{"id":5386,"date":"2025-07-16T10:13:11","date_gmt":"2025-07-16T10:13:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/16\/authorities-dismantled-diskstation-ransomware-attacking-synology-nas-devices-worldwide\/"},"modified":"2025-07-16T10:13:11","modified_gmt":"2025-07-16T10:13:11","slug":"authorities-dismantled-diskstation-ransomware-attacking-synology-nas-devices-worldwide","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/16\/authorities-dismantled-diskstation-ransomware-attacking-synology-nas-devices-worldwide\/","title":{"rendered":"Authorities Dismantled \u201cDiskstation\u201d Ransomware Attacking Synology NAS Devices Worldwide"},"content":{"rendered":"<p>    Authorities Dismantled \u201cDiskstation\u201d Ransomware Attacking Synology NAS Devices Worldwide<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Italian State Police, in collaboration with French and Romanian law enforcement agencies, have successfully dismantled the dangerous \u201c<a href=\"https:\/\/cybersecuritynews.com\/synology-network-file-system-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Diskstation<\/a>\u201d ransomware group that specifically targeted Synology Network-Attached Storage (NAS) devices across multiple countries.\u00a0<\/p>\n<p>The operation, coordinated through EUROPOL, resulted in the arrest of several Romanian nationals and exposed a sophisticated cybercriminal network that encrypted victim systems and demanded cryptocurrency payments for data recovery.<\/p>\n<pre class=\"wp-block-preformatted\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\"><strong>Key Takeaways<\/strong><br><\/mark>1. Italian police, with French and Romanian authorities, dismantled the \"Diskstation\" ransomware gang targeting Synology NAS devices globally.<br>2. Criminals encrypted business systems and demanded cryptocurrency ransoms from victims in various sectors.<br>3. Authorities used forensic analysis and blockchain tracking to trace the criminal network.<br>4. Several Romanian nationals arrested, with the main suspect (44) in detention for computer access and extortion charges.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Ransomware Gang Exploits Synology NAS Zero-Days<\/strong><\/h2>\n<p>The investigation began following numerous complaints from Lombardy-based companies whose IT infrastructure had been compromised through advanced ransomware attacks.\u00a0<\/p>\n<p>The cybercriminals employed sophisticated encryption algorithms to render business-critical data inaccessible, effectively paralyzing production processes across various sectors including graphic design, film production, and event organization.<\/p>\n<p>The Cybersecurity Operations Center in Milan conducted comprehensive <a href=\"https:\/\/cybersecuritynews.com\/free-forensic-investigation-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic analysis<\/a> of the attacked computer systems, utilizing advanced malware detection techniques and reverse engineering methodologies.\u00a0<\/p>\n<p>Investigators <a href=\"https:\/\/www.commissariatodips.it\/notizie\/articolo\/operazione-elicius\/index.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">performed<\/a> detailed blockchain analysis to trace cryptocurrency transactions, employing specialized tools to follow the digital money trail from victim payments to the perpetrators\u2019 wallets.\u00a0<\/p>\n<p>This dual-approach investigation methodology proved crucial in identifying the attack vectors and establishing the criminal network\u2019s operational structure.<\/p>\n<p>The ransomware group demonstrated particular expertise in exploiting vulnerabilities within Synology NAS devices, which are commonly used by businesses for data storage and backup solutions.\u00a0<\/p>\n<p>The attackers leveraged zero-day exploits and credential stuffing techniques to gain unauthorized access to these systems before deploying their encryption payloads.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Ransomware Ring Shut Down<\/strong><\/h2>\n<p>The complexity of the cybercriminal operation necessitated expanded international cooperation, leading to the establishment of a specialized task force coordinated by EUROPOL.\u00a0<\/p>\n<p>The collaborative effort included cyber crime units from Italy, France, and Romania, each contributing expertise in different aspects of the investigation including digital forensics, <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-cryptocurrency-and-blockchain-developers\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency analysis<\/a>, and cross-border legal procedures.<\/p>\n<p>During coordinated searches conducted in Bucharest in June 2024, investigators from the Milan COSC participated alongside Romanian authorities, successfully apprehending several suspects in the act of committing cybercrime.\u00a0<\/p>\n<p>The operation yielded substantial digital evidence confirming the investigative hypotheses and revealing the full scope of the criminal network\u2019s activities.<\/p>\n<p>The primary suspect, a 44-year-old Romanian citizen, has been placed in pre-trial detention by the Milan Court on charges of \u201cUnauthorized Access to a Computer or Telematic System\u201d and \u201cExtortion\u201d.\u00a0<\/p>\n<p>The charges reflect the serious nature of the crimes, which affected numerous Italian victims and demonstrated the international scope of the ransomware operation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt; <a href=\"https:\/\/any.run\/demo?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=red_flags&amp;utm_content=demo&amp;utm_term=070725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a>\u00a0<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/diskstation-ransomware-dismantled\/\">Authorities Dismantled \u201cDiskstation\u201d Ransomware Attacking Synology NAS Devices Worldwide<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/diskstation-ransomware-dismantled\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities Dismantled \u201cDiskstation\u201d Ransomware Attacking Synology NAS Devices Worldwide Italian State Police, in collaboration with French and Romanian law enforcement agencies, have successfully dismantled the dangerous \u201cDiskstation\u201d ransomware group that specifically targeted Synology Network-Attached Storage (NAS) devices across multiple countries.\u00a0 The operation, coordinated through EUROPOL, resulted in the arrest of several Romanian nationals and exposed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,231],"tags":[130],"class_list":["post-5386","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-ransomware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5386"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5386"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5386\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}