Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Quick Security-LegendaryDisk Security-DiskStation Security Ransomware


  • Please log in to reply
34 replies to this topic

#16 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 27 December 2023 - 09:11 PM

There is nothing new to report that I am aware of.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


BC AdBot (Login to Remove)

 


#17 duke666

duke666

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:07 AM

Posted 05 January 2024 - 03:52 PM

hi

 

have same or similar problem

 

find description below

 

if threre are any news, I would really appreciated it for sharing

 

Best regards

Gasper

 

-----------------
 

On January 3, 2023, I noticed that there was no data on the NAS or that certain folders were missing.
 
When checking the folders, I realized that he had left a txt file with the contents of how to transfer the ransom in order to get the data back.
since it is a txt file, I attached it as an attachment
name: !!_!!README!!_!!.zip
password: unzip
 
Known data or description:
  • as I was told on 3.1. noticed that documents are missing on the NAS - Synology
  • The NAS is connected to 3 other computers in the home household, so it mostly deleted the documents on those too, luckily not quite all
  • from what I saw (date of creation !!_!!README!!_!!.txt file) this happened on 01.01.2024@06:01
  • according to their log, the attached picture (Screenshot 2024-01-05 150705.png) shows that the volume of documents has dropped from approx. 6 (75%) to 2.7TB (38%) - I have 8TB disks in the NAS
  • logged on to the NAS via a web browser and found some documents in the #recycle folders, not all, but what belongs to this root folder. Unfortunately, some root folders do not have #recycle and as a result I do not know where this data is
  • I save the data on a local disk (I hope they are not infected as well)
 
I have a large amount of data, since there are several archives; personal archive with pictures and documents (logged root folders) and documentation of three companies.
 
As I said, I managed to download some data and I'm still "downloading" it via the web, with the fact that the NAS and PC in the connection are not online so that the "ransom-guy" can't see what's happening.
when I collect everything down, it will be necessary to organize everything in order to estimate how many documents are missing.
 
in the NAS, an acquaintance who is more skilled in computing found some file that was planted, but I said that he should not delete it until we have as much as possible downloaded.

Attached Files



#18 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 05 January 2024 - 04:32 PM

When or if a free (or legitimate paid for) decryption solution is found, that information will be provided in this support topic and victims will receive notification if subscribed to it. In addition, a news article most likely will be posted on the Bleeping Computer front page.
 
Contents of !!_!!README!!_!!.txt which indicates they are calling this LegendaryDisk Security.

HI
This is LegendaryDisk Security.
What happened?
- Your Network was not secure.
- Your Network-Attached Storage was compromised.
What does this mean!? 
Where are my files!?
- All your data has been encrypted and moved to a special shared folder.
- All your important documents have been downloaded.
What can I do to recover my data!?
- If you want to recover your data, you have to send 0.03 Bitcoin to this wallet address:
bc1pj3udvah8xelvenu93dm0dc9sllgmev2xcfvck5de2c6pc3hqpzxs2nnjvc
Always double check the address when copy/pasting it !!!!!
- You have up to 15 days to send the payment. 
After this date the decryption will be almost impossible.
What should I do after sending the payment?
- Your ID is: Lne1rcbnmzce8:nas-h227:yg33fspkiee01
- Please email us your ID and payment confirmation(txid) to:
diskbleeper@onionmail.org
- After we confirm your payment you will receive the password and download link  so you can mount the shared folder and decrypt all your data.
Can I still use my nas?
- Do not delete any files you find on your nas.
- Do not try to recover your data using any software as it will not work.
- Do not modify any volumes or storage pools on your nas.
- Do not write large amounts of data to your disk.
- Do not restart or power on/off your synology multiple times. It will result in archive corruption!
Why have my files been downloaded?
- We reserve the right to leak or sell all your important documents, if you don't contact us.
Where can I buy and send bitcoin?
- You can easily buy and send bitcoin from:
https://paxful.com/buy-bitcoin
https://paybis.com/
https://www.moonpay.com/buy/btc
https://noones.com/
https://www.bybit.com/en-us/learn/crypto/buy-bitcoin/
https://www.binance.com/en/buy-Bitcoin
https://localcoinswap.com/buy/bitcoin
Search for Bitcoin ATM's in your area.
You can think of this as a failed security audit.
We are professionals. This is a one time deal. We will decrypt a few files from your nas, as proof, if you need it.
We will send you the password immediately after the payment.
All Files, folders and subfolders will be unchanged.
We will even send you tips on how to strengthen your network security, to prevent any future attacks.
Thank you.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#19 jamessturge

jamessturge
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 05 January 2024 - 04:58 PM

Bad news. If you want your data you will have to negotiate with the hackers. The encryption in 7zip is robust and the password is long, meaning it is impossible to break the encryption. It would be interesting to know what version of the Synology DSM they were on when they were hacked.

#20 duke666

duke666

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:07 AM

Posted 05 January 2024 - 05:27 PM

Bad news. If you want your data you will have to negotiate with the hackers. The encryption in 7zip is robust and the password is long, meaning it is impossible to break the encryption. It would be interesting to know what version of the Synology DSM they were on when they were hacked

Did you managed to negotiate? if yes, did you get it cheaper and did you get all files back?



#21 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 05 January 2024 - 05:34 PM

If you are thinking about paying the ransom, negotiating with the ransomware developers (which is not advisable) or using a data recovery service, you may want to read my comments about victim experiences in Should you pay the ransom? (Post #17) first.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#22 jamessturge

jamessturge
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 05 January 2024 - 05:48 PM

We managed to negotiate. It wasn't cheap, the information was important, and we had to pay. They sent the password to decrypt the files with 7zip after receiving the payment. We learned that we must have a secondary backup to avoid massive data loss. The Synology brand disappointed me. I think the NAS was hacked for having Synology quickconnect active.

#23 jamessturge

jamessturge
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 05 January 2024 - 05:50 PM

We managed to negotiate. It wasn't cheap, the information was important, and we had to pay. They sent the password to decrypt the files with 7zip after receiving the payment. We learned that we must have a secondary backup to avoid massive data loss. The Synology brand disappointed me. I think the NAS was hacked for having Synology quickconnect active.

#24 duke666

duke666

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:07 AM

Posted 06 January 2024 - 04:30 AM

Another question is, if they hacked NAS, is there anything on PCs ?
I do have few financial programs or web site access that I don't want them to get.
All those are 2FA protected, but still it concerns me.
What program or service to use ?

When I will put all my data "leftovers" that I will find, there will be lots of duplicated data. What program do you suggest to use for sync it to avoid missing or duplicated files?


Thank you for Ans support

#25 jamessturge

jamessturge
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 07 January 2024 - 02:10 PM

Hackers take any vulnerability in the network or computers to infiltrate. You definitely can't depend on a single repository to store data. Some things we have implemented: antivirus with mandatory EDR for each computer on the network. Network segmentation with VLAN. Restriction of administrative access on computers. Backup in the cloud, with Microsoft 365 OneDrive + idrive. Recurring backup at the end of the day on external hard drive and in the cloud.

#26 nicovelas

nicovelas

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:07 AM

Posted 12 January 2024 - 01:31 PM

Hi, has anyone got any news about this ransomware? About how Yesterday I came across an almost identical ransom note, on my Synology NAS device, and apparently empty hard drives (with encrypted data). It's really frustrating not being able to do anything.
 
I upload the ransom note I received in case it can be of help. If anyone could give any hints on how to fix it that would be wonderful.
 

 

Hello.

 
This is DiskStation Security.
 
What happened?
 
- Your network was not secure.
- Your Network-Attached Storage was compromised.
 
What does this mean? Where are my files?
 
- All your data has been encrypted and hidden on a special volume.
- All your important documents have been downloaded.
 
What can I do to recover my data?
 
- If you want to recover your data, you have to send 0.12 Bitcoin to this wallet address:
 
bc1qhphgyrn0pk7gfl2j2l3qmql97zny3kfpvlxt2c
 
Always double check the address when copying/pasting it!!!!!
 
- You have until the 18th of January 2024 to send the payment.
After this date your files will be almost impossible to recover.
 
What should I do after I send the payment?
 
- Your ID is: XXXXXXX
- Please email us your ID and payment confirmation to:
 
nasdata@beeble.com
nasworker@protonmail.com
 
- After we confirm your payment you will receive detailed instructions on how to decrypt all your data. It does not require any technical skills and it is done fast.
 
Can I still use my nas?
 
- Do not delete any files you find on your NAS.
- Do not try to recover your data using any software as it will result in permanent data loss.
- Do not modify any volumes or storage pools on your NAS.
- Do not write large amounts of data to your disk.
 
Why have my files been downloaded?
 
- We reserve the right to leak or sell all your important documents, if no payment is made.
 
Where can I buy and send bitcoin?
 
- You can easily buy and send bitcoin from:
 
 
You can think of this as a failed security audit.
 
We are professionals. This is a one time deal. 
We will restore your data immediately after the payment.
We will even send you tips on how to strengthen your network security, to prevent any future attacks.
 
 
Thank you.

 



#27 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 12 January 2024 - 02:03 PM

@nicovelas

DiskStation Security is probably another variant related to 7even Security, Umbrella Security, Quick Security & LegendaryDisk Security Ransomware. As such I have merged your topic into this one.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#28 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 12 January 2024 - 02:36 PM

Unfortunately, like 7even Security & Umbrella Security, there is no known method that I am aware of to decrypt files encrypted by DiskStation Security, Quick Security or LegendaryDisk Security without paying the ransom (not advisable) and obtaining the private encryption keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities. Without the criminal's master private key that can be used to decrypt your files, decryption is impossible. That usually means the key is unique (specific) for each victim and generated in a secure way (RSA, AES, Salsa20, ChaCha20, ECDH, ECC) that cannot be brute-forced.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#29 ThomasKliet

ThomasKliet

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 20 January 2024 - 10:21 AM

I had a Nas compromised with LegendaryDisk Security ransomeware, this is what I did:

 

  1. Mount RAID HDDs into a Ubuntu PC (follow the instructions here: https://kb.synology.com/tr-tr/DSM/tutorial/How_can_I_recover_data_from_my_DiskStation_using_a_PC)
  2. Could not find an encrypted zip file anywhere, so go to the folder:
     /mnt/@synologydrive/@sync/repo/ 
  3. There you can find your info disorganized and renamed to folders and files like .W or a-z list of names.
  4. In the terminal type:
    file '/mnt/@synologydrive/@sync/repo/M/v/.X'
    

    and you will get the type of file that you should use: 

    PDF Document, version 1.6+
    
  5. I scan the entire disk with clamAV, no viruses but in your case could be different.

  6. If you do not find any of your info, try to scan the folder for big files or folders using the command:

    sudo du -h /mnt/@synologydrive/ --max-depth=1
    

    and check the type of file using the file command.


Edited by ThomasKliet, 20 January 2024 - 10:22 AM.


#30 hromerov

hromerov

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:07 AM

Posted 08 February 2024 - 08:31 AM

Hi everyone!, 

 

I`ve been hacked, the text of the rescue note is this:

 

"Hello.
 
This is DiskStation Security.
 
What happened?
 
- Your network was not secure.
- Your Network-Attached Storage was compromised.
 
What does this mean? Where are my files?
 
- All your data has been encrypted and hidden on a special volume.
- All your important documents have been downloaded.
 
What can I do to recover my data?
 
- If you want to recover your data, you have to send 0.12 Bitcoin to this wallet address:
 
bc1qka3qxgr0c8y0szf68wjv7ywla2l9uhvxj825dq
 
Always double check the address when copying/pasting it!!!!!
 
- You have until the 10th of February 2024 to send the payment.
After this date your files will be almost impossible to recover.
 
What should I do after I send the payment?
 
- Your ID is: pro-office
- Please email us your ID and payment confirmation to:
 
NASDATA@TUTA.IO
nasfile@protonmail.com
NAS-DATA@yandex.com
 
- After we confirm your payment you will receive detailed instructions on how to decrypt all your data. It does not require any technical skills and it is done fast.
 
Can I still use my nas?
 
- Do not delete any files you find on your NAS.
- Do not try to recover your data using any software as it will result in permanent data loss.
- Do not modify any volumes or storage pools on your NAS.
- Do not write large amounts of data to your disk.
 
Why have my files been downloaded?
 
- We reserve the right to leak or sell all your important documents, if no payment is made.
 
Where can I buy and send bitcoin?
 
- You can easily buy and send bitcoin from:
 
 
You can think of this as a failed security audit.
 
We are professionals. This is a one time deal. 
We will restore your data immediately after the payment.
We will even send you tips on how to strengthen your network security, to prevent any future attacks.
 
 
Thank you."
 
Anyone knows what ransomware is?

Thanks!





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users