Researchers Warn of 674% Surge in Deadbolt Ransomware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Flaw Exploited by DeadBolt Ransomware CVE-2022-27593 is a critical (CVSS 9.1) externally controlled reference to a resource (CWE-610, an SSRF-style flaw) in the Photo Station photo-sharing application for QNAP NAS devices running QTS. Because the flaw is reachable over the network with no privileges or user interaction required, an unauthenticated attacker who can reach a Photo Station instance can force the application to reference attacker-controlled resources and modify system files. This is the vulnerability the DeadBolt ransomware operation exploited to compromise and encrypt thousands of internet-facing QNAP NAS devices in 2022. Any QNAP NAS running vulnerable Photo Station versions across QTS 4.2.x through 5.x is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08, ransomware use is known, and EPSS puts the 30-day exploitation probability at 87.9% (100th percentile), though no public PoC is known. Do: Upgrade Photo Station to the fixed version for your QTS branch: 6.1.2+ on QTS 5.0.1, 6.0.22+ on QTS 5.0.0/4.5.x, 5.7.18+ on QTS 4.3.6, 5.4.15+ on QTS 4.3.3, and 5.2.14+ on QTS 4.2.6. If patching is not immediately possible, disable Photo Station or remove it from internet exposure, since the flaw requires no authentication. Check devices for DeadBolt compromise (encrypted files and ransom notes) and apply updates per CISA's KEV required action and QNAP's instructions. | 9.1 | 88% | KEV ransomware |
| large≈ tens of thousands of internet-exposed QNAP NAS devices running Photo Station, with thousands confirmed encrypted by DeadBolt |
Full article363 words · extracted from infosecurity-magazine.com · click to collapse
Security experts have flagged a spectacular surge in network-attached storage (NAS) devices around the world infected with the Deadbolt ransomware variant.
Devices made by Taiwanese company QNAP have been targeted by the group since the start of the year. It appears that the hackers took advantage of a vulnerability in the products to compromise them, causing major problems for the consumers and small businesses that are typical QNAP customers.
However, attack surface management vendor Censys has warned that the attacks have kept on coming over the summer.
It recorded a global infection count of 2459 on June 27, rising to 7783 on July 15, then 9091 on July 30, and finally a high of 19,029 devices on September 4. That's a 674% increase in just over two months.
A majority of these infections were found in the US, with 2472 hosts showing signs of Deadbolt, followed by Germany (1778), and Italy (1383).
A spike in infections noted between September 1 and the following day, when the number of affected devices jumped from 7748 to 13,802, may have been caused by a newly exploited zero-day bug, which QNAP described in a notice on September 3.
The recent spike is way higher than the normal cadence of new infections recorded by Censys, explained senior security researcher Mark Ellzey.
The firm was able to track infected devices due to the way Deadbolt ransomware works, he explained.
“Instead of encrypting the entire device, which effectively takes the device offline (and out of the purview of Censys), the ransomware only targets specific backup directories for encryption and vandalizes the web administration interface with an informational message explaining how to remove the infection,” said Ellzey.
“Due to how this ransomware communicates with the victim, Censys could easily find infected devices exposed on the public internet via this simple search query. Besides broad information about which hosts were infected with Deadbolt, we could also obtain and track every unique bitcoin wallet address used as a ransom since the BTC address used for ransom drops is embedded within the HTML body.”
QNAP users are urged to upgrade to the latest version to fix the latest vulnerability, tracked as CVE-2022-27593.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/researchers-674-surge-deadbolt/