• News/
  • https://www.bleepingcomputer.com/news/security/us-indicts-black-kingdom-ransomware-admin-for-microsoft-exchange-attacks/

US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks

BleepingComputer
·
Bill Toulas
·
Published May 2, 2025
·
Updated

A 36-year-old Yemeni national, who is believed to be the developer and primary operator of 'Black Kingdom' ransomware, has been indicted by the United States for conducting 1,500 attacks on Microsoft Exchange servers. The suspect, Rami Khaled Ahmed, is accused of deploying the Black Kingdom malware on roughly 1,500 computers in the United States and abroad, demanding ransom payments of $10,000 in Bitcoin. "According to the indictment, from March 2021 to June 2023, Ahmed and others infected computer networks of several U.S.-based victims, including a medical billing services company in Encino, a ski resort in Oregon, a school district in Pennsylvania, and a health clinic in Wisconsin," explains a U.S. Department of Justice announcement. "When the malware was successful, the ransomware then created a ransom note on the victim's system that directed the victim to send $10,000 worth of Bitcoin to a cryptocurrency address controlled by a co-conspirator and to send proof of this payment to a Black Kingdom email address," reads another part of the announcement. The U.S. DoJ highlights that Ahmed designed Black Kingdom ransomware to exploit a vulnerability in Microsoft Exchange for initial access to targeted computers. This was first reported in March 2021 by researcher Marcus Hutchins, who discovered web shells deployed by Black Kingdom ransomware operators on Exchange servers vulnerable to ProxyLogon attacks. The ProxyLogon flaw refers to a set of critical vulnerabilities in Micro...

Read full article

Affected Software

2 affected components
Microsoft Exchange Server
Pulse Secure Pulse Secure VPN
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the indictment of a Yemeni national for operating the Black Kingdom ransomware that targeted Microsoft Exchange servers.

2

What security implications are discussed in the article?

The article highlights the vulnerability of Microsoft Exchange servers to ransomware attacks and the legal consequences for cybercriminals.

3

What products or software are affected?

The primary affected software is Microsoft Exchange Server, with additional mentions of Pulse Secure VPN.

4

How many attacks did the indicted individual conduct?

The individual is believed to have conducted approximately 1,500 attacks on Microsoft Exchange servers.

5

What was the role of the individual indicted?

The individual is identified as the developer and primary operator of the Black Kingdom ransomware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203