Netskope Threat Labs

BlackKingdom

ATP Sandbox Adv. HeuristicsAV

BlackKingdom (a.k.a. Black Kingdom) is a ransomware family that targeted organizations around the world, including through exploitation of vulnerable Pulse Secure VPN servers. Its operators demanded relatively small ransoms and deployed the encryptor with little sophistication, which researchers connected to financially motivated actors exploiting common edge device flaws.

First seen
February 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.Ransom.BlackKingdom.FFFFFFFE
Generic.Ransom.BlackKingdom.00E3CA35
Generic.Ransom.BlackKingdom.0369AD92
Generic.Ransom.BlackKingdom.07CA39A1
Generic.Ransom.BlackKingdom.09B84C68
Generic.Ransom.BlackKingdom.09D97F4D
Generic.Ransom.BlackKingdom.09F399D3
Generic.Ransom.BlackKingdom.0A8A983F
Generic.Ransom.BlackKingdom.0DC70541
Generic.Ransom.BlackKingdom.0DD572A9