Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

US Charges Yemeni Man for Black Kingdom Ransomware Attacks

Rami Khaled Ahmed, a 36-year-old from Yemen, has been charged for launching ransomware attacks between 2021 and 2023.

A 36-year-old Yemeni national has been charged by the United States over the ransomware attacks he allegedly launched against organizations in the US and elsewhere.

The suspect, Rami Khaled Ahmed, is believed to be behind Black Kingdom ransomware attacks. Authorities said he delivered his malware to roughly 1,500 systems, including ones belonging to schools, hospitals and businesses. 

He has been charged with conspiracy, intentional damage to a protected computer, and threatening damage to a protected computer. 

He faces up to five years in prison for each charge. However, he is believed to be located in Yemen and it remains to be seen if he will ever be prosecuted in the United States. 

According to the DoJ, Ahmed developed and deployed the Black Kingdom ransomware. The charges focus on attacks launched by the Yemeni national and others between March 2021 and June 2023.

Black Kingdom, aka Pydomer, made headlines in 2020 and 2021, when it targeted systems through the exploitation of Microsoft Exchange and Pulse Secure VPN vulnerabilities. 

Advertisement. Scroll to continue reading.

While the ransom note dropped by Black Kingdom on compromised systems mentioned data theft, the ransomware appears to have focused on encrypting files. Black Kingdom does not appear to have had a leak website to name victims and leak stolen data.

Security experts noted back in mid-2021 that the development of the Black Kingdom malware seemed amateurish and it was possible to recover encrypted files without paying a ransom. 

The Black Kingdom ransomware has not made any headlines since 2021. 

Related: LockBit Ransomware Mastermind Unmasked, Charged

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: Authorities Disrupt 8Base Ransomware, Arrest Four Russian Operators

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.