eCh0raix Ransomware
eCh0raix, also known as QNAPCrypt, is a newly observed ransomware tool targeting QNAP consumer and enterprise network attached storage (NAS) devices.
Summary
eCh0raix, also known as QNAPCrypt, is a newly observed ransomware tool targeting QNAP consumer and enterprise network attached storage (NAS) devices.
Threat details
At the time of publication, eCh0raix appears to be delivered to directly to target systems, with each variant using a unique RSA key, although it is unclear how it is distributed.
Once installed, eCh0raix will connect to a Tor-based command and control server using a SOCKS5 proxy to download it's RSA key along with a tailored ransom note. It then checks the system language, and terminates itself if Belarussian, Ukrainian or Russian are detected. eCh0raix encrypts all non-system files using an AES-256 CFB key, which is then encrypted using the unique RSA key
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:50 pm