What's new

QNAP - AgeLocker Ransomware

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

sentinelvdx

Very Senior Member

QNAP Security Advisory | Bulletin ID: QSA-21-15​


Taipei, Taiwan, April 29, 2021 - QNAP® had published security enhancement against security vulnerabilities that could affect specific versions of QNAP products. Please use the following information and solutions to correct the security issues and vulnerabilities.

AgeLocker Ransomware​

Release date: April 29, 2021
Security ID: QSA-21-15
Severity rating: High
CVE identifier: N/A
Affected products: All QNAP NAS

Summary​

The QNAP security team has detected suspicious ransomware in the wild known as AgeLocker, which has the potential to affect QNAP NAS devices.

Recommendation​

To secure your device, we strongly recommend regularly updating QTS or QuTS hero and all installed applications to their latest versions to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.

To further secure your device, do not expose your NAS to the internet. If you must connect your NAS to the internet, we highly recommend using a trusted VPN or a myQNAPcloud link.

Updating QTS or QuTS hero​

  1. Log on to QTS as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS or QuTS hero downloads and installs the latest available update.
Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating All Installed Applications​

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to App Center.
  3. Select My Apps.
  4. Beside Install Updates, click All.
    A confirmation message appears.
  5. Click OK.
    QTS or QuTS hero updates all your installed applications to their latest versions.


Revision History: V1.0 (April 29, 2021) - Published



If you have any questions regarding this issue, please contact us at https://www.qnap.com/go/support-ticket/.
 
I'm seriously considering someone is targeting QNAP's to impact on their image.... maybe some ex QNAP coder? idk...
 
I'm seriously considering someone is targeting QNAP's to impact on their image.... maybe some ex QNAP coder? idk...
Probably just poor security, and a large enough userbase to be worth explicitly targeting. This ain't the first malware targeting QNAP, a few years ago I had a customer's QNAP infected by a cryptominer. I had to manually clean it up, because their malware scanner didn't recognize it yet (I sent them the sample afterward for their analysis).
 
The one I posted is April 21, 2021. The Agelocker you posted is old. It is September 23, 2020.
 
The one I posted is April 21, 2021. The Agelocker you posted is old. It is September 23, 2020.
Because AgeLocker appeared in 2020, QLocker appeared later, but the fix for AgeLocker was fixed recently on the latest firmware.
Check the date of the security bulletin posted by QNAP "April 29, 2021"
QLocker and AgeLocker works different
 
Similar threads

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top