Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis

2026-05-20 Ahnlab

https://asec.ahnlab.com/en/93932/

Thumbnail for Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis

EndPoint, formerly known as Midnight, is a Babuk-derived ransomware family that targets Windows, ESXi, and NAS environments and uses double extortion through encryption and data-leak threats. The malware supports argument-controlled encryption scope, deletes volume shadow copies, stops backup and security services, uses ChaCha20 with custom RSA key protection, and applies partial encryption to improve speed. AhnLab notes that a previously observed ransom note used `[email protected]`, an account identified as used by North Korea-linked threat actors since 2024, but the report stops short of attributing EndPoint itself to a specific DPRK actor. The report provides four MD5 hashes and defensive guidance focused on isolated backups, recovery testing, patching, and strong authentication.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aa8a043fd3d64fc96864cf5361bbb82… 2026-05-20 2026-06-02
HASH dd9de77c6e17093b0b2150b3f0c66e8… 2026-05-20 2026-06-02
HASH 1e58448808006de410ddb31a4d6ff82… 2026-05-20 2026-06-02
HASH 3d9a71cfec82fef531227465f40d910… 2026-05-20 2026-06-02
EMAIL [email protected] 2026-05-20 2026-06-02

Related Reports

« Back