QNAP NAS devices around the world are being affected by a cyber attack widespread after the DeadBolt ransomware group began encrypting network-attached storage devices.
QNAP NAS users reported that their files were encrypted, with a .deadbolt file extension. Upon receiving it, they found a screen that showed a message asking them to deposit Bitcoins in a certain wallet. These cases of ransomware charging in cryptocurrencies are becoming more and more common since cryptocurrencies allow money laundering because they are difficult to trace.
Be careful if you have a QNAP NAS
The victims of this ransomware attack they received a decryption key to recover their files as part of a follow-up transaction. although there is no confirmation that paying the ransom will result in successful file decryption.
QNAP assured its customers that they can access its administration page by navigating to this link. It also promises that its product security incident response team is conducting an investigation to see how to deal with these cyberattacks.
For now they have asked users to take their devices offline and place them behind a firewall until a solution is found. The team of DeadBolt ransomware has offered to share with QNAP the zero-day vulnerability it allowed the devices, along with master keys to be sold via Bitcoin payments. So, unless it is imperative, you should disconnect your NAS from QNAP since it is not only a victim of this ransomware, but also because it has a day-one vulnerability, which means that it is exposed to other cyberattacks as soon as the exploit spreads. spread between circles black hat who want to replicate this attack.
Source: TechRadar