QNAP Warns Customers Of Recent Wave Of Ransomware Attacks

QNAP Warns Customers Of Recent Wave Of Ransomware Attacks

QNAP has issued an advisory about a recent wave of ransomware attacks targeting its NAS storage devices and encrypting files.

Last week, BleepingComputer broke the story of ransomware known as AgeLocker attacking publicly exposed QNAP NAS devices.

AgeLocker ransom note

The ransomware gets its name from its use of the encryption algorithm called Actually Good Encryption (AGE) when encrypting files.

At the time of our reporting, it was not known how the attackers were gaining access to QNAP devices, but a new security advisory by QNAP indicates that the attackers are targeting older vulnerable versions of Photo Station.

Also Read: Personal Data Websites: 3 Things That You Must Be Informed

“QNAP Product Security Incident Response Team (PSIRT) has found evidence that the ransomware may attack earlier versions of Photo Station. We are thoroughly investigating the case and will release more information as soon as possible,” QNAP stated in an advisory.

Photo Station is a built-in application that allows users to upload photos to their NAS device, create albums, and remotely view them.

QNAP had previously warned of another ransomware called eCh0raix that also targeted vulnerabilities in the app.

How to secure your QNAP device

To secure your NAS device, QNAP advises all owners to upgrade to the latest QTS version and update all installed applications, especially Photo Station.

To install the latest QTS update, you can perform the following steps:

  1. Log on to QTS as an administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.

You can also manually update the QTS firmware by going to Support > Download Center and downloading the manual update for your specific device.

To update all the apps on your QNAP devices, please follow these steps:

  1. Log on to QTS as an administrator.
  2. Go to App Center.
  3. Select My Apps.
  4. Beside Install Updates, click All.
    A confirmation message appears.
  5. Click OK.
    QTS updates all your installed applications to their latest versions.

In addition to QNAP’s suggestions, it is also suggested that you do not expose the QTS Administration page or QTS applications to the Internet.

If an attacker cannot gain access to these pages, they will not be able to exploit any known vulnerabilities to gain access to your device.

Also Read: 5 Assessment Tools To Find The Right Professional Fit

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago