Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis
2026-05-20 • Ahnlab •
EndPoint, formerly known as Midnight, is a Babuk-derived ransomware family that targets Windows, ESXi, and NAS environments and uses double extortion through encryption and data-leak threats. The malware supports argument-controlled encryption scope, deletes volume shadow copies, stops backup and security services, uses ChaCha20 with custom RSA key protection, and applies partial encryption to improve speed. AhnLab notes that a previously observed ransom note used `[email protected]`, an account identified as used by North Korea-linked threat actors since 2024, but the report stops short of attributing EndPoint itself to a specific DPRK actor. The report provides four MD5 hashes and defensive guidance focused on isolated backups, recovery testing, patching, and strong authentication.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e82bcf417f51acc6b2d8a94ceabd5e36 | 2026-06-02 | 2026-06-02 |
| HASH | c00cc937e064946ee42776cfe80754d7 | 2026-06-02 | 2026-06-02 |
| HASH | b77ad606ba04d2d0077130679a257c96 | 2026-06-02 | 2026-06-02 |
| HASH | 34be5e70f1260da87096b80dc7b026ac | 2026-06-02 | 2026-06-02 |
| [email protected] | 2026-06-02 | 2026-06-02 |