Synology NAS Attack
Posted by: Mike-B on 05 August 2014
I picked up on this posted on www yesterday
http://www.anandtech.com/show/...ynolocker-ransomware
I understand at this time only a portion of Synology servers are affected.
Synology has confirmed that SynoLocker attacks servers running out of date versions of DSM 4.3.
So far, it looks like the matter is localized to non-updated versions of DSM 4.3, but Synology are working on it to see if it also effects DSM 5.0.
The latest version is 5.0-4493 Update 3
In the interim, they are asking people to take the following precautions:
Close all open ports for external access as soon as possible, and/or unplug your Disk/RackStation from your router
Update DSM to the latest version
Backup as soon as possible
Synology will provide further information as soon as it is available.
If your NAS has been infected:
(A) Do not trust (ignore) any email from unauthorized/non-genuine Synology email.
Synology email always has the “synology.com” address suffix.
(B) Do a hard shutdown of your Disk/RackStation to prevent any further issues.
This means a long-press of your unit’s power button, until a long beep has been heard. The unit will shut itself down safely from that point.
(C) Contact Synology Support as soon as possible at, http://www.synology.com/en-global/su...knowledge_base
If anyone has new info on this, it would be good to hear from you.