Overview
A new strain of eCh0raix ransomware has been discovered targeting QNAP and Synology Network Attached Storage (NAS) devices. This is not the first time that either vendor has been the target of ransomware, however it appears to be the first time that the same ransomware group has been identified as being the source.
Impact
Access to and encryption of all data on the device as well as the potential to use the device as a mechanism to pivot the attack to target other devices.
Affected Products
QNAP NAS running HBS 3 (QNAP NAS devices running HBS 2 and HBS 1.3 are not affected.)
There is no clear version of Synology NAS devices that are affected as attacks against this type of device appear to be brute force password attacks.
Vulnerability Detection
The attempted use of hard-coded and credentials in QNAP devices and the brute forcing of administrative credentials for either vendor’s device are key indicators of an attack against the devices.
Containment, Mitigations & Remediations
Palo Alto Networks’ Unit 42 security researchers are advising affected NAS owners to follow best practices to block ransomware attacks targeting their data:
- Update device firmware to keep attacks of this nature at bay. Details about updating QNAP NAS devices against CVE-2021-28799 can be found on the QNAP website.
- Create complex login passwords to make brute-forcing more difficult for attackers.
- Limit connections to SOHO-connected devices from only a hard-coded list of recognized IPs to prevent network attacks used to deliver ransomware to devices.
Separately, Synology provided advice more specific to their devices, but still in-line with security best practices:
- Use a complex and strong password and apply password strength rules to all users.
- Create a new account in the administrator group and disable the system default “admin” account.
- Enable Auto Block in Control Panel to block IP addresses with too many failed login attempts.
- Run Security Advisor to make sure there is no weak password in the system.
Indicators of Compromise
Regular changes to files, resulting in different hashes, have been seen to occur on a regular basis and so the below should not just be considered in isolation.
The below IoC’s are curtesy of the Palo Alto Network’s Unit 42 Research division:












