Blog Layout

QNAP Still Dealing With Attacks On NAS Devices

sccomputerguys • Dec 24, 2021

QNAP has recently warned its customers of an ongoing campaign that is targeting QNAP NAS (Network Attached Storage) devices and infecting them with cryptomining malware.  This particular campaign is deploying software designed to mine Bitcoin and using your computing power to generate profits for them.  If you are infected, you'll see a new process running on your system named "OOM_Reaper."

While it's certainly not the direst threat you can face the malware will utilize up to 50 percent of your system's processing power while mimicking a kernel process with a PID higher than 1000.

If you find that you are already infected, here are the steps the company recommends taking to rid yourself of the malware:

  • Update QTS or QuTS hero to the latest version.
  • Install and update Malware Remover to the latest version.
  • Use stronger passwords for your administrator and other user accounts.
  • Update all installed applications to their latest versions.
  • Do not expose your NAS to the internet, or avoid using default system port numbers 443 and 8080.

The company has really been struggling this year  as they have been targeted by an unusual surge in attacks against them and the equipment they sell.  In January QNAP urged their users to defend themselves from a nasty malware attack that rendered their NAS devices unusable after spawning rogue processes that would soak up most of the target system's processing power. Then in March the company faced a similar cryptomining campaign which installed a miner called UnityMiner.

Before that beginning in May of 2019 and continuing intermittently until June of 2020 QNAP users faced a spate of eChoraix ransomware attacks which came to also be known as QNAPCrypt.

All that to say that if you're a QNAP customer you're probably already familiar with threats on the landscape. If you're not doing so already be sure to head to the company's website and review their FAQ page which lists current best practices relating to security.

By sccomputerguys 22 Jul, 2022
Do you own one or more of the following products made by Cisco? The RV110W Wireless-N VPN Firewall The RV130 VPN Router The RV130W Wireless-N Multifunction VPN Router The RV215W Wireless-N VPN ...
By sccomputerguys 21 Jul, 2022
Do you use Microsoft Teams?  If so, you'll be thrilled to know that the Redmond Giant is continuing to pour resources into improving the software with a specific focus on audio and ...
By sccomputerguys 20 Jul, 2022
Corporate branding can be worth its weight in gold and certain images are absolutely iconic.  The Golden Arches, the Nike "swoosh," and Apple's Apple all come to mind. Logo images give companies ...
By sccomputerguys 19 Jul, 2022
Remember the Heartbleed scare we had a couple years back?  It was a nasty side-channel attack that was somewhat exotic and difficult to pull off, and it was absolutely devastating and sent ...
By sccomputerguys 18 Jul, 2022
Microsoft Exchange servers are once more in the crosshairs of hackers around the world.  Most recently, hacking groups have been specifically targeting them to deploy BlackCat ransomware. As is common among ransomware ...
By sccomputerguys 16 Jul, 2022
If you grew up in the days before the internet, it's absolutely staggering to think of all the ways that mobile technology has changed our lives (and mostly for the better). Remember ...
By sccomputerguys 15 Jul, 2022
It may seem as though Internet Explorer is the browser that will not die, but according to Microsoft, it is now a step closer to breathing its last virtual breath. Microsoft has ...
By sccomputerguys 14 Jul, 2022
If you're involved with IT Security at any level and if your network includes Linux servers, keep a watchful eye out for the new Panchan botnet. It first appeared in the wilds ...
By sccomputerguys 13 Jul, 2022
These days, companies spend significant sums of money to protect themselves from cyber criminals.  The threat matrix is vast, and attacks can come from almost any quarter. That is why many companies ...
By sccomputerguys 12 Jul, 2022
Do you receive healthcare of any kind from Kaiser Permanente?  If so, be aware that they recently published a data breach notification indicating that an unidentified attacker accessed an email account that ...
More Posts
Share by: