How to foil SynoLocker and minimize the damage

  • 5 August 2014
  • 1 reply
  • 342 views

Userlevel 7
Comment: This raonsomware is due to non-updated versions of DiskStation Manager
=================================================================================================
Author: Zeljka Zorz/ HNS Managing Editor. Posted on 05.08.2014
 
 
We wrote on Monday warning about Synology NAS users being targeted with SynoLocker, a customized version of the Cryptolocker ransomware, which encrypts the files contained on the devices and asks 0.6 BitCoin ($350) for the decryption key.


http://www.net-security.org/images/articles/threat.jpg
It is still not known how the malware manages to compromise the devices, but Synology says that so far, it looks like the problem is localized to non-updated versions of DiskStation Manager (DSM) 4.3. They are still researching the issue to see if it effects DSM 5.0 as well.

 
Help Net Security/ Full Article Here/ http://www.net-security.org/malware_news.php?id=2829
 

1 reply

Userlevel 7
The following article is a update on SynoLocker
 
(SynoLocker Trojan crime gang: We QUIT this gig)
 
By John Leyden, 14 Aug 2014
 
 
A ransomware Trojan gang appears to be moving on, and has offered to sell its remaining decryption keys in bulk for 200 BTC ($103,000, £61,500).
Cybercrooks behind the recent SynoLocker Trojan – which targets the network attached storage devices manufactured by Synology – have apparently decided to cash out on their ill-gotten gains. The ransomware encrypted users' files before demanding a payment for a private key necessary to unscramble them.
 The process, akin to a bank selling off bad debt in the world of legitimate business, was discovered by security researchers at F-Secure.
"The website where victims are instructed to go to for payment instructions, has been updated," explains F-Secure research intern Artturi Lehtiö in a blog post.
"The page now includes the notice 'This website is closing soon...' The operator(s) also claim that they are still in possession of over 5,500 private keys but that they are willing to sell the entire collection for 200 Bitcoins."
 
http://www.theregister.co.uk/2014/08/14/synolocker_trojan_closing_down_sale/The Register/ Full Read Here/
 

Reply