{"id":11649,"date":"2014-08-07T23:35:27","date_gmt":"2014-08-08T06:35:27","guid":{"rendered":"http:\/\/37prime.wordpress.com\/?p=11649"},"modified":"2014-08-07T23:35:27","modified_gmt":"2014-08-08T06:35:27","slug":"synology-issues-official-statement-to-address-synolocker-ransomware","status":"publish","type":"post","link":"https:\/\/37prime.com\/news\/2014\/08\/07\/synology-issues-official-statement-to-address-synolocker-ransomware\/","title":{"rendered":"Synology Issues Official Statement to Address SynoLocker Ransomware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-14299\" src=\"http:\/\/37prime.com\/news\/wp-content\/uploads\/2014\/08\/Synology-on-SynoLocker.jpg\" alt=\"Synology on SynoLocker\" width=\"960\" height=\"540\" \/><\/p>\n<p>Synology has been sending users email regarding the SynoLocker ransomware, mirroring\u00a0<a href=\"http:\/\/www.synology.com\/en-us\/company\/news\/article\/470\" target=\"_blank\">the\u00a0statement posted at Synology website<\/a>\u00a0from August 5, 2014.<\/p>\n<blockquote>\n<h2 style=\"font-weight:bold;\">Dear Synology users,<\/h2>\n<p>We would like to inform you that a ransomware called &#8220;SynoLocker&#8221; is currently affecting some Synology NAS users. This ransomware locks down affected servers, encrypts users\u2019 files, and demands a fee to regain access to the encrypted files.<\/p>\n<p>We have confirmed that the ransomware only affects Synology NAS servers running older versions of DiskStation Manager by exploiting a security vulnerability that was fixed and patched in December, 2013.<\/p>\n<p>Affected users may encounter the following symptoms:<\/p>\n<ul>\n<li>When attempting to log in to DSM, a screen appears informing users that data has been encrypted and a fee is required to unlock data.<\/li>\n<li>Abnormally high CPU usage or a running process called \u201csynosync\u201d (which can be checked at\u00a0Main Menu\u00a0&gt;\u00a0Resource Monitor).<\/li>\n<li>DSM 4.3-3810 or earlier; DSM 4.2-3236 or earlier; DSM 4.1-2851 or earlier; DSM 4.0-2257 or earlier is installed, but the system says no updates are available at\u00a0Control Panel\u00a0&gt;\u00a0DSM Update.<\/li>\n<\/ul>\n<p>If you have encountered the above symptoms, please shutdown the system immediately and contact our technical support here:\u00a0<a style=\"color:#0087e1;\" href=\"https:\/\/myds.synology.com\/support\/support_form.php\" target=\"_blank\">https:\/\/myds.synology.com\/support\/support_form.php<\/a><\/p>\n<p>If you have not encountered the above symptoms, we strongly recommend downloading and installing DSM 5.0, or any version below:<\/p>\n<ul>\n<li>DSM 4.3-3827 or later<\/li>\n<li>DSM 4.2-3243 or later<\/li>\n<li>DSM 4.0-2259 or later<\/li>\n<li>DSM 3.x or earlier is not affected<\/li>\n<\/ul>\n<p>You can manually download the latest version from our\u00a0<a style=\"color:#0087e1;\" href=\"http:\/\/www.synology.com\/en-global\/support\/download\" target=\"_blank\">Download Center<\/a>\u00a0and install it at\u00a0Control Panel\u00a0&gt;\u00a0DSM Update\u00a0&gt;\u00a0Manual DSM Update.<\/p>\n<p>If you notice any strange behavior or suspect your Synology NAS server has been affected by the above issue, please contact us at\u00a0<a style=\"color:#0087e1;\" href=\"mailto:security@synology.com\">security@synology.com<\/a>.<\/p>\n<p>We sincerely apologize for any problems or inconvenience this issue has caused our users. We\u2019ll keep you updated with the latest information as we continue to address this issue.<\/p>\n<p>Thank you for your continued patience and support.<\/p>\n<p>Sincerely,<br \/>\nSynology Development Team<\/p><\/blockquote>\n<p>As a rule of thumb, Synology users should put their DiskStations behind firewalls and disable port forwarding\u00a0for now. Make sure\u00a0the DiskStations are running the latest version of DSM possible. More importantly, backup the content of the DiskStation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Synology has been sending users email regarding the SynoLocker ransomware, mirroring\u00a0the\u00a0statement posted at Synology website\u00a0from August 5, 2014. Dear Synology users, We would like to inform you that a ransomware called &#8220;SynoLocker&#8221; is currently affecting some Synology NAS users. This ransomware locks down affected servers, encrypts users\u2019 files, and demands a fee to regain access &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/37prime.com\/news\/2014\/08\/07\/synology-issues-official-statement-to-address-synolocker-ransomware\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Synology Issues Official Statement to Address SynoLocker Ransomware&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[4],"tags":[2123,2472,2648,2871,2872,936],"class_list":["post-11649","post","type-post","status-publish","format-standard","hentry","category-news","tag-nas","tag-ransomware","tag-security","tag-synolocker","tag-synology","tag-tech"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pcNtU-31T","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/11649","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/comments?post=11649"}],"version-history":[{"count":0,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/11649\/revisions"}],"wp:attachment":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/media?parent=11649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/categories?post=11649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/tags?post=11649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}