Skip to content
Novel Midnight ransomware decrypted

Novel Midnight ransomware decrypted

Scworld • November 6, 2025

Norton has released a free decryption tool for the newly emergent Midnight ransomware strain after researchers from its parent firm Gen Digital discovered a vulnerability stemming from operators' attempts to accelerate and strengthen the payload's encryption capabilities, HackRead reports.

Despite building upon its Babuk ransomware -based underpinnings with the integration of ChaCha20 and RSA encryption, Midnight ransomware had faulty RSA key usage enabling partial decryption, according to researchers, who were able to convert the vulnerability into a practical recovery technique.

Further analysis of the Midnight ransomware revealed the targeting of most files, aside from .exe, .dll, and .msi, through file size-based encryption. Encrypted files are often appended with .Midnight or .endpoint extensions, while targeted systems were found to have a ransom note referencing file restoration and a debug log file, researchers added.

Organizations and users looking to use the free decryption tool have been advised to retain the backup option to ensure smooth data restoration.

Extracted Entities

Attack Types (1)

Ransomware Groups (2)