새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석

2026-06-02 Ahnlab Analysis of Endpoint (Midnight) Ransomware: An Encryption Guest That Arrived at Dawn

https://asec.ahnlab.com/ko/93931/

Thumbnail for 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석

EndPoint, formerly known as Midnight, is assessed as a Babuk-derived ransomware variant that targets Windows as well as ESXi and NAS environments and combines file encryption with data-theft extortion. The malware supports path and network-share scoped encryption, stops database/office/mail processes, deletes volume shadow copies with vssadmin, and forcibly stops backup or security services including Veeam, Sophos, and Acronis. It uses ChaCha20 for file encryption, protects session keys with custom RSA public-key operations, applies partial encryption based on file size, appends footer metadata, and uses the mutex Mutexisfunnylocal to prevent duplicate execution. AhnLab notes that a past ransom-note email, [email protected], impersonated an East Asia Institute director and was identified as used by a North Korea-linked actor after 2024.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aa8a043fd3d64fc96864cf5361bbb82… 2026-05-20 2026-06-02
HASH dd9de77c6e17093b0b2150b3f0c66e8… 2026-05-20 2026-06-02
HASH 1e58448808006de410ddb31a4d6ff82… 2026-05-20 2026-06-02
HASH 3d9a71cfec82fef531227465f40d910… 2026-05-20 2026-06-02
EMAIL [email protected] 2026-05-20 2026-06-02

Related Reports

« Back