#Midnight
Incident/Operation
2026-04-16 • 국내 중소기업 대상 신규 랜섬웨어 범죄 확산에 따른 보안 권고문
Midnight, later known as EndPoint, is a Babuk-derived ransomware family targeting Windows, ESXi, and NAS environments. From late 2025 into 2026 it affected multiple South Korean small and midsize organizations, especially manufacturers, after operators used malicious business-themed emails, remote-access malware, and compromised IT service relationships to expand into customer networks. It supports double extortion through data theft and encryption, terminates business and security processes, disables backup services, deletes shadow copies, and uses fast partial-file encryption. Encrypted files receive the .endpoint extension, and ransom notes direct victims to contact the operators.
-
4
Tagged Reports
-
3
Unique Authors
-
48
Active Days