Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis

2026-05-20 Ahnlab

https://asec.ahnlab.com/en/93932/

Thumbnail for Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis

EndPoint, formerly known as Midnight, is a Babuk-derived ransomware family that targets Windows, ESXi, and NAS environments and uses double extortion through encryption and data-leak threats. The malware supports argument-controlled encryption scope, deletes volume shadow copies, stops backup and security services, uses ChaCha20 with custom RSA key protection, and applies partial encryption to improve speed. AhnLab notes that a previously observed ransom note used `[email protected]`, an account identified as used by North Korea-linked threat actors since 2024, but the report stops short of attributing EndPoint itself to a specific DPRK actor. The report provides four MD5 hashes and defensive guidance focused on isolated backups, recovery testing, patching, and strong authentication.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e82bcf417f51acc6b2d8a94ceabd5e36 2026-06-02 2026-06-02
HASH c00cc937e064946ee42776cfe80754d7 2026-06-02 2026-06-02
HASH b77ad606ba04d2d0077130679a257c96 2026-06-02 2026-06-02
HASH 34be5e70f1260da87096b80dc7b026ac 2026-06-02 2026-06-02
EMAIL [email protected] 2026-06-02 2026-06-02

Related Reports

« Back