Heimdal Security Blog

QNAP NAS Devices Targeted Now by Another Cryptocurrency Mining Malware

Yesterday, QNAP (Quality Network Appliance Provider), the provider of solutions in fields like hardware design, in-house manufacturing, or software development having its focus on video innovation, storage, and networking, published a security alert on their website informing about a new cryptocurrency mining malware that has started to target its devices.  Customers are required to implement straight off some preventive measures.

A bitcoin miner has been reported to target QNAP NAS. Once a NAS is infected, CPU usage becomes unusually high where a process named “[oom_reaper]” could occupy around 50% of the total CPU usage. This process mimics a normal, legitimate kernel process with the same name. However, while the legitimate kernel process PID is usually below 1000, the bitcoin miner PID is usually greater than 1000.

Source

The company wrote that a current investigation is ongoing on this topic, however, data related to the initial vector access vector has not been provided.

Mitigation Measures Recommended by QNAP

Following this news, QNAP made also some recommendations for its clients on how to keep their devices protected:

Details on how to implement all the recommended prevention and mitigation measures are also shared in the same alert.

For any other issues or questions, the company could also be contacted at the QNAP Helpdesk.

QNAP Devices Targeted In the Past Too by Other Malware

We also wrote in March about a cryptocurrency mining campaign featuring the UnityMiner that was targeting at that time unpatched QNAP NAS devices. The mining program exploiting QNAP vulnerabilities dubbed Unity Miner was discovered by 360 Netlab researchers and it was targeting two QNA vulnerabilities classified CVE-2020-2506 and CVE-2020-2507.

Before these revealed attacks, however, NAS had been already targeted for some months by other infections related to eChOraix Ransomware, Muhstik Ransomware, or QSnatch malware.

Did you enjoy this article? Follow us on LinkedInTwitterFacebookYoutube, or Instagram to keep up to date with everything we post!