AgeLocker Ransomware
Applied models:
-
All NAS Series
The AgeLocker Ransomware has been reported to target QNAP NAS Linux, and MacOS devices. This ransomware attempts to encrypt the files of victims by using the “Age” encryption tool. The provided links will be information on the AgeLocker ransomware and our security advisory about this.
https://www.bleepingcomputer.com/news/security/agelocker-ransomware-targets-qnap-nas-devices-steals-data/
https://www.qnap.com/en-us/security-advisory/qsa-20-06
The following are some FAQs for your reference:
1. What should I do?
Answer: Please follow the security advisory to the letter. You will have to also re-initialize the NAS once you are comfortable with any backup of the data.
2. Will I be able to restore my files? I have another QNAP NAS TS-451+. It is in the same network.
Answer: You will have to restore from a known-good backup. Unfortunately, ransomware attacks are dangerous because of the encryption aspect which reduces our ability to do much. For your other NAS, please follow the security advisory and update all applications and firmware to the latest versions.
3. How can I protect it? I have changed the admin password in the second one immediately. Is it enough?
Answer: Please follow the security advisory and update all applications and firmware to the latest versions.