Ransomware targets Synology storage systems

Spread the love

Several users of Synology systems are complaining that their NAS has been affected by ransomware. The malware, called Synolocker, encrypts files; users have to pay hundreds of dollars to access their files again.

The users complain on the Synology forum that they can no longer access their files. Their NAS system’s configuration page has been replaced with a warning that the files are encrypted, and the user has to pay money to get the encryption key. Users would have to pay 0.6 bitcoin, converted approximately 260 euros, for access. It is not clear whether users will regain access after payment.

SynoLocker’s method and name are reminiscent of CryptoLocker, a notorious ransomware that has affected many users. It is unknown how the SynoLocker spreads, but it is likely that ssh access or holes in the administration interface are used to install the malware. This means that shielding the NAS via the router greatly reduces the chance of being infected.

According to one forum user, there is a trick to get the Synology NAS working again, but it failed to access its files. Security vulnerabilities in Synology systems were previously used to mine bitcoins and dogecoins, among other things. Attackers would thus have stolen half a million euros.

Source: Twitter @MikeEvangelist

You might also like
Exit mobile version