News: 1619128674

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

If you have a QNAP NAS, stop what you're doing right now and install its latest updates. Do it before Qlocker gets you

(2021/04/22)


QNAP has urged its customers to install and run its latest firmware and malware removal tools on their NAS boxes amid a surge in ransomware infections.

Two file-scrambling nasties, Qlocker and eCh0raix, are said to be tearing through vulnerable QNAP storage equipment, encrypting data and demanding ransoms to restore the information.

[1]

In response, QNAP [2]said on Thursday users should do the following to avoid falling victim:

Install the latest software updates for the Multimedia Console, Media Streaming Add-on, and Hybrid Backup Sync apps on their QNAP NAS gear to close off vulnerabilities that can be exploited by ransomware to infect devices.

Install the latest Malware Remover tool from QNAP, and run a malware scan. The manufacturer said it has "released an updated version of Malware Remover for operating systems such as QTS and QuTS hero to address the ransomware attack."

Change the network port of the web-based user interface away from the default of 8080, presumably to mitigate future attacks.

Make sure they use strong, unique passwords that can't easily be brute-forced or guessed.

If possible, follow the 3-2-1 rule on backups: have at least three good copies of your documents stored on at least two types of media, at least one of which is off-site.

[3]

QNAP also warned:

If user data is encrypted or being encrypted, the NAS must not be shut down. Users should run a malware scan with the latest Malware Remover version immediately, and then contact QNAP Technical Support at [4]service.qnap.com .

How exactly is the ransomware getting onto people's network-attached storage systems? Well, look no further than these three critical vulnerabilities that QNAP patched this month and highlighted today in its warning to customers:

[5]CVE-2020-36195 aka QSA-21-11 : An SQL injection flaw in the in Multimedia Console and the Media Streaming add-on that can be exploited to ultimately gain control of the box. This was patched on April 16, just days before the latest ransomware outbreak kicked off.

[6]CVE-2021-28799 aka QSA-21-13 : Hard-coded login credentials were found and removed in HBS 3 Hybrid Backup Sync. If you know these creds, you can gain control of the device via this backdoor access. Though its advisory states it was released today, it was actually patched in version 16.0.0415 released on April 16.

[7]CVE-2020-2509 aka QSA-21-05 : A command-injection vulnerability in QTS and QuTS hero that can be exploited to seize control of a box. This was also patched on April 16.

Plus don't forget [8]all the previous holes in QNAP's products.

The Qlocker plague this month, described as " [9]massive " by the malware trackers at Bleeping Computing, leaves victims with their files stored in encrypted and password-protected 7zip archives and a note demanding 0.01 Bitcoins for the necessary passphrase to unlock the data.

[10]

It's interesting to note that 21-year-old Stanford student and infosec resercher Jack Cable found a flaw in the extortionware's backend that could be used to decrypt Qlocker-scrambled data, and [11]via Twitter discretely helped victims restore their files until the malware's masterminds caught wind and fixed the issue, CyberScoop [12]reported . ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIHx9iHgAjjPQkSJBuYhfQAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.qnap.com/en/news/2021/response-to-qlocker-ransomware-attacks-take-actions-to-secure-qnap-nas

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIHx9iHgAjjPQkSJBuYhfQAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://service.qnap.com/

[5] https://www.qnap.com/en/security-advisory/qsa-21-11

[6] https://www.qnap.com/en/security-advisory/qsa-21-13

[7] https://www.qnap.com/de-de/security-advisory/qsa-21-05

[8] https://www.theregister.com/2021/04/02/qnap_bug_nas/

[9] https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIHx9iHgAjjPQkSJBuYhfQAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://twitter.com/jackhcable/status/1385064776435310593

[12] https://www.cyberscoop.com/jack-cable-qlocker-ransomware-recovery/

[13] https://whitepapers.theregister.com/

"slackware users don't matter. in my experience, slackware users are
either clueless newbies who will have trouble even with tar, or they are
rabid do-it-yourselfers who wouldn't install someone else's pre-compiled
binary even if they were paid to do it."