UK and US alert QNAP owners to upgrade firmware to block malware

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) today issued an alert about the risks of infection faced by QNAP NAS devices if QSnatch malware attacks restart.

Although the attack infrastructure used in previous QSnatch attacks (from early 2014 to mid-2017 and from late 2018 to late 2019) is currently not active, the two agencies urge all QNAP customers to update their NAS devices as soon as possible to block future campaigns.

"All QNAP NAS devices are potentially vulnerable to QSnatch malware if not updated with the latest security fixes," the two agencies explain (1, 2).

"Organizations that are still running a vulnerable version must run a full factory reset on the device prior to completing the firmware upgrade to ensure the device is not left vulnerable," the joint alert warns.

The two agencies have found roughly 62,000 infected devices worldwide in mid-June 2020, of which about 7,600 were found in the United States and 3,900 in the United Kingdom.
 

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top