Stellar Logo
  • For Individuals
    Back to main menu

    For Individual

    • Windows Data Recovery

      Recovers lost or deleted Office documents, emails, presentations & multimedia files.

      • Free
      • Standard
      • Professional
      • Premium
    • Mac Data Recovery

      Recovers deleted files, photos, videos etc. on Mac.

      • Free
      • Standard
      • Professional
      • Premium
    • Photo Recovery

      Recover photos, videos, & audio files from all cameras and storage on Windows or Mac.

      • Standard
      • Professional
      • Premium
    • iPhone Data Recovery

      Recover deleted photos, videos, contacts, messages etc. directly from iPhone & iPad.

      • Recover
      • Erase
      • Toolkit
    • Video Repair

      Repair multiple corrupt videos in one go. Supports MP4, MOV & other formats.

      • Standard
      • Premium
    • Photo Repair

      Repair multiple corrupt photos in one go. Supports JPEG & other formats.

      • Standard
      • Professional
      • Premium
  • For Business
    Back to main menu

    For Business

    • Email Repair
      • Exchange Repair Repair corrupt EDB file & export mailboxes to Live Exchange or Office 365
      • Outlook PST Repair Repair corrupt PST & recover all mailbox items including deleted emails & contacts
      • OLM Repair Repair Outlook for Mac (OLM) 2011 & 2016 backup files & recover all mailbox items
      • Exchange Toolkit Repair EDB & Exchange backup file to restore mailboxes, convert OST to PST, & convert EDB to PST
      • Active Directory Repair Repair corrupt Active Directory database (Ntds.dit file) & extract all objects in original form
    • Email Converter
      • EDB to PST Convert online & offline EDB file & extract all mailbox items including Public Folders in PST
      • OST to PST Convert inaccessible OST file & extract all mailbox items including deleted emails in PST
      • NSF to PSTConvert IBM Notes NSF file & export all mailbox items including emails & attachments to PST
      • MBOX to PSTConvert MBOX file of Thunderbird, Entourage & other clients, & export mailbox data to PST
      • OLM to PST Convert Outlook for Mac Data File (OLM) & export all mailbox data to PST in original form
      • GroupWise to PST Convert GroupWise mail & export all mailbox items - emails, attachments, etc. - to PST
      • EML to PSTConvert Windows Live Mail (EML) file & export mailbox data - emails, attachments, etc. - to PST
      • Office 365 to PSTConnect to Office 365 account & export mailbox data to PST and various other formats
      • Migrator for Office 365Quickly migrate Outlook data files(OST/PST) directly to Office 365 or Live Exchange
    • File Repair
      • SQL Repair Repair corrupt .mdf & .ndf files and recover all database components in original form
      • Access RepairRepair corrupt .ACCDB and .MDB files & recover all records & objects in a new database
      • QuickBooks RepairRepair corrupt QuickBooks® data file & recover all file components in original form
      • MySQL RepairRepair MyISAM & InnoDB tables and recover all objects - keys, views, tables, triggers, etc.
      • Excel RepairRepair corrupt Excel (.XLS & .XLSX) files and recover tables, charts, chart sheet, etc.
      • BKF RepairRepair corrupt backup (BKF, ZIP, VHDX and .FD) files and restore complete data
      • Database ConverterInterconvert MS SQL, MySQL, SQLite, and SQL Anywhere database files
      • PowerPoint RepairRepair corrupt PPT files and restore tables, header, footer, & charts, etc. like new
      • File Repair ToolkitRepair corrupt Excel, PowerPoint, Word & PDF files & restore data to original form
    • Data Recovery & Erasure
      • Data RecoveryRecover lost or deleted data from HDD, SSD, external USB drive, RAID & more.
      • Tape Data RecoveryRetrives data from all types and capacities of tape drives including LTO 1, LTO 2, LTO 3, & others.
      • Virtual Machine RecoveryRecover documents, multimedia files, and database files from any virtual machine
      • File ErasurePermanently wipe files and folders, and erase traces of apps and Internet activity.
      • Mobile ErasureCertified and permanent data erasure software for iPhones, iPads, & Android devices
      • Drive ErasureCertified and permanent data erasure software for HDD, SSD, & other storage media
    • Toolkit
      • Exchange Toolkit5-in-1 software toolkit to recover Exchange database, convert EDB to PST, convert OST to PST, restore Exchange backup, and reset Windows Server password.
      • Outlook ToolkitComprehensive software suite to repair PST files, merge PST files, eliminate duplicate emails, compact PST files, and recover lost or forgotten Outlook passwords.
      • File Repair ToolkitPowerful file repair utility to fix corrupt Word, PowerPoint, and Excel documents created in Microsoft Office. It also repairs corrupt PDF files and recovers all objects.
      • MS SQL Toolkit5-in-1 software toolkit to repair corrupt SQL database, restore database from corrupt backup, reset database password, analyze SQL logs, & interconvert databases.
      • Data Recovery ToolkitSoftware helps to recovers deleted data from Windows, Mac and Linux storage devices. Also supports recovery from RAIDs & Virtual Drives.
    • Forensic
      • Email ForensicAdvanced email forensic solution for cyber experts to audit, analyze, or investigate emails & gather evidences.
      • Log Analyzer for MySQLAnalyze forensic details of MySQL server database log files such as Redo, General Query, and Binary Log.
      • Exchange AuditorExchange Server monitoring solution to automate audits, scans and generate reports ìn real-time.
      • Log Analyzer for MS SQLTrack & analyze MS SQL Server database transactions log files.
  • Our Partners
  • Lab Services
  • Support
  • About

Trending Searches

Data Recovery

Photo Recovery

Video Repair

iPhone Data Recovery

File Erasure Software

Exchange Repair

OST to PST

PST Repair

Raid Recovery

MS SQL Repair

Exchange Server 4 minute read

How to Recover Exchange Server after Black KingDom Ransomware Attack?

Ravi Singh
Written By
Ravi Singh
Shaun Hardneck
Approved By
Shaun Hardneck
stellar calander
Updated on
March 16th, 2023

Contents

  • Black KingDom Ransomware – How it Works 
  • Steps to Eliminate and Prevent Black KingDom Ransomware Attack
  • Conclusion

Black KingDom is a ransomware variant, which targets on-premises Exchange servers that are not updated and are exposed to ProxyLogon vulnerabilities. In this post, we discuss about the Black KingDom ransomware, ways to safeguard your Exchange server against such malicious attacks, and methods to recover Exchange server after such attacks.

Black KingDom Ransomware – How it Works 

Black KingDom ransomware, also known as DemonWare or GAmmAWare, was first detected in February 2020. Earlier, it was used to attack corporate networks using Pulse VPN. The threat actors are now using the ransomware to target and attack the vulnerable Exchange servers.

Black KingDom ransomware encrypts the files on the compromised Exchange servers and adds a .DEMON extension to the encrypted filenames with a ransom note named decrypt_file.TxT or ReadMe.txt. The ransom note demands either 0.052 or 0.19 Bitcoin (equivalent to $500/ $10,000) as payment for decryption key that (according to the attackers) can help victims recover their data.

ReadMe text file
Image Source – Black Kingdom ransom note
ReadMe text sample
Image Source – Black Kingdom ransom note

The Bitcoin address 1Lf8ZzcEhhRiXpk6YNQFpCJcUisiXb34FT has received a total of 0.17300000 BTC ($9,154.35) on March 18. However, you should never pay or meet any ransom demands, as users often do not receive the promised decryption key or tool.

Steps to Eliminate and Prevent Black KingDom Ransomware Attack

You can eliminate the Black KingDom ransomware from the Exchange server by following the methods discussed below and avoid further encryption. However, removing Black KingDom ransomware may not restore the affected data or files already encrypted by ransomware.  

Step 1: Restore from Backup

If the server is infected by the Black KingDom or any other ransomware, you can set up a new server and then restore the mailboxes from the backup. But if the backup isn’t available or obsolete, the only viable option is to use an Exchange repair software, such as Stellar Repair for Exchange.

The software can help you extract mailboxes from non-encrypted Exchange databases on the affected server and export them directly to the new Exchange server. But if the ransomware encrypts the database, the tool may not work.

Step 2: Use Exchange On-Premises Mitigation Tool

Before using the Exchange repair software or manually extracting the mailboxes, you must run the Exchange On-Premises Mitigation Tool (EOMT) to check and eliminate the ransomware or any other malware from the vulnerable server.

The EOMT tool helps you check if your Exchange system is vulnerable. It addresses CVE-2021-26855 vulnerability. It is currently the most effective way to eliminate web shells and malware, including Black KingDom ransomware, deployed by the threat actors.

The steps to run EOMT tool are as follows:

  • After downloading the EOMT tool, extract the files. Copy the Security folder from the extracted files that contain the EOMT PowerShell script and save it at your desired location. We saved it in the Documents folder (see the screenshot below).
EOMT PowerShell script
  • Now open PowerShell as administrator and then enter the following command to navigate to Security/src folder location. In our case, it is:

cd C:\Users\Administrator\Documents\Security\src

PowerShell as administrator
  • Now enter the following command in PowerShell to run the EOMT.ps1 script and check if your Exchange server is vulnerable and compromised:

.\EOMT.ps1

EOMT.ps1

The script checks the server vulnerability by installing the IIS URL rewrite tool. It then runs the Microsoft Safety Scanner or MSERT in quick scan mode to find and remove threats, such as web shells and malware from the server.

 Microsoft Safety Scanner

In case you suspect or find threats in Quick Scan, it is strongly suggested that you run MSERT in Full Scan mode. Full Scan will take longer but will thoroughly scan the server and eliminate all possible threats from the server.

To run MSERT in Full Scan mode, use the following PowerShell command:

.\EOMT.ps1 -RunFullScan –DoNotRunMitigation

Step 3: Update the Server

After running the EOMT, update the Exchange server with March 2021 Exchange Security Updates. Once updated, you can use either the Exchange Admin center (EAC) or Exchange Management Shell (EMS) cmdlets to export mailboxes to PST from unaffected databases. However, this works only if the server did not crash or break after the attack.

Step 4: Restore Mailboxes on New Exchange Server

In case the Exchange server broke or crashed due to Hafnium or Black KingDom ransomware attack, you can install an Exchange repair software to export mailboxes from the remaining unencrypted Exchange databases to the new Exchange server. The software auto maps the mailboxes from the source Exchange database to the destination server and facilitates hassle-free recovery and migration of the mailboxes.

Using the software, you can restore the mailboxes on the new server more quickly and reduce downtime significantly.

Conclusion

Black KingDom is another ransomware that exploits ProxyLogon vulnerabilities to get administrator access to the Exchange server. In our previous post, we discussed the Hafnium ransomware that uses ProxyLogon exploit (CVE-2021-26855 vulnerability) to access vulnerable on-premises Exchange servers and deploy web shells to infiltrate the server. These web shells enable the threat actors to install malware or ransomware on the server.

To prevent ransomware attacks, such as the Black KingDom or Hafnium, you should immediately patch your server by installing Microsoft’s latest Exchange updates. Also, employ effective defense and backup techniques to safeguard your Exchange server against data loss due to such malicious attacks.

Also Read: How to Recover Microsoft Exchange Server after Hafnium Attack?

About The Author

Ravi Singh

Ravi Singh is a Senior Writer at Stellar®. He is an expert Tech Explainer, IoT enthusiast, and a passionate nerd with over 7 years of experience in technical writing. He writes about Microsoft Exchange, Microsoft 365, Email Migration, Linux, Windows, Mac, DIY Tech, and Smart Home. Ravi spends most of his weekends working with IoT (DIY Smart Home) devices and playing Overwatch. He is also a solo traveler who loves hiking and exploring new trails.

Best Selling Products

Stellar Repair for Exchange

Stellar Repair for Exchange

Software recommended by MVPs & Administr

Read More
Stellar Toolkit for Exchange

Stellar Toolkit for Exchange

5-in-1 suite of specialized tools, highl

Read More
Stellar Converter for EDB

Stellar Converter for EDB

Stellar Converter for EDB is a professio

Read More
Stellar Converter for OST

Stellar Converter for OST

Powerful software trusted by Microsoft M

Read More

Leave a comment Cancel reply

Your email address will not be published. Required fields are marked *

Image Captcha
Refresh Image Captcha

Enter Captcha Here :

Table of Contents    arrow

  1. Black KingDom Ransomware – How it Works 
  2. Steps to Eliminate and Prevent Black KingDom Ransomware Attack
  3. Conclusion

Categories

offer banner

Related Posts

related post
Exchange Server

Exchange DAG Cluster Service Terminated with Error 7024

Stellar Author Shelly Bhardwaj March 14, 2023 Read More
related post
Exchange Server

How to Use Remove-DatabaseAvailabilityGroupServer?

Stellar Author Eric Simson February 10, 2023 Read More
related post
Exchange Server

How to Fix the Exchange Server 2019 Upgrade Error 5506?

Stellar Author Eric Simson January 31, 2023 Read More

Free Trial for 60 Days

Technology You Can Trust A Brand Present Across The Globe

  • tuv1
  • tuv2
  • Nist
  • hipa

Stellar Official Website

Stellar Data Recovery Inc.
48 Bridge Street Metuchen,
New Jersey 08840,
United States

ALSO AVAILABLE AT

ALSO AVAILABLE AT

About

  • About us
  • Career
  • ISMS Policy
  • Privacy Policy
  • Terms of Use
  • License Policy
  • Refund Policy
  • End User License Agreement

RESOURCES

  • Blog
  • Articles
  • Product Videos
  • Knowledge Base
  • Case Studies
  • Whitepapers
  • Software Catalog

NEWS & EVENTS

  • News
  • Events

PARTNERS

  • Affiliates
  • Resellers
  • Distributors

Useful Links

  • Contact Us
  • Support
  • Special Offers
  • Student Discounts
  • Awards & Reviews
  • Downloads
  • Store
  • Sitemap

Stellar & Stellar Data Recovery are Registered Trademarks of Stellar Information Technology Pvt. Ltd. © Copyright 2023 Stellar Information Technology Pvt. Ltd. All Trademarks Acknowledged.

Follow Us Facebook Twitter Linkedin Youtube

  • Notron
  • dcma

Subscribe to our newsletter!

Its good time to subscribe and get the latest promtion

With subscribing you agree with our Terms & Conditions

This website uses cookies in order to provide you with the best possible experience and to monitor and improve the performance of the site in accordance with our cookie policy. You can reject cookies at any time in your browser settings.

cookies-cross
Got it