ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Warning: Yet Another Bitcoin Mining Malware Targeting QNAP NAS Devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2495
+1 in the same advisory: …2496
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

NVD description · AI analysis pending
6.11%
  • qnap quts hero
  • qnap qts
CVE-2020-2506
Unauthenticated Improper Access Control in QNAP Helpdesk for QTS

CVE-2020-2506 is an improper access control flaw (CWE-284) in the QNAP Helpdesk application used with QTS, affecting Helpdesk versions prior to 3.0.3. The flaw is network-exploitable with no privileges or user interaction required per the CVSS 3.1 vector, so a remote attacker can trigger it by sending crafted requests to a device running a vulnerable Helpdesk version. Successful exploitation lets the attacker gain privileges or read sensitive information, compromising the security of the affected software. Any QNAP NAS running QTS with the Helpdesk app at a version below 3.0.3 is affected. The flaw was added to CISA's KEV catalog on 2022-03-25, confirming exploitation in the wild (EPSS currently estimates a ~2% probability of exploitation in the next 30 days, 79th percentile, and no public PoC is known); QNAP NAS broadly remain targeted by ransomware and cryptomining campaigns, though those headline campaigns are not specifically tied to this CVE.

Do: Update the QNAP Helpdesk app to version 3.0.3 or later via QTS App Center, per vendor instructions, as required by the CISA KEV listing; verify the installed Helpdesk version first. If the app is not needed, disable or remove it, and avoid exposing the NAS management interface and Helpdesk service directly to the internet. Given active ransomware and cryptomining campaigns against QNAP NAS, treat unpatched internet-facing QTS devices as high priority and review access logs for suspicious activity.

9.82% KEV
  • QNAP Helpdesk prior to 3.0.3 (QNAP application running on QTS)
largetens of thousands to low hundreds of thousands of internet-exposed QNAP NAS devices running a vulnerable Helpdesk app (estimate)
CVE-2020-2507
The vulnerability have been reported to affect earlier versions of QTS.

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

NVD description · AI analysis pending
9.83%
  • qnap helpdesk
Full article322 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 08, 2021

Network-attached storage (NAS) appliance maker QNAP on Tuesday released a new advisory warning of a cryptocurrency mining malware targeting its devices, urging customers to take preventive steps with immediate effect.

"A bitcoin miner has been reported to target QNAP NAS. Once a NAS is infected, CPU usage becomes unusually high where a process named '[oom_reaper]' could occupy around 50% of the total CPU usage," the Taiwanese company said in an alert. "This process mimics a kernel process but its [process identifier] is usually greater than 1000."

QNAP said it's currently investigating the infections, but did not share more information on the initial access vector that's being used to compromise the NAS devices. Affected users can remove the malware by restarting the appliances.

In the interim, the company is recommending that users update their QTS (and QuTS Hero) operating systems to the latest version, enforce strong passwords for administrator and other user accounts, and refrain from exposing the NAS devices to the internet.

QNAP NAS devices have long been a lucrative target for a number of malicious campaigns in recent years.

In July 2020, cybersecurity agencies in the U.S. and U.K. issued a joint bulletin about a threat that infected the NAS devices with a data-stealing malware dubbed QSnatch (or Derek). In December 2020, the device maker warned of two high-severity cross-site scripting flaws (CVE-2020-2495 and CVE-2020-2496) that enabled remote adversaries to take over the devices.

Then in March 2021, Qihoo 360's Network Security Research Lab disclosed a cryptocurrency campaign that exploited two security flaws in the firmware — CVE-2020-2506 and CVE-2020-2507 — to gain root privileges and deploy a miner called UnityMiner on compromised devices. And as of April this year, QNAP NAS devices have also been the target of eCh0raix and Qlocker ransomware attacks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html