The cybersecurity landscape continues to evolve as new ransomware variants emerge from the remnants of previous campaigns. Midnight ransomware is one such development, drawing significant inspiration from the infamous Babuk ransomware that first appeared in early 2021.

Like its predecessor, Midnight uses sophisticated encryption techniques and targeted file selection strategies to maximize damage to infected systems. However, what sets this particular variant apart is the inadvertent introduction of cryptographic weaknesses that have created a rare opportunity for victims to recover their data without paying a ransom.
See also: Cl0p Ransomware Exploits New 0-Day Vulnerabilities
From Babuk to Midnight ransomware
The path from Babuk to Midnight traces back to 2021, when Babuk's operators suddenly ceased operations and released their full source code, triggering a wave of new ransomware (based on that source code).
GenDigital security analysts and researchers identified Midnight as one such development, noting that while the malware retains the core architecture of Babuk, it incorporates modified encryption schemes that inadvertently undermine file protection .
Decryption tool
This discovery proved crucial in developing a functional decryption tool, turning what could have been a catastrophic situation into a recoverable one for the affected organizations.

The technical implementation of Midnight reveals the source of its vulnerability. The ransomware uses ChaCha20 to encrypt file contents, while using RSA encryption to protect ChaCha20 keys.
See also: October 2025: Increase in phishing and ransomware attacks
The RSA-encrypted key and its corresponding SHA256 hash are added directly to the end of each encrypted file, maintaining consistent formatting across all known samples. This design choice, while simplifying the attack mechanism, creates predictable patterns that security researchers successfully exploited when developing the decryption tool.
Midnight ransomware demonstrates operational flexibility through command-line parameters that control its behavior. The /e adds file extensions such as .Midnight to the contents of files, rather than directly modifying the file names. The /n allows encryption of network-attached volumes, while –paths=PATHS targets specific directories for selective encryption.
Early variants prioritized high-value targets, such as databases, backups, and files with extensions such as .sql, .mdf, .bak, and .dbf. More recent versions have expanded their scope, encrypting almost all file types except executable files such as .exe, .dll, and .msi.
See also: Increase in ransomware attacks on European organizations

Affected systems display characteristic indicators, such as ransom notes titled “How To Restore Your Files.txt”, .Midnight or .endpoint file extensions , and a mutex named “Mutexisfunnylocal” that prevents multiple instances of malware from executing simultaneously.
Organizations that recognize these characteristics can immediately implement mitigation measures and leverage available decryption tools to restore their systems without giving in to the attackers' demands.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
