QNAP devices are being hacked to mine cryptocurrency

Ransomware
(Image credit: Shutterstock)

Crypto mining malware has once again targeted Network-Attached Storage (NAS) devices of popular Taiwanese storage manufacturer QNAP.

The new malware, discovered by researchers at Qihoo 360's Network Security Research Lab (360 Netlab), is exploiting an already-patched remote code execution (RCE) vulnerability, which allowed attackers to break into the device and use it for malicious crypto mining tasks. 

“According to the vendor’s request, we are not disclosing the technical details of the vulnerability in order to protect QNAP NAS users, [and] we speculate that there are still hundreds of thousands of online QNAP NAS devices with the vulnerability,” 360 Netlab noted in its report.

Unpatched targets

The researchers first noticed reports of the campaign in the beginning of March, quickly realising that what they dubbed UnityMiner could potentially infect all QNAP NAS devices running firmware versions that have not been patched since August 2020. 

Despite a fix being available for over six months, the researchers discovered over 4.2 million NAS devices all over the world that can be potentially exploited by the malware. 

Commenting on the workings of the malware, the researchers note that “the attacker customized the program by hiding the mining process and the real CPU memory resource usage information, so when the QNAP users check the system usage via the WEB management interface, they cannot see the abnormal system behavior.”

QNAP and the researchers have advised users to immediately update the firmware on their devices to thwart the attacks. 

Via: BleepingComputer

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Digital image of a lock.
QNAP says it has fixed several major vulnerabilities in NAS backup, recovery app
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
China
Chinese hackers targeting Juniper Networks routers, so patch now
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning