Black Kingdom ransomware was deployed against unpatched on-premises Microsoft Exchange servers after attackers exploited the ProxyLogon chain, particularly CVE-2021-27065, and installed web shells for remote access. Reporting from multiple security firms says the operators used shells including ChackLogsPL.aspx, ckPassPL.aspx, hackIdIO.aspx, and in some cases China Chopper, then launched the payload through PowerShell, WMI, and downloads from infrastructure such as yuuuuu44[.]com. Trend Micro also linked ProxyLogon exploitation to other malware families including LemonDuck and Prometei, showing that Exchange compromises quickly became a shared delivery path for ransomware, coinminers, and botnets.
Researchers described Black Kingdom as a relatively crude Python ransomware built with PyInstaller, but still disruptive: it encrypted files, could encrypt them multiple times, stopped SQL-related services, deleted Windows Event Logs, and displayed a ransom note demanding $10,000 in Bitcoin. Analysis found the malware uploaded victim IDs and encryption keys to Mega, but fell back to a hardcoded key if that failed, creating a significant cryptographic weakness that may allow recovery in some cases. Additional reporting tied the campaign to random encrypted-file extensions, shared payment infrastructure, possible data-theft extortion claims, and at least one likely ransom payment, while analysts assessed the Exchange attacks as largely opportunistic rather than confidently attributable to a known threat actor.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Sophos telemetry began detecting Black KingDom activity on vulnerable on-premises Microsoft Exchange servers on March 18. The attacks exploited ProxyLogon CVE-2021-27065, deployed webshells, and launched ransomware via PowerShell and WMI.
Trend Micro telemetry showed the Prometei botnet exploiting ProxyLogon after BlackKingdom. The report linked both BlackKingdom and Prometei to similar post-exploitation behavior such as use of ExchDefender.exe and the fake MSExchangeDefenderPL service.
Trend Micro reported that BlackKingdom began exploiting ProxyLogon shortly after LemonDuck. In these intrusions, attackers used China Chopper web shells on compromised Exchange servers and post-exploitation tooling including ExchDefender.exe.
Trend Micro telemetry showed LemonDuck exploiting ProxyLogon beginning in March 2021. The activity preceded BlackKingdom and Prometei exploitation in the same broader wave.
Securelist reported renewed Black Kingdom activity in 2021 tied to exploitation of Microsoft Exchange ProxyLogon vulnerabilities, particularly CVE-2021-27065. The report described opportunistic deployment after webshell installation and highlighted a hardcoded fallback key weakness that could enable file recovery.
Trend Micro stated that the Microsoft Exchange ProxyLogon vulnerability set was discovered in late 2020. These zero-days later enabled attacks on unpatched Exchange servers.
Securelist noted that Black Kingdom was also observed in 2020 following exploitation of the Pulse Secure vulnerability CVE-2019-11510. This shows the ransomware was used before the later Exchange-focused activity.
Securelist reported that the Black Kingdom ransomware family was first seen in 2019. The malware was characterized as a Python-based ransomware later reused in subsequent campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcenews.sophos.com
Open sourcenews.sophos.com
Open sourcesecurelist.com
Open sourcetrendmicro.com
Open sourceproxylogon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.