Security researchers have identified a new ransomware strain dubbed eCh0raix, which targets Linux devices with QNAP Network Attached Storages (NAS). The ransomware is designed to infect and encrypt victims' files using AES encryption.

The malware, based on the Go programming language , has only 400 lines of code. It has a very low detection rate and only targets Linux- based QNAP NAS servers .
QNAP is a Taiwanese company known for selling NAS servers that are primarily used for storage and media playback needs. Generally, NAS servers are used to store large amounts of data and files.
The ransomware, dubbed “QNAPCrypt” by Intezer and “eCh0raix” by Anomali, carries basic ransomware functionality, but contains several differences.
Once the malware is executed, it contacts the command and control server to begin the encryption process. Before encryption, it requests specific information from the C&C server, such as the wallet address where the ransom money will be deposited from the ransomware victims, and a public RSA key.
Communication with the C2 server is done over the Tor network, with the help of a SOCKS5 proxy. The data sent from the server is JSON encoded. The ransomware encrypts the file using an AES-256 key and adds the .ccrypt extension to the encrypted files.
Before the encryption process begins, the following services are terminated on the infected NAS servers:
apache2
httpd
nginx
mysqld
MySQL
PHP-fpm
php5-fpm
PostgreSQL
eCh0raix encrypts the following extensions:
.dat.db0.dba.dbf.dbm.dbx.dcr.der.dll.dml.dmp.dng.doc.dot.dwg.dwk.dwt.dxf.dxg.ece.eml.epk.eps.erf.esm .ewp.far.fdb.fit.flv.fmp.fos.fpk.fsh.fwp.gdb.gho.gif.gne.gpg.gsp.gxk.hdm.hkx.htc.htm.htx.hxs.idc.idx .ifx.iqy.iso.itl.itm.iwd.iwi.jcz.jpe.jpg.jsp.jss.jst.jvs.jws.kdb.kdc.key.kit.ksd.lbc.lbf.lrf.ltx.lvl .lzh.m3u.m4a.map.max.mdb.mdf.mef.mht.mjs.mlx.mov.moz.mp3.mpd.mpp.mvc.mvr.myo.nba.nbf.ncf.ngc.nod.nrw .nsf.ntl.nv2.nxg.nzb.oam.odb.odc.odm.odp.ods.odt.ofx.olp.orf.oth.p12.p7b.p7c.pac.pak.pdb.pdd.pdf.pef .pem.pfx.pgp.php.png.pot.ppj.pps.ppt.prf.pro.psd.psk.psp.pst.psw.ptw.ptx.pub.qba.qbb.qbo.qbw.qbx.qdf.qfx
Ways to Protect Yourself from eCh0raix ransomware
What actions should NAS administrators take to effectively protect their systems? Security researchers recommend that admins restrict external access to QNAP NAS devices, use strong passwords, and ensure that their devices are up-to-date with the latest security patches.
