새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석

2026-06-02 Ahnlab Analysis of Endpoint (Midnight) Ransomware: An Encryption Guest That Arrived at Dawn

https://asec.ahnlab.com/ko/93931/

Thumbnail for 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석

EndPoint, formerly known as Midnight, is assessed as a Babuk-derived ransomware variant that targets Windows as well as ESXi and NAS environments and combines file encryption with data-theft extortion. The malware supports path and network-share scoped encryption, stops database/office/mail processes, deletes volume shadow copies with vssadmin, and forcibly stops backup or security services including Veeam, Sophos, and Acronis. It uses ChaCha20 for file encryption, protects session keys with custom RSA public-key operations, applies partial encryption based on file size, appends footer metadata, and uses the mutex Mutexisfunnylocal to prevent duplicate execution. AhnLab notes that a past ransom-note email, [email protected], impersonated an East Asia Institute director and was identified as used by a North Korea-linked actor after 2024.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e82bcf417f51acc6b2d8a94ceabd5e36 2026-06-02 2026-06-02
HASH c00cc937e064946ee42776cfe80754d7 2026-06-02 2026-06-02
HASH b77ad606ba04d2d0077130679a257c96 2026-06-02 2026-06-02
HASH 34be5e70f1260da87096b80dc7b026ac 2026-06-02 2026-06-02
EMAIL [email protected] 2026-06-02 2026-06-02

Related Reports

« Back