QNAP today warned customers of ongoing attacks targeting their NAS devices with cryptomining malware, urging them to take immediate steps to protect themselves.

See also: Nobelium hacking group uses new Ceeloader malware
The cryptominer deployed in this campaign on compromised devices will create a new process named [oom_reaper] that will mine Bitcoin cryptocurrency.
When executed, the malware can occupy up to 50% of all CPU resources and emulate a kernel process with a PID higher than 1000.
Customers who suspect their NAS has been infected with this bitcoin miner are advised to reboot their device, which may remove the malware.
QNAP also recommends that customers take the following measures to protect their devices from these attacks:
- Update hero QTS or QuTS to the latest version.
- Install and update Malware Remover to the latest version.
- Use stronger passwords for administrator and other user accounts.
- Update all installed applications to their latest versions.
- Do not expose your NAS to the internet or avoid using the default system port numbers 443 and 8080.
You can find detailed information about the steps required for each of the above actions in today's security advisory.
See also: Magnat Campaign: Malware Spreads Through Fake Software Downloads

QNAP NAS devices under siege
NAS devices are an attractive target for attackers, and this is not the first time QNAP systems have been targeted by cryptomining malware this year.
In March, researchers at Qihoo 360's Network Security Research Lab (360 Netlab) revealed that a cryptominer called UnityMiner hijacks QNAP NAS devices without patching against two pre-authorization remote command execution (RCE) vulnerabilities in the Helpdesk application.
In January, QNAP users were called upon to defend their devices from a malware that rendered them useless after spawning the dovecat and dedpma processes that would consume almost all system resources.
QNAP notified customers of the eCh0raix (also known as QNAPCrypt) ransomware attacks in May (as well as June 2019 and June 2020). This notification came two weeks after another warning about the AgeLocker ransomware outbreak.
See also: A simple technique enhances phishing campaigns to spread malware
A massive Qlocker ransomware campaign began hitting vulnerable QNAP devices in mid-April. The attackers earned $260,000 in just five days.
QNAP customers who want to further protect their NAS devices from attacks are recommended to follow these best practices.
Information source: bleepingcomputer.com
