Overview

A new strain of eCh0raix ransomware has been discovered targeting QNAP and Synology Network Attached Storage (NAS) devices. This is not the first time that either vendor has been the target of ransomware, however it appears to be the first time that the same ransomware group has been identified as being the source.

Impact

Access to and encryption of all data on the device as well as the potential to use the device as a mechanism to pivot the attack to target other devices.

Affected Products

QNAP NAS running HBS 3 (QNAP NAS devices running HBS 2 and HBS 1.3 are not affected.)
There is no clear version of Synology NAS devices that are affected as attacks against this type of device appear to be brute force password attacks.

Vulnerability Detection

The attempted use of hard-coded and credentials in QNAP devices and the brute forcing of administrative credentials for either vendor’s device are key indicators of an attack against the devices.

Containment, Mitigations & Remediations

Palo Alto Networks’ Unit 42 security researchers are advising affected NAS owners to follow best practices to block ransomware attacks targeting their data:

  • Update device firmware to keep attacks of this nature at bay. Details about updating QNAP NAS devices against CVE-2021-28799 can be found on the QNAP website.
  • Create complex login passwords to make brute-forcing more difficult for attackers.
  • Limit connections to SOHO-connected devices from only a hard-coded list of recognized IPs to prevent network attacks used to deliver ransomware to devices.

Separately, Synology provided advice more specific to their devices, but still in-line with security best practices:

  • Use a complex and strong password and apply password strength rules to all users.
  • Create a new account in the administrator group and disable the system default “admin” account.
  • Enable Auto Block in Control Panel to block IP addresses with too many failed login attempts.
  • Run Security Advisor to make sure there is no weak password in the system.

Indicators of Compromise

Regular changes to files, resulting in different hashes, have been seen to occur on a regular basis and so the below should not just be considered in isolation.

The below IoC’s are curtesy of the Palo Alto Network’s Unit 42 Research division:

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content