The ransomware is coded in Python and compiled to an executable using PyInstaller it supports two encryption modes: one generated dynamically and one using a hardcoded key. The complexity and sophistication of the Black Kingdom family cannot bear a comparison with other Ransomware-as-a-Service (RaaS) or Big Game Hunting (BGH) families. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
KasperskyEndpoint Security for Business Select.Kaspersky Internet Security for Android.