QNAP NAS is a device developed by QNAP Systems, which is a Taiwanese corporation specializing in developing network attached storage devices such as NAS.
The NAS can be directly connected to the network users, in most cases, a NAS consists of multiple hard drives organized as a RAID system. This type of device is perfect for businesses that have a high flow of data.
Given these features provided by QNAP on their NAS devices, ransomware groups have been focusing their attacks on QNAP NAS. The groups that have been prominent with these attacks are QNAPCrypt and DeadBolt.
Ransomware is malware designed to encrypt all data stored on a system, blocking access to files and charging a high fee to release the decryption key.
To access the victim’s system the groups use numerous strategies such as virus-ridden websites, malicious emails, illicit programs, Phishing, brute force attacks, employee grooming, and perhaps most worryingly, using vulnerabilities in the QNAP NAS itself.
The DeadBolt ransomware claims to have found an hour 0 vulnerability, this name is given to vulnerabilities discovered that are unknown by its developers. And from what it seems, in fact this vulnerability is real.
QNAP itself has published an alert about the attacks made by the group, instructing its users not to connect the NAS directly to the Internet but to a Firewall for the protection of the device.
DeadBolt is selling the information about this vulnerability on the Dark Web for 50 Bitcoins, if this vulnerability becomes known to other groups, the ransomware attacks on QNAP NAS may increase sharply.
In case of successful ransomware attacks, all files and backups that are connected to the network will be encrypted, and the group will charge a high fee to decrypt the affected files.
Digital Recovery provides an option to paying the ransom, the recovery of data encrypted by ransomware. Through its solutions from Digital Recovery, files can be recovered and thus the company’s system restored. All this, without any kind of negotiation with the criminals.