Synology NAS Ransomware | Guide to remove it from system


Introduction
New cyber-security report sheds light on the current Ransomware attack resurgence on Synology NAS (Network Attached Storage) systems.

Understanding Synology?
Synology is a Taiwan headquartered storage vendor that specializes in Network Attached Storage (NAS) appliances. NAS is a computer data storage server that provides data access to heterogeneous group of clients.
This renowned Corporation was founded in January 2000 & distributes products worldwide.

Synology NAS's Interface breached

Synology NAS Ransomware
Recent research revealed that Synology owners discovered that all the files in their NAS systems were encrypted. Hence, users of Synology NAS were warned to strengthen the passwords to their Network attached storage.

Threat Behaviour
Investigations revealed that the attackers breached Synology NAS’s login interface via brute force or so called dictionary attacks and stole admin’s credentials. Once the guessed password matched with the default password, the attackers gained access to the NAS device and encrypted all the files on their NAS system. These cyber criminals demanded 0.06 Bitcoin, now worth $583 to restore the encrypted data.
It is believed that attackers leveraged botnet address to hide the real source IP.



Comments

Popular posts from this blog

How to remove Speedtest-guide.com redirect from your system

The novel DNS protocol helps Mozart Malware evade detection

How to remove ZUpdater.exe Trojan from your system?