HomeSecurityQNAP warns of eCh0raix ransomware attacks

QNAP warns of eCh0raix ransomware attacks

QNAP is warning customers about a Roon Server zero-day bug and eCh0raix ransomware attacks targeting Network Attached Storage (NAS) devices.

eCh0raix ransomware QNAP

See also: Toshiba TEC Corp: Subsidiary falls victim to DarkSide ransomware

This warning comes just two weeks after QNAP users were notified of an ongoing outbreak of AgeLocker ransomware attacks.

The Taiwan-based NAS device maker says it has received reports of devices affected by the eCh0raix ransomware in a security advisory published today.

“The eCh0raix ransomware has been reported to affect QNAP NAS devices,” the company said. “Devices that use weak passwords may be more susceptible to an attack.

See also: Ransomware: What you need to know about this major threat!

QNAP urged customers to “act immediately” to protect their data from potential eCh0raix attacks:

  • Use stronger passwords for your administrator accounts.
  • Enable IP access protection to protect accounts from brute force attacks.
  • Avoid using default port numbers 443 and 8080.

Detailed step-by-step instructions on changing the NAS password, enabling IP access protection, and changing the system port number are available in the security advisory.

See also: Lorenz ransomware: A new threat to businesses

Roon Server zero-day

Today, while not making a direct connection to the eCh0raix attacks, QNAP also warned of a zero-day vulnerability that actively affects Roon Labs' Roon Server 2021-02-01, as well as older versions.

The company recommends disabling the Roon Server music server and exposing the NAS to the Internet to protect against these active attacks until Roon Labs provides a security update.

To disable Roon Server on your NAS, you need to follow this procedure:

  1. Log in to QTS as an administrator.
  2. Open the App Center, then click. A search box appears.
  3. Type “Roon Server” and then press ENTER. Roon Server appears in the search results.
  4. Click the arrow below the Roon Server icon.
  5. Select Stop. The application is disabled.

QNAP also patched a command injection in its Malware Remover application on Thursday.

This security flaw would allow remote attackers to execute arbitrary commands on devices running vulnerable versions of applications.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS