NAS326 encrypted by ransomware ("ANON RTS LOCKER", .anon extension) – no UPnP/DyDNS enabled, need he

Options
jockeman
jockeman Posts: 2 image  Freshman Member

Hi

My NAS326 got encrypted by ransomware. All files now have the original name plus a ".anon" extension (e.g. photo.jpg.anon), and a text file ransom note calling itself "ANON RTS LOCKER" was dropped in the folders. The note demands 0.007 BTC and lists Bitcoin addresses, a TOX ID, and contact emails.

What's confusing me is the entry point. I've checked:

  • UPnP Port Mapping (Network > UPnP Port Mapping): all services (AFP, CIFS, FTP, HTTP, MediaServer, WebDAV) are disabled.
  • DyDNS (Network > DyDNS): disabled, no hostname configured, no external address shown.
  • My Windows laptop, which was used to access the NAS: no trace of any malicious executable, nothing suspicious in Defender's protection history or Prefetch around the infection date (~21 Aug 2025).

So it looks like neither UPnP nor DyDNS was exposing the NAS, and the laptop itself seems clean. I suspect either manual port forwarding was set up on my router at some point, or the NAS was compromised through a firmware vulnerability directly.

Questions:

  1. Is "ANON RTS LOCKER" a known ransomware variant that's been hitting NAS326 devices? I've seen mentions of eCh0raix, Checkmate, and Want_to_Cry on NAS326 in other threads here, but the note's name doesn't match any of those directly.
  2. Given that UPnP and DyDNS were both off, what other attack vectors should I check on the NAS side? (Old firmware version, exposed services, etc.)
  3. Is there any known decryptor for the ".anon" extension / this ransom note format on NAS326 specifically?

My firmware version: V5.21(AAZF.18)

No router port-forwarding DyDNS or UPnP.

Any guidance is appreciated.