安全ID : QSA-21-56

Bitcoin Miner [oom_reaper]


  • 发布日期 : December 7, 2021

  • 受影响产品: All QNAP NAS

状态

已解决


Summary

A bitcoin miner has been reported to target QNAP NAS. Once a NAS is infected, CPU usage becomes unusually high where a process named "[oom_reaper]" could occupy around 50% of the total CPU usage. This process mimics a normal, legitimate kernel process with the same name. However, while the legitimate kernel process PID is usually below 1000, the bitcoin miner PID is usually greater than 1000.

We strongly recommend users to act immediately to protect their device.

If you have any questions regarding this issue, please contact us through the QNAP Helpdesk.

Recommendation

To protect your device from infection, we recommend the following actions:

  1. Update QTS or QuTS hero to the latest version.
  2. Install and update Malware Remover to the latest version.
  3. Use stronger passwords for your administrator and other user accounts.
  4. Update all installed applications to their latest versions.
  5. Do not expose your NAS to the internet, or avoid using default system port numbers 443 and 8080.

If you suspect your NAS has been infected with the bitcoin miner, restarting the NAS may also remove the malware.

Updating QTS or QuTS hero

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS or QuTS hero downloads and installs the latest available update.

Updating Malware Remover

  1. Log on to QTS or QuTS hero as administrator.
  2. Open the App Center and then click .
    A search box appears.
  3. Enter "Malware Remover".
    Malware Remover appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your Malware Remover is already up to date.
  5. Click OK.
    The application is updated.

Changing an Administrator Password

  1. Log on to QTS or QuTS hero as administrator.
  2. Click the profile picture on the QTS or QuTS hero Task Bar.
    The Options window opens.
  3. Click Change Password.
  4. Specify the old password.
  5. Specify the new password.
    QNAP recommends the following criteria to improve password strength:
    • At least 8 characters in length
    • Include both uppercase and lowercase characters
    • Include at least one number and one special character
    • Must not be the same as the username or the username reversed
    • Must not include characters that are consecutively repeated three or more times
  6. Verify the new password.
  7. Click Apply.

Changing User Passwords

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to Control Panel > Privilege > Users.
  3. Select a user.
  4. Click Change Password.
    The Change Password window appears.
  5. Specify the old password.
  6. Specify the new password.
    QNAP recommends the following criteria to improve password strength:
    • At least 8 characters in length
    • Include both uppercase and lowercase characters
    • Include at least one number and one special character
    • Must not be the same as the username or the username reversed
    • Must not include characters that are consecutively repeated three or more times
  7. Verify the new password.
  8. Click Apply.
  9. Repeat the above steps to change passwords for other users.

Updating All Installed Applications

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to App Center.
  3. Select My Apps.
  4. Next to Install Updates, click All.
    A confirmation message appears.
  5. Click OK.
    QTS or QuTS hero updates all your installed applications to their latest versions.

Changing the System Port Number

  1. Log on to QTS or QuTS hero as administrator.
  2. Go to Control Panel > System > General Settings > System Administration.
  3. Specify a new system port number.
    Warning: Do not use 443 or 8080.
  4. Click Apply.
    QTS or QuTS hero applies the new system port number.

修订历史:
V1.0 (December 7, 2021) - Published
V1.1 (December 8, 2021) - Clarification added
V2.0 (December 30, 2021) - Status updated

选择规格

      显示更多 隐藏更多
      open menu
      back to top