Black Kingdom ransomware operators exploit Pulse VPN flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-11510 | Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known. Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users) | |
| CVE-2019-11539 | Authenticated Command Injection in Ivanti Pulse Connect Secure and Policy Secure Ivanti/Pulse Secure Pulse Connect Secure and Pulse Policy Secure contain an OS command injection flaw (CWE-78) in the admin web interface. An authenticated attacker can send crafted requests to the administrative web interface to inject and execute arbitrary operating-system commands on the appliance. Successful exploitation gives full control of the VPN or network access control appliance, enabling data theft, persistence, and pivoting into the corporate intranet. Any organization running an affected Pulse Connect Secure (9.0RX/8.3RX/8.2RX/8.1RX) or Pulse Policy Secure (9.0RX/5.4RX/5.3RX/5.2RX/5.1RX) release is exposed, especially internet-facing VPN gateways. Exploitation is very active: the bug is in CISA's KEV, public research chained it with CVE-2019-11510 into an unauthenticated RCE chain, APT groups and Black Kingdom ransomware operators have been reported exploiting Pulse VPN flaws, and EPSS estimates a 98.5% probability of exploitation within 30 days. Do: Upgrade Pulse Connect Secure to 9.0R3.4+ (or 8.3R7.1+, 8.2R12.1+, 8.1R15.1+) and Pulse Policy Secure/Policy Secure to 9.0R3.2+ (or 5.4R7.1+, 5.3R12.1+, 5.2R12.1+, 5.1R15.1+) per vendor instructions. Restrict exposure of the admin web interface to trusted networks, rotate administrative credentials, and hunt for signs of compromise on appliances that were internet-exposed, particularly where the chained CVE-2019-11510 file-read flaw may also have been exploited. | 7.2 | 99% | KEV ransomware PoC ×2 |
| masson the order of 100,000 to several hundred thousand internet-exposed Pulse Connect Secure/Policy Secure appliances |
Full article446 words · extracted from securityaffairs.com · click to collapse

Black Kingdom ransomware operators are targeting organizations using unpatched Pulse Secure VPN software to deploy their malware.
Researchers from security firm REDTEAM reported that operators behind the Black Kingdom ransomware are targeting enterprises exploiting the CVE-2019-11510 flaw in Pulse Secure VPN software to gain access to the network.
Black Kingdom ransomware was first spotted in late February by security researcher GrujaRS. the malicious code encrypts files and appends the .DEMON extension to filenames of the encrypted documents.
Early this year, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) warned organizations that attackers continue to exploit the well known Pulse Secure VPN vulnerability tracked as CVE-2019-11510.
The CVE-2019-11510 flaw in Pulse Connect Secure is a critical arbitrary file read vulnerability.
“Unauthenticated remote attacker with network access via HTTPS can send a specially crafted URI to perform an arbitrary file reading vulnerability.” reads the advisory.
The vulnerability could be easily exploitable by using publicly available proof-of-concept code. The flaw can be used in combination with the CVE-2019-11539 remote command injection issue gain access to private VPN networks.
The vulnerability was addressed in April 2019, but many organizations delayed updating their servers.
Researchers from security firm REDTEAM discovered that the Black Kingdom ransomware establishes persistence by impersonating a legitimate scheduled task for Google Chrome. Attackers used a name that differs from the legitimate task for a single letter:
GoogleUpdateTaskMachineUSA - Black Kingdom task
GoogleUpdateTaskMachineUA - legitimate Google Chrome task
Redteam researchers published an analysis detailing TTPs and IOC for the Black Kingdom ransomware.
“Attackers gained initial access to the infrastructure via Pulse Secure VPN vulnerability [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11510]. For persistence they use a scheduled task [https://attack.mitre.org/techniques/T1053/].” reads the analysis published by Redteam. “Task name is GoogleUpdateTaskMachineUSA, which resembles a legitimate task of Google Chrome that ends with UA, not USA. “
REDTEAM researchers reported that the scheduled task runs a Base64-encoded string code in a hidden PowerShell window to fetch a script named “reverse.ps1” that establishes a reverse shell on the infected machine.
Below the content of the cversions_cache.ps1 powershell script:

The “reverse.ps1” script resides at 198.13.49[.]179, which is operated by the Choopa provider that was used by other cybercriminal gangs.
“It [198.13.49[.]179] resolves to three domains, the third one being connected to other servers in the U.S. and Italy hosting Android and cryptocurrency mining malware.” reported BleepingComputer.
- host.cutestboty.com
- keepass.cutestboty.com
- anno1119.com
Below the ransom note asking dropped by the ransomware on the infected hosts. The operators demanded $10,000 worth of Bitcoin to decrypt the files and avoid that they will be destroyed or sold.

| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Black Kingdom ransomware, ransomware)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/104789/cyber-crime/black-kingdom-ransomware-pulse-vpn.html