Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis
2026-05-20 • Ahnlab •
EndPoint, formerly known as Midnight, is a Babuk-derived ransomware family that targets Windows, ESXi, and NAS environments and uses double extortion through encryption and data-leak threats. The malware supports argument-controlled encryption scope, deletes volume shadow copies, stops backup and security services, uses ChaCha20 with custom RSA key protection, and applies partial encryption to improve speed. AhnLab notes that a previously observed ransom note used `[email protected]`, an account identified as used by North Korea-linked threat actors since 2024, but the report stops short of attributing EndPoint itself to a specific DPRK actor. The report provides four MD5 hashes and defensive guidance focused on isolated backups, recovery testing, patching, and strong authentication.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aa8a043fd3d64fc96864cf5361bbb82… | 2026-05-20 | 2026-06-02 |
| HASH | dd9de77c6e17093b0b2150b3f0c66e8… | 2026-05-20 | 2026-06-02 |
| HASH | 1e58448808006de410ddb31a4d6ff82… | 2026-05-20 | 2026-06-02 |
| HASH | 3d9a71cfec82fef531227465f40d910… | 2026-05-20 | 2026-06-02 |
| [email protected] | 2026-05-20 | 2026-06-02 |