Norton has released a free decryption tool for the Midnight ransomware strain after researchers at Gen Digital identified a critical vulnerability in the ransomware's encryption implementation. Midnight, which is based on the leaked Babuk ransomware source code, attempted to enhance its encryption by integrating ChaCha20 and RSA algorithms, but a flaw in the RSA key usage allowed researchers to develop a practical method for partial decryption and data recovery. The ransomware targets most file types except for executables such as .exe, .dll, and .msi, and appends .Midnight or .endpoint extensions to encrypted files. Victims typically find a ransom note referencing file restoration and may also see debug log files created by the malware.
The decryptor, now publicly available, enables organizations and individuals affected by Midnight ransomware to restore their files without paying a ransom. Security experts advise users to retain backup copies of their data to ensure smooth restoration and to use the decryptor as a safe recovery option. The Midnight ransomware's rapid file encryption, based on file size, was intended to improve attack efficiency but ultimately introduced the cryptographic weakness that led to its defeat. This development highlights the risks ransomware operators face when modifying existing malware frameworks and the importance of robust cryptographic implementation.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Norton publicly released a free decryptor for Midnight ransomware, making the recovery tool available to affected organizations and users. A follow-up report the next day confirmed the ransomware had been successfully decrypted.
Researchers at Norton developed a working decryptor for the novel Midnight ransomware, enabling victims to recover encrypted files without paying. This is the core technical breakthrough reported across the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.