Threat Database Malware oom_reaper Malware

oom_reaper Malware

The oom_reaper malware threat is a new crypto-miner that targets the NAS (Network-Attached Storage) devices of the Taiwanese corporation QNAP. Details about the threat were released by the company itself in a new advisory report. According to QNAP's findings, oom_reaper takes over the device's hardware resources and uses them to mine for Bitcoins. The attacks are still under investigation and QNAP did not reveal the initial access vector that the cybercriminals used to infect its devices.  

Once deployed on the device, oom_reaper will try to mask its activity as a legitimate kernel process. However, its process identifier is typically set at more than 1000. While active, oom_reaper may cause unusually high CPU usage. In some instances, the malware threat was responsible for taking up around 50% of the total CPU usage. 

Owners of NAS devices manufactured by QNAP are encouraged to take preventive measures. For now, restarting the breached devices seems to remove the malware. QNAP also recommends updating the QTS and QuTS Hero operating systems to the latest available versions. Additional best practices include setting up strong passwords for the accounts with access to the device, as well as not exposing the NAS devices to the Internet. 

Trending

Most Viewed

Loading...