How to defend against DeadBolt ransomware attacks?
ANSWER
There has recently been an active campaign exploiting NAS servers. QNAP® Systems, Inc. (QNAP) issued a statement in response to a new type of ransomware called DeadBolt. As stated by the manufacturer:

DeadBolt has been widely targeting all NAS exposed to the Internet without any protection and encrypting users' data for Bitcoin ransom.
What recommendations does QNAP provide?
- Block internet access to the web-based administration panel (it is also advisable to disable: Enable UPnP Port forwarding).
- Update to the latest firmware version.
- Close all ports accessible on the device from the internet.
DeadBolt ransomware attacks target only NAS devices exposed to the internet, and given that the attackers claim to be exploiting a zero-day vulnerability, it is recommended that these devices be disconnected from the internet.
- https://www.qnap.com/pl-pl/security-news/2022/take-immediate-actions-to-stop-your-nas-from-exposing-to-the-internet-and-fight-against-ransomware-together
- https://www.bleepingcomputer.com/news/security/qnap-warns-of-new-deadbolt-ransomware-encrypting-nas-devices/
- https://nascompares.com/2022/01/26/qnap-nas-attacked-by-deadbolt-ransomware/


