

It’s not clear yet how SynoLocker’s operators installed the malware, for example, if they had exploited a vulnerability in Synology devices. After the most important files was copied I turned of my disk.” Therefore I started to copy my most important files to another disk while encryption was in progress on other files. When I open the main page on the webserver i get a message that SynoLocker has started encrypting my files and that I have to go to a specific address on Tor network to get the files unlocked. That is, if you can backup files faster than the program encrypts them. According to the user, there’s a small window of opportunity to minimise the damage.

As one victim on Synology’s English user forum commented, the SynoLocker “service” asks for 0.6 Bitcoins to unlock the encrypted files, which at today’s exchange rate is around USD$350.
