QNAP - AgeLocker Ransomware

  • ATTENTION! As of November 1, 2020, you are not able to reply to threads 6 months after the thread is opened if there are more than 500 posts in the thread.
    Threads will not be locked, so posts may still be edited by their authors.
    Just start a new thread on the topic to post if you get an error message when trying to reply to a thread.

sentinelvdx

Very Senior Member

QNAP Security Advisory | Bulletin ID: QSA-21-15​


Taipei, Taiwan, April 29, 2021 - QNAP® had published security enhancement against security vulnerabilities that could affect specific versions of QNAP products. Please use the following information and solutions to correct the security issues and vulnerabilities.

AgeLocker Ransomware​

Release date: April 29, 2021
Security ID: QSA-21-15
Severity rating: High
CVE identifier: N/A
Affected products: All QNAP NAS

Summary​

The QNAP security team has detected suspicious ransomware in the wild known as AgeLocker, which has the potential to affect QNAP NAS devices.

Recommendation​

To secure your device, we strongly recommend regularly updating QTS or QuTS hero and all installed applications to their latest versions to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.

To further secure your device, do not expose your NAS to the internet. If you must connect your NAS to the internet, we highly recommend using a trusted VPN or a myQNAPcloud link.

Updating QTS or QuTS hero​

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS or QuTS hero downloads and installs the latest available update.
Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating All Installed Applications​

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to App Center.
  3. Select My Apps.
  4. Beside Install Updates, click All.
    A confirmation message appears.
  5. Click OK.
    QTS or QuTS hero updates all your installed applications to their latest versions.


Revision History: V1.0 (April 29, 2021) - Published



If you have any questions regarding this issue, please contact us at https://www.qnap.com/go/support-ticket/.
 

sentinelvdx

Very Senior Member
I'm seriously considering someone is targeting QNAP's to impact on their image.... maybe some ex QNAP coder? idk...
 

RMerlin

Asuswrt-Merlin dev
I'm seriously considering someone is targeting QNAP's to impact on their image.... maybe some ex QNAP coder? idk...
Probably just poor security, and a large enough userbase to be worth explicitly targeting. This ain't the first malware targeting QNAP, a few years ago I had a customer's QNAP infected by a cryptominer. I had to manually clean it up, because their malware scanner didn't recognize it yet (I sent them the sample afterward for their analysis).
 

sentinelvdx

Very Senior Member

coxhaus

Part of the Furniture
The one I posted is April 21, 2021. The Agelocker you posted is old. It is September 23, 2020.
 

sentinelvdx

Very Senior Member
The one I posted is April 21, 2021. The Agelocker you posted is old. It is September 23, 2020.
Because AgeLocker appeared in 2020, QLocker appeared later, but the fix for AgeLocker was fixed recently on the latest firmware.
Check the date of the security bulletin posted by QNAP "April 29, 2021"
QLocker and AgeLocker works different
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top