Menu
Hacked Synology NAS systems used in high-profit cryptocurrency mining operation

Hacked Synology NAS systems used in high-profit cryptocurrency mining operation

A hacker earned over $600,000 by infecting network-attached storage devices with Dogecoin mining malware, Dell SecureWorks researchers said

A hacker exploited publicly known vulnerabilities to install malware on network-attached storage systems manufactured by Synology and used their computing power to generate Dogecoins, a type of cryptocurrency.

The operation took place during the first months of the year and is likely the most profitable of its kind to date, earning the attacker over US$600,000 according to a recent analysis by researchers from Dell SecureWorks.

Using CPUs and GPUs to solve cryptographic problems as part of cryptocurrency systems is an activity referred to as mining. Those who perform it -- typically using their own systems -- are automatically rewarded by the system with units or subunits of that respective currency.

At the beginning of February reports started appearing online from users complaining about sluggish performance and high CPU usage on their Synology NAS systems, which have a Linux-based operating system called DiskStation Manager (DSM) developed by the Taiwan-based manufacturer.

The problems were tracked to an unauthorized application running on affected systems from a directory called PWNED that turned out to be a custom version of a cryptocurrency mining program called CPUMiner specifically compiled for Synology's DSM OS, the Dell SecureWorks researchers said Friday in a blog post.

An analysis of the rogue program showed that it had been configured to mine Dogecoin, a peer-to-peer cryptocurrency similar to Bitcoin that was launched in December 2013.

The Dell SecureWorks researchers identified two electronic wallet addresses associated with the rogue mining activity and determined that their owner had mined over 500 million Dogecoins, worth about $620,000, mostly during January and February.

"To date, this incident is the single most profitable, illegitimate mining operation," the researchers said. "This conclusion is based in part on prior investigations and research done by the Counter Threat Unit, as well as further searching of the Internet."

Evidence found on various websites suggests the hacker responsible for the attack uses the online alias "Foilo," is of German descent and has used malware and exploits before. The SecureWorks researchers believe the affected Synology NAS systems were compromised by exploiting vulnerabilities publicly disclosed in September 2013 by security researcher Andrea Fabrizi.

Synology released DSM updates to block the PWNED attacks in February.

The incident is the latest on a growing list of mass attacks against embedded devices reported this year. According to security experts, attackers are shifting their focus from desktop applications to such devices because they're plagued by basic vulnerabilities and can't be easily secured by nontechnical users.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags malwareintrusionsynologypatchesExploits / vulnerabilitiesDell SecureWorks

Events

SustainTech

Join key decision-makers within Environmental, Social, and Governance (ESG) that have the power to affect real change and drive sustainable practices. SustainTech will bridge the gap between ambition and tangible action, promoting strategies that attendees can use in their day-to-day operations within their business.

EDGE 2023

EDGE is the leading technology conference for business leaders in Australia and New Zealand, built on the foundations of collaboration, education and advancement.

WIICTA 2023

ARN has celebrated gender diversity and recognised female excellence across the Australian tech channel since first launching WIICTA in 2012, acknowledging the achievements of a talented group of female front runners who have become influential figures across the local industry.

ARN Innovation Awards 2023

Innovation Awards is the market-leading awards program for celebrating ecosystem innovation and excellence across the technology sector in Australia.

Brand Post

Show Comments