국내 중소기업 대상 신규 랜섬웨어(Midnight, Endpoint) 감염 확산에 따른 보안 권고문 배포

2026-04-16 KRNPA Security advisory issued due to spread of new ransomware infections (Midnight, Endpoint) targeting domestic SMEs

https://www.police.go.kr/user/bbs/BD_selectBbs.do?q_bbsCode=1002&q_bbscttSn=20260416133126296

Thumbnail for 국내 중소기업 대상 신규 랜섬웨어(Midnight, Endpoint) 감염 확산에 따른 보안 권고문 배포

South Korean authorities warn that Midnight and Endpoint ransomware infections have been observed against domestic SMEs, especially manufacturers, with additional cases in retail, energy, and public-sector environments. The attackers first compromise IT system integration and maintenance providers, then abuse stolen information and trusted customer relationships to expand into client companies. The infection chain begins with malicious emails disguised as quotation requests, job applications, consulting discussions, or security guidance; opened attachments install remote-control malware and enable theft of internal and account data before ransomware deployment. The campaign uses double extortion by stealing data before encryption and threatening disclosure, with ransom demands reportedly around 1% of victim revenue. The advisory emphasizes email filtering, remote-access controls, MFA, credential hygiene, offline backups, script restrictions, and EDR/XDR coverage to reduce spread through supplier trust paths.

Related Reports

« Back