
#QNAP QBLOCKER INSTALL#
Subsequently, on April 22, we released a piece of Product Security News to urge our users to install all recently-released updates before we can confirm the actual attack path. We've also added short scripts to attempt extractions of the encryption key when the compression is still in progress. After the encryption begins, Qlocker will leave a ransom note and delete itself to increase the difficulty of our investigation.īased on the limited information we've gathered from early-reported cases, we released updated detection rules of the QNAP NAS Malware Remover app to detect and stop malware activities. After the NAS is breached, the attacker would insert malicious code into the system to delete all snapshots and to compress user files with a password by using the built-in 7-Zip utility that is intended for normal file compression/decompression operations. Once the weakness is exploited, the malware could obtain the inappropriate permission level of the QNAP NAS involved. The attacker took advantage of a patched HBS vulnerability. Subsequently, after our initial investigation, it is confirmed that the Qlocker ransomware is exploiting one of the patched HBS vulnerabilities against unpatched QNAP NAS that are directly connected to the Internet. On April 21, we began to receive user reports about possible ransomware attacks. On April 16, 2021, we released an updated version () of the Hybrid Backup Sync (HBS) app to add new features and to address certain security issues described in the QNAP Security Advisory QSA-21-13.

We sincerely invite our users to join us and work together toward the goal of fighting against ransomware, in order to make the Internet a safer place for everyone.

#QNAP QBLOCKER PATCH#
While it has always been QNAP's top priority to timely patch software issues and to release relevant information, we stand behind our commitment and are doubling our efforts to the continuing enhancement of the security features provided in our products. We understand that our users are deeply troubled by this incident. Recently the Qlocker ransomware launched a hostile campaign against QNAP NAS and has caused inconvenience and data loss for our valued users.
