There is nothing new to report that I am aware of.
Posted 27 December 2023 - 09:11 PM
There is nothing new to report that I am aware of.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 05 January 2024 - 03:52 PM
hi
have same or similar problem
find description below
if threre are any news, I would really appreciated it for sharing
Best regards
Gasper
-----------------
Posted 05 January 2024 - 04:32 PM
When or if a free (or legitimate paid for) decryption solution is found, that information will be provided in this support topic and victims will receive notification if subscribed to it. In addition, a news article most likely will be posted on the Bleeping Computer front page.
Contents of !!_!!README!!_!!.txt which indicates they are calling this LegendaryDisk Security.
HI
This is LegendaryDisk Security.
What happened?
- Your Network was not secure.
- Your Network-Attached Storage was compromised.
What does this mean!?
Where are my files!?
- All your data has been encrypted and moved to a special shared folder.
- All your important documents have been downloaded.
What can I do to recover my data!?
- If you want to recover your data, you have to send 0.03 Bitcoin to this wallet address:
bc1pj3udvah8xelvenu93dm0dc9sllgmev2xcfvck5de2c6pc3hqpzxs2nnjvc
Always double check the address when copy/pasting it !!!!!
- You have up to 15 days to send the payment.
After this date the decryption will be almost impossible.
What should I do after sending the payment?
- Your ID is: Lne1rcbnmzce8:nas-h227:yg33fspkiee01
- Please email us your ID and payment confirmation(txid) to:
diskbleeper@onionmail.org
- After we confirm your payment you will receive the password and download link so you can mount the shared folder and decrypt all your data.
Can I still use my nas?
- Do not delete any files you find on your nas.
- Do not try to recover your data using any software as it will not work.
- Do not modify any volumes or storage pools on your nas.
- Do not write large amounts of data to your disk.
- Do not restart or power on/off your synology multiple times. It will result in archive corruption!
Why have my files been downloaded?
- We reserve the right to leak or sell all your important documents, if you don't contact us.
Where can I buy and send bitcoin?
- You can easily buy and send bitcoin from:
https://paxful.com/buy-bitcoin
https://paybis.com/
https://www.moonpay.com/buy/btc
https://noones.com/
https://www.bybit.com/en-us/learn/crypto/buy-bitcoin/
https://www.binance.com/en/buy-Bitcoin
https://localcoinswap.com/buy/bitcoin
Search for Bitcoin ATM's in your area.
You can think of this as a failed security audit.
We are professionals. This is a one time deal. We will decrypt a few files from your nas, as proof, if you need it.
We will send you the password immediately after the payment.
All Files, folders and subfolders will be unchanged.
We will even send you tips on how to strengthen your network security, to prevent any future attacks.
Thank you.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 05 January 2024 - 04:58 PM
Posted 05 January 2024 - 05:27 PM
Bad news. If you want your data you will have to negotiate with the hackers. The encryption in 7zip is robust and the password is long, meaning it is impossible to break the encryption. It would be interesting to know what version of the Synology DSM they were on when they were hacked
Did you managed to negotiate? if yes, did you get it cheaper and did you get all files back?
Posted 05 January 2024 - 05:34 PM
If you are thinking about paying the ransom, negotiating with the ransomware developers (which is not advisable) or using a data recovery service, you may want to read my comments about victim experiences in Should you pay the ransom? (Post #17) first.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 05 January 2024 - 05:48 PM
Posted 05 January 2024 - 05:50 PM
Posted 06 January 2024 - 04:30 AM
Posted 07 January 2024 - 02:10 PM
Posted 12 January 2024 - 01:31 PM
Hello.
This is DiskStation Security.What happened?- Your network was not secure.- Your Network-Attached Storage was compromised.What does this mean? Where are my files?- All your data has been encrypted and hidden on a special volume.- All your important documents have been downloaded.What can I do to recover my data?- If you want to recover your data, you have to send 0.12 Bitcoin to this wallet address:bc1qhphgyrn0pk7gfl2j2l3qmql97zny3kfpvlxt2cAlways double check the address when copying/pasting it!!!!!- You have until the 18th of January 2024 to send the payment.After this date your files will be almost impossible to recover.What should I do after I send the payment?- Your ID is: XXXXXXX- Please email us your ID and payment confirmation to:nasdata@beeble.comnasworker@protonmail.com- After we confirm your payment you will receive detailed instructions on how to decrypt all your data. It does not require any technical skills and it is done fast.Can I still use my nas?- Do not delete any files you find on your NAS.- Do not try to recover your data using any software as it will result in permanent data loss.- Do not modify any volumes or storage pools on your NAS.- Do not write large amounts of data to your disk.Why have my files been downloaded?- We reserve the right to leak or sell all your important documents, if no payment is made.Where can I buy and send bitcoin?- You can easily buy and send bitcoin from:You can think of this as a failed security audit.We are professionals. This is a one time deal.We will restore your data immediately after the payment.We will even send you tips on how to strengthen your network security, to prevent any future attacks.Thank you.
Posted 12 January 2024 - 02:03 PM
@nicovelas
DiskStation Security is probably another variant related to 7even Security, Umbrella Security, Quick Security & LegendaryDisk Security Ransomware. As such I have merged your topic into this one.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 12 January 2024 - 02:36 PM
Unfortunately, like 7even Security & Umbrella Security, there is no known method that I am aware of to decrypt files encrypted by DiskStation Security, Quick Security or LegendaryDisk Security without paying the ransom (not advisable) and obtaining the private encryption keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities. Without the criminal's master private key that can be used to decrypt your files, decryption is impossible. That usually means the key is unique (specific) for each victim and generated in a secure way (RSA, AES, Salsa20, ChaCha20, ECDH, ECC) that cannot be brute-forced.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 20 January 2024 - 10:21 AM
I had a Nas compromised with LegendaryDisk Security ransomeware, this is what I did:
/mnt/@synologydrive/@sync/repo/
file '/mnt/@synologydrive/@sync/repo/M/v/.X'
and you will get the type of file that you should use:
PDF Document, version 1.6+
I scan the entire disk with clamAV, no viruses but in your case could be different.
If you do not find any of your info, try to scan the folder for big files or folders using the command:
sudo du -h /mnt/@synologydrive/ --max-depth=1
and check the type of file using the file command.
Edited by ThomasKliet, 20 January 2024 - 10:22 AM.
Posted 08 February 2024 - 08:31 AM
Hi everyone!,
I`ve been hacked, the text of the rescue note is this:
0 members, 1 guests, 0 anonymous users