What are you looking for ?
RAIDON

Qnap Security Advisory Bulletin ID: QSA-21-56

Concerning bitcoin miner reported to target firm's NAS

Qnap Systems, Inc. has published a security advisor concerning a bitcoin miner to target company’s NAS.

Investigating Bitcoin Miner [oom_reaper]

  • Release date: December 7, 2021

  • Security ID: QSA-21-56

  • Affected products: All Qnap NAS

  • Status: Investigating

Summary
A bitcoin miner has been reported to target Qnap NAS. Once a NAS is infected, CPU usage becomes unusually high where a process named ‘[oom_reaper]’ could occupy around 50% of the total CPU usage. This process mimics a kernel process but its PID is usually greater than 1000.

The company strongly recommend users to act immediately to protect their device.

If you have any questions regarding this issue, please contact us through the Qnap Helpdesk.

Recommendation:
To protect your device from infection, the company recommend the following actions:

  1. Update QTS or QuTS hero to the latest version.

  2. Install and update Malware Remover to the latest version.

  3. Use stronger passwords for your administrator and other user accounts.

  4. Update all installed applications to their latest versions.

  5. Do not expose your NAS to the internet, or avoid using default system port numbers 443 and 8080.

If you suspect your NAS has been infected with the bitcoin miner, restarting the NAS may also remove the malware.

Updating QTS or QuTS hero:

  1. Log on to QTS or QuTS hero as administrator.

  2. Go to Control Panel > System > Firmware Update.

  3. Under Live Update, click Check for Update.
    QTS or QuTS hero downloads and installs the latest available update.

Updating Malware Remover:

  1. Log on to QTS or QuTS hero as administrator.

  2. Open the App Center and then click Qnap Loupe
    A search box appears.

  3. Enter ‘Malware Remover’.
    Malware Remover appears in the search results.

  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your Malware Remover is already up to date.

  5. Click OK.
    The application is updated.

Changing an administrator password:

  1. Log on to QTS or QuTS hero as administrator.

  2. Click the profile picture on the QTS or QuTS hero Task Bar.
    The Options window opens.

  3. Click Change Password.

  4. Specify the old password.

  5. Specify the new password.
    Qnap recommends the following criteria to improve password strength:

    • At least eight characters in length

    • Include both uppercase and lowercase characters

    • Include at least one number and one special character

    • Must not be the same as the username or the username reversed

    • Must not include characters that are consecutively repeated three or more times

  6. Verify the new password.

  7. Click Apply.

Changing user passwords:

  1. Log on to QTS or QuTS hero as administrator.

  2. Go to Control Panel > Privilege > Users.

  3. Select a user.

  4. Click Change Password.
    The Change Password window appears.

  5. Specify the old password.

  6. Specify the new password.
    Qnap recommends the following criteria to improve password strength:

    • At least eight characters in length

    • Include both uppercase and lowercase characters

    • Include at least one number and one special character

    • Must not be the same as the username or the username reversed

    • Must not include characters that are consecutively repeated three or more times

  7. Verify the new password.

  8. Click Apply.

  9. Repeat the above steps to change passwords for other users.

Updating all installed applications:

  1. Log on to QTS or QuTS hero as administrator.

  2. Go to App Center.

  3. Select My Apps.

  4. Next to Install Updates, click All.
    A confirmation message appears.

  5. Click OK.
    QTS or QuTS hero updates all your installed applications to their latest versions.

Changing system port number:

  1. Log on to QTS or QuTS hero as administrator.

  2. Go to Control Panel > System > General Settings > System Administration.

  3. Specify a new system port number.
    Warning: Do not use 443 or 8080.

  4. Click Apply.
    QTS or QuTS hero applies the new system port number.

Revision History: V1.0 (December 7, 2021) – Published

Articles_bottom
SNL Awards_2026
AIC