwrite (encrypted) > Rename
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used to target ~1,500 systems globally, including U.S. businesses, schools, and hospitals (as described).
Basic ransomware targeting unpatched Microsoft Exchange servers via ProxyLogon.
Ransomware used to target unpatched on-premises Microsoft Exchange servers via the ProxyLogon vulnerability (CVE-2021-27065). After exploitation, attackers deploy a webshell, use PowerShell to download the payload, execute it via WMI, encrypt files, upload victim ID and encryption key material to Mega, delete Windows Event Logs, and display a full-screen ransom window while dropping a ransom note named decrypt_file.TxT.
Ransomware used against unpatched on-premises Microsoft Exchange servers via ProxyLogon. It is described as rudimentary and amateurish, delivered through a webshell, executed via PowerShell/WMI, able to spread to other computers on the network, encrypt files, delete Windows Event logs, terminate SQL-related services, upload victim ID and encryption key to Mega, and display a full-screen ransom window.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.