Another ransomware operation known as “Black Kingdom” is exploiting Microsoft Exchange Server ProxyLogon vulnerabilities to encrypt servers. Specifically, over the weekend, security researcher Marcus Hutchins, also known as MalwareTechBlog , tweeted that malicious actors were compromising Microsoft Exchange servers via ProxyLogon vulnerabilities to deploy ransomware.
Read also: DearCry ransomware: Targets unpatched Microsoft Exchange servers
Based on logs from honeypots , Hutchins reported that malicious actors exploited the vulnerabilities to execute a PowerShell script that downloads the ransomware executable from “yuuuuu44[.] Com” and then transfers it to other computers on the network.

Based on submissions to the ransomware site ID Ransomware, victims' devices were encrypted as part of the Black Kingdom campaign, with the first submissions appearing on March 18th.
Michael Gillespie, creator of the ID Ransomware, told BleepingComputer that his system has seen over 30 unique submissions to his system, with many being submitted directly from mail servers.
The victims are located in Greece, the US, Canada, Austria, Switzerland, Russia, France, Israel, the UK, Italy, Germany, Australia and Croatia.

When encrypting devices, the ransomware encrypts files using random extensions and then creates a ransom note named decrypt_file.TxT. Hutchins noted that he saw a different ransom note named ReadMe.txt that uses different text.

BleepingComputer has seen ransom notes demanding $10,000 in Bitcoin and using the same Bitcoin address (1Lf8ZzcEhhRiXpk6YNQFpCJcUisiXb34FT) for payment. This Bitcoin address only received one payment on March 18.

Another ransomware known as BlackKingdom was used in attacks that took place in June 2020, when hackers breached corporate networks by exploiting vulnerabilities in Pulse VPN.
See also: Black Kingdom ransomware compromises networks with Pulse VPN flaws
While it has not yet been confirmed whether the recent attacks and those from summer 2020 use the same ransomware, Hutchins said the current ransomware executable is a Python script compiled into a Windows executable. The Black Kingdom ransomware from June 2020 was also coded in Python.
For victims of the recent Black Kingdom attacks, cybersecurity company Emsisoft may be able to provide assistance with file recovery.

Black Kingdom is the second confirmed ransomware targeting Microsoft Exchange ProxyLogon vulnerabilities. The first was DearCry ransomware, which was used in a limited number of attacks earlier this month.
Suggestion: Acer: REvil ransomware gang demands $50,000,000 ransom!
Recently, the world's 6th largest electronics manufacturer "Acer" was attacked by REvil ransomware which is believed to have been carried out by exploiting ProxyLogon vulnerabilities. However, this has not been confirmed so far.
Information source: bleepingcomputer.com
