Synology Warns NAS Owners of Botnet-Creating StealthWorker Malware
The StealthWorker malware family is attempting to enlist network-attached storage (NAS) devices into a botnet used for a variety of purposes, according to Synology.
The company said these attacks don't exploit vulnerabilities in its products. Instead they "leverage a number of already infected devices to try and guess common administrative credentials" that can then be used to install malicious payloads without the owner's knowledge.
Those brute force attacks aren't particularly sophisticated, but they can be effective. Synology says "devices infected [by the malware] may carry out additional attacks on other Linux-based devices, including Synology NAS," and that the malicious payloads "may include ransomware." Spreading ransomware makes sense for a botnet targeting NAS devices. The entire point of the product category is to make storing important files, system backups, and private information easier; odds are good that a NAS owner would be upset about losing access to that data.