Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

US Charges Yemeni Man for Black Kingdom Ransomware Attacks

Rami Khaled Ahmed, a 36-year-old from Yemen, has been charged for launching ransomware attacks between 2021 and 2023.

A 36-year-old Yemeni national has been charged by the United States over the ransomware attacks he allegedly launched against organizations in the US and elsewhere.

The suspect, Rami Khaled Ahmed, is believed to be behind Black Kingdom ransomware attacks. Authorities said he delivered his malware to roughly 1,500 systems, including ones belonging to schools, hospitals and businesses. 

He has been charged with conspiracy, intentional damage to a protected computer, and threatening damage to a protected computer. 

He faces up to five years in prison for each charge. However, he is believed to be located in Yemen and it remains to be seen if he will ever be prosecuted in the United States. 

According to the DoJ, Ahmed developed and deployed the Black Kingdom ransomware. The charges focus on attacks launched by the Yemeni national and others between March 2021 and June 2023.

Black Kingdom, aka Pydomer, made headlines in 2020 and 2021, when it targeted systems through the exploitation of Microsoft Exchange and Pulse Secure VPN vulnerabilities. 

Advertisement. Scroll to continue reading.

While the ransom note dropped by Black Kingdom on compromised systems mentioned data theft, the ransomware appears to have focused on encrypting files. Black Kingdom does not appear to have had a leak website to name victims and leak stolen data.

Security experts noted back in mid-2021 that the development of the Black Kingdom malware seemed amateurish and it was possible to recover encrypted files without paying a ransom. 

The Black Kingdom ransomware has not made any headlines since 2021. 

Related: LockBit Ransomware Mastermind Unmasked, Charged

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: Authorities Disrupt 8Base Ransomware, Arrest Four Russian Operators

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.