Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

QNAP Still Dealing With Attacks On NAS Devices

QNAP Still Dealing With Attacks On NAS Devices

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

QNAP has recently warned its customers of an ongoing campaign that is targeting QNAP NAS (Network Attached Storage) devices and infecting them with cryptomining malware.  This particular campaign is deploying software designed to mine Bitcoin and using your computing power to generate profits for them.  If you are infected, you'll see a new process running on your system named "OOM_Reaper."

While it's certainly not the direst threat you can face the malware will utilize up to 50 percent of your system's processing power while mimicking a kernel process with a PID higher than 1000.

If you find that you are already infected, here are the steps the company recommends taking to rid yourself of the malware:

  • Update QTS or QuTS hero to the latest version.
  • Install and update Malware Remover to the latest version.
  • Use stronger passwords for your administrator and other user accounts.
  • Update all installed applications to their latest versions.
  • Do not expose your NAS to the internet, or avoid using default system port numbers 443 and 8080.

The company has really been struggling this year  as they have been targeted by an unusual surge in attacks against them and the equipment they sell.  In January QNAP urged their users to defend themselves from a nasty malware attack that rendered their NAS devices unusable after spawning rogue processes that would soak up most of the target system's processing power. Then in March the company faced a similar cryptomining campaign which installed a miner called UnityMiner.

Before that beginning in May of 2019 and continuing intermittently until June of 2020 QNAP users faced a spate of eChoraix ransomware attacks which came to also be known as QNAPCrypt.

All that to say that if you're a QNAP customer you're probably already familiar with threats on the landscape. If you're not doing so already be sure to head to the company's website and review their FAQ page which lists current best practices relating to security.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime