The ech0raix ransomware has once again started targeting vulnerable QNAP Network Attached Storage (NAS) devices.
ech0raix (also known as QNAPCrypt) had hit QNAP customers in multiple large-scale waves starting with the summer of 2019 when the attackers brute-forced their way into Internet-exposed NAS devices.
Since then, several other campaigns have been detected and reported by this ransomware strain’s victims, in June 2020, in May 2020, and a massive surge of attacks targeting devices with weak passwords that started in mid-December 2021 and slowly reduced towards early February 2022.
A new surge of ech0raix attacks has now been confirmed by an increasing number of ID Ransomware submissions and users reporting being hit in the BleepingComputer forums with the earliest hit recorded on June 8.
A few dozen ech0raix samples were submitted but the actual number is likely to be higher since only some of the victims will use the ID Ransomware service to identify the ransomware that encrypted their devices.
As more details regarding the attack is unavailable the attack vector used in this new ech0raix campaign remains unknown.
QNAP is yet to issue a warning to alert customers of these attacks, but the company has previously urged the users to protect their data from potential eCh0raix attacks by:
- using stronger passwords for administrator accounts
- enabling IP Access Protection to protect accounts from brute force attacks
- and avoiding using default port numbers 443 and 8080
QNAP provides detailed step-by-step instructions on changing the NAS password, enabling IP Access Protection, and changing the system port number in its security advisory.
The company has also urged customers to disable Universal Plug and Play (UPnP) port forwarding on their routers to prevent exposing their NAS devices to attacks from the Internet.
QNAP also warned customers to secure their devices against ongoing attacks deploying DeadBolt ransomware payloads.
It urges all NAS users to check and update QTS to the latest version as soon as possible, and avoid exposing their NAS to the Internet.














Comments