The malicious actors behind the eCh0raix Ransomware have launched a new campaign targeting QNAP NAS devices. eCh0raix was first observed in June 2019, after victims began reporting ransomware attacks on a BleepingComputer forum. On June 1, 2020, there was a sharp increase in eCh0raix victims requesting help on the BleepingComputer forums to identify and deal with the ransomware. Malicious actors gain access to QNAP NAS devices through known vulnerabilities or through weak passwords used on a device. Once the attackers, they install the ransomware, which encrypts files stored on the device and appends the .encrypt extension to the file name. ransom contain a link to a Tor payment website. This website will then demand around $500 for a decryptor.

One victim reported finding strange QNAP app names in their device’s AppCenter after encryption. However, it is not known whether these are malicious packages installed by the threat actors or custom-loaded packages that were encrypted and no longer read properly. While a decryptor was released by security BloodDolly to decrypt previous versions for free, the ransomware developer has since patched the code.

There is currently no way to recover files for free unless a user has enabled the QNAP Snapshot service. If someone has enabled QNAP's block-based snapshot feature, they can use the snapshots to recover data .
What should QNAP NAS device owners do to protect themselves from the eCh0raix Ransomware?

If you have a QNAP NAS device, you can protect yourself by following these steps:
- Update QTS to the latest version.
- Install and update “Security Advisor” to the latest version.
- Use a stronger administrator password.
- Enable network access protection to protect accounts from brute force attacks.
- Disable SSH and Telnet services if you are not using them.
- Avoid using the default port numbers 443 and 8080.
- Enable the QNAP Snapshot service.
- Do not connect your QNAP NAS device to the Internetunless necessary.
