Security ID : NAS-201805-24
Security Advisory for VPNFilter Malware
Release date : May 24, 2018
CVE identifier : N/A
Affected products: All QNAP NAS running QTS 4.2.6 build 20170628, 4.3.3 build 20170703, and earlier versions or using the default password for the administrator account
Severity
Medium
Status
Resolved
Summary
A malware called VPNFilter is known to steal information and allow attackers to remotely damage infected devices. The malware reportedly affects different devices, including some QNAP NAS models running QTS 4.2.6 build 20170628, 4.3.3 build 20170703, and earlier versions, or using the default password for the administrator account.
We have already noted this issue last year and have updated our malware signatures in Malware Remover 2.2.1 and later. Concerned users can scan their NAS with Malware Remover 2.2.1 or later versions.
Recommendation
To avoid possible exploits, users must:
- Update QTS to the 4.2.6 build 20170729, 4.3.3 build 20170727 or later versions.
- Install Malware Remover 2.2.1 or later versions, and then run a full scan.
- Change the password if you are using the default password for the administrator account.
Installing the QTS Update
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
QTS downloads and installs the latest available update.
Installing and running the latest version of Malware Remover
- Log on to QTS as administrator.
- Open the App Center, and then click the Search icon.
A search box appears. - Type “Malware Remover”, and then press ENTER.
The Malware Remover application appears in the search results list. - Click Install.
A confirmation message appears. - Click OK.
The application is installed. - Open Maware Remover.
- Click Start Scan.
Malware Remover scans the NAS for malware.
Change the administrator account password
- Log on to QTS as administrator.
- On the task bar, click admin > Options.
The Options window appears. - Click Change Password.
The Change Password screen appears. - Enter your old password.
- Specify a password that contains 6 to 64 ASCII characters.
- Click Apply.
QTS saves your new password.
Revision History: V1.0 (May 24, 2018) - Published