Operators of the Black Kingdom ransomware are targeting businesses with unpatched Pulse Secure VPN software, according to security researchers.

The malware was trapped in a honeypot, allowing researchers to analyze and document the tactics used by threat actors.
They exploit CVE-2019-11510, a critical vulnerability affecting older versions of Pulse Secure VPN that was patched in April 2019. Companies delayed updating their software even after the exploits, with the US government and some threat actors exploiting it – some organizations continue to run a vulnerable version of the product.
REDTEAM.PL, a Poland-based cybersecurity services company, observed that Black Kingdom operators used the same backdoor provided by Pulse Secure VPN to breach what they believed was a target.
From the researchers' observations, the ransomware established persistence by impersonating a legitimate scheduled task for Google Chrome, with just one letter making the difference:

According to REDTEAM.PL's analysis, the scheduled task executes a Base64-encoded string of code in a hidden PowerShell to retrieve a script named "reverse.ps1" that is likely used to open a "reverse shell" on the compromised host.

Adam Ziaja from REDTEAM.PL said that the script cannot be retrieved from the remote server controlled by the attacker, possibly because the server hosting it was blocked before the payload was delivered.
The IP address where “reverse.ps1” resided is 198.13.49.179, which is managed by Choopa, a subsidiary of Vultr, known for its cheap virtual private servers (VPS). servers are also used by cybercriminals to host their malicious tools.

Recent appearance
Black Kingdom ransomware was first detected in late February by security researcher GrujaRS, who found that it appended the .DEMON extension to encrypted files.
The analyzed sample contacted the same IP address found in the REDTEAM.PL. The following ransom note appeared, demanding $10,000 to be deposited into a bitcoin wallet and threatening that failure to do so would result in the destruction or sale of the data.

