새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석
2026-06-02 • Ahnlab • Analysis of Endpoint (Midnight) Ransomware: An Encryption Guest That Arrived at Dawn •
EndPoint, formerly known as Midnight, is assessed as a Babuk-derived ransomware variant that targets Windows as well as ESXi and NAS environments and combines file encryption with data-theft extortion. The malware supports path and network-share scoped encryption, stops database/office/mail processes, deletes volume shadow copies with vssadmin, and forcibly stops backup or security services including Veeam, Sophos, and Acronis. It uses ChaCha20 for file encryption, protects session keys with custom RSA public-key operations, applies partial encryption based on file size, appends footer metadata, and uses the mutex Mutexisfunnylocal to prevent duplicate execution. AhnLab notes that a past ransom-note email, [email protected], impersonated an East Asia Institute director and was identified as used by a North Korea-linked actor after 2024.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e82bcf417f51acc6b2d8a94ceabd5e36 | 2026-06-02 | 2026-06-02 |
| HASH | c00cc937e064946ee42776cfe80754d7 | 2026-06-02 | 2026-06-02 |
| HASH | b77ad606ba04d2d0077130679a257c96 | 2026-06-02 | 2026-06-02 |
| HASH | 34be5e70f1260da87096b80dc7b026ac | 2026-06-02 | 2026-06-02 |
| [email protected] | 2026-06-02 | 2026-06-02 |