Protecting NAS Systems from Cryptoviruses (Ransomware)

Note: The strategy presented here is universal for Synology DiskStation devices running DSM 7.x. The settings have been tested in practice on Synology DS223j.
Table of Contents
- Understanding the Threat
- Basic Protective Measures
- Snapshot Protection (Most Important!)
- 3-2-1 Backup Strategy
- Network Security
- Access Control
- Monitoring and Alerts
- Recovery Plan
1. Understanding the Threat
How Do Crypto Viruses Work?
Crypto viruses typically infect a NAS in the following ways:
- Infected computer — a virus on your Windows/Mac computer encrypts the files on the NAS
- Open ports — direct access to the NAS from the internet
- Weak passwords — brute-force attacks
- Malicious applications — installed unofficial packages
- Phishing — theft of the admin password
What happens during an attack?
- All files are encrypted (photos, documents, videos)
- Extensions such as .locked, .encrypted, and .crypted are added
- A ransom is demanded in cryptocurrency
- RAID 1 DOES NOT HELP - The virus encrypts both drives simultaneously!
2. Key Protective Measures
Step 1: Strong Passwords and 2FA
Changing Passwords:
- Control Panel > Users & Groups
- Select each user > Edit
-
Set a STRONG password:
- At least 12–16 characters
- Upper- and lowercase letters
- Numbers and special characters
- Example: M@gicN4S!2025&Secure
- Use a password manager (Bitwarden, 1Password)
Enabling two-factor authentication (2FA):
- Control Panel > Users & Groups
- Select a user > Edit
- Go to the “2-factor Authentication” tab
- Enable 2FA
-
Scan the QR code with an app such as:
- Google Authenticator
- Microsoft Authenticator
- Authy
Step 2: Automatically block attacks
Account Protection:
- Control Panel > Security > Account
- Enable account protection: YES
- Enable auto block: YES
-
Settings:
- Login attempts: 5
- Within (minutes): 5
- Block for (minutes): 60 or permanently
- Apply
Trusted IP list (optional):
- Add the IP addresses of your devices
- This way, you won’t be blocked accidentally
Step 3: Firewall
Enabling the Firewall:
- Control Panel > Security > Firewall
- Enable firewall: YES
- Tabs: “Firewall Profile” > Edit Default Profile
Recommended rules:
Port | Protocol | Allowed/Blocked | Description |
---------------------------------------------------------------------------+
5000-5001 | TCP | Allow (LAN only) | DSM Web Interface (HTTP/HTTPS)|
22 | TCP | Deny (or LAN only) | SSH |
21 | TCP | Deny | FTP |
139,445 | TCP | Allow (LAN only) | SMB/CIFS |
All other | All | Deny | Block everything else from the WAN |
---------------------------------------------------------------------------+
Important:
- Allow access ONLY from the local network
- Block all ports from the Internet (WAN)
- If you need external access → use QuickConnect or VPN
Step 4: Disable Unnecessary Services
Control Panel > File Services:
- FTP: Disable (if you don’t need it)
- FTPS: Disable (if you don’t need it)
-
SMB: Enable (required for Windows sharing)
- Minimum SMB version: SMB2 or higher (not SMB1!)
- AFP: Disable (legacy Mac sharing)
- NFS: Disable (if you’re not using Linux/Unix clients)
Control Panel > Terminal & SNMP:
- SSH: Disable (or change the port and allow access only from specific IP addresses)
- Telnet: Disable (NEVER enable it!)
Step 5: Updates
Automatic Updates:
- Control Panel > Update & Restore
-
DSM Update:
- Install the latest DSM update automatically: YES
- Send me email notifications of available updates: YES
-
Check for package updates regularly:
- Package Center > Settings
- Auto-update important packages: YES
3. Snapshot Protection (MOST IMPORTANT!)
Why are Snapshots Critical?
Snapshots are THE MOST POWERFUL protection against ransomware! They are snapshots of the file system that:
- Are created in seconds
- Take up minimal space (only the changes)
- Allow recovery to a specific point in time before the attack
- Ransomware CANNOT encrypt them (if they are configured correctly)
Configuring Snapshots
Prerequisite:
- You must use the Btrfs file system
- If you were using ext4, you must recreate the volume (data will be lost!)
Step 1: Enable Snapshot Replication
- Package Center
- Install “Snapshot Replication”
- Launch the application
Step 2: Create a Snapshot Schedule
- Snapshot Replication > Snapshots
- Select the shared folder (e.g., “Documents”)
- Create > Snapshot Schedule
Recommended configuration:
For critical folders (Documents, Photos):
Frequency:
- Hourly: the last 24 hours (keep 24 snapshots)
- Daily: the last 7 days (keep 7 snapshots)
- Weekly: the last 4 weeks (save 4 snapshots)
- Monthly: the last 3 months (save 3 snapshots)
For less critical folders (Downloads, Temp):
Frequency:
- Daily: the last 7 days
- Weekly: the last 4 weeks
Step 3: Lock the Snapshots (IMPORTANT!)
- Settings > Advanced
- Enable: “Lock snapshots”
- Retention period: select a lock period (e.g., 30 days)
This makes the snapshots read-only, and even the administrator cannot delete them!
Step 4: Hiding Snapshot Directories
- Snapshot Replication > Settings > Advanced
- Disable: “Make snapshot visible”
This hides the #snapshot folder from users and viruses!
Checking Snapshots
Check regularly:
- Snapshot Replication > Snapshots
- Check to see if snapshots are being created correctly
- Check the space used
Restore test:
- Once a month, try to restore a file from a snapshot
- This confirms that the process is working
4. 3-2-1 Backup Strategy
The 3-2-1 Rule:
- 3 copies of the data
- 2 different types of media
- 1 offsite copy
Option A: Hyper Backup (recommended)
Installation:
- Package Center > Hyper Backup
- Install
Option 1: Backup to a USB drive
- Connect an external USB drive to the DS223j
- Hyper Backup > + (Create backup task)
- Select “Local Folder & USB”
- Select the USB drive
- Select the folders to back up
-
Encryption: REQUIRED!
- Set a strong password
- Save it in a password manager
-
Schedule:
- Daily backup during the night (e.g., 3:00 AM)
- Compression: Enable
- Intelligent versioning: Enable (keep 256 versions)
Option 2: Cloud backup
- Hyper Backup > + (Create)
-
Select a cloud service:
- Synology C2 Storage (paid, but native)
- Google Drive (free up to 15GB)
- Dropbox
- OneDrive
- Backblaze B2 (inexpensive, $6/TB/month)
- Set up connection
- Select the folders
- Encryption: REQUIRED!
- Schedule: Weekly or Daily
Option 3: Backup to another NAS (if you have one)
- Hyper Backup > +
- Remote NAS Device
- Enter the IP and credentials for the second NAS
Important settings in Hyper Backup:
- Backup rotation: Smart Recycle (to save space)
- Integrity check: Enable (checks the backups)
- Notifications: Email on success/failure
Option B: Cloud Sync (for synchronization)
Difference between Hyper Backup and Cloud Sync:
- Hyper Backup: versioned backup (you can roll back)
- Cloud Sync: real-time synchronization (like Dropbox)
For ransomware protection: Hyper Backup is better!
Cloud Sync is useful for:
- Quick access to files from anywhere
- Sharing with others
- BUT: ransomware can sync encrypted files
If you use Cloud Sync:
- Package Center > Cloud Sync
- Set up the connection
-
IMPORTANT: Enable versioning in the cloud:
- Google Drive: retains versions for 30 days
- Dropbox: retains versions for 30 days (or 180 with a paid plan)
5. Network Security
Step 1: No direct access from the Internet!
Check port forwarding:
- Log in to the router’s admin panel
- Check Port Forwarding / Virtual Server / NAT rules
-
Delete ALL rules for:
- Ports 5000, 5001 (DSM)
- Port 22 (SSH)
- Ports 445, 139 (SMB)
- Port 21 (FTP)
If external access is required, use:
Option A: QuickConnect (most secure)
- Control Panel > External Access > QuickConnect
- Enable QuickConnect
- Create a QuickConnect ID (for example: mynasname)
- Access via: quickconnect.to/mynasname
- Traffic passes through Synology servers (secure)
Option B: VPN Server (more complex, but very secure)
- Package Center > VPN Server
- Install
- Configure OpenVPN or L2TP/IPSec
- Connect to the VPN as if you were on the local network
- Then access the NAS locally
DO NOT use:
- DDNS + Port Forwarding (dangerous!)
- UPnP (automatically opens ports)
Step 2: Isolating the NAS on the network (advanced)
If your router supports VLANs:
- Create a separate VLAN for the NAS
- Restrict access between VLANs
- This way, if a computer becomes infected, it cannot directly access the NAS
If you don’t have VLANs:
- Place the NAS on a separate subnet (if possible)
- Use a guest network for untrusted devices
6. Access Control
Step 1: Principle of Least Privilege
Creating a read-only user:
- Control Panel > User & Group > Create
- Name: “readonly_user”
- Password: strong password
-
Shared folder permissions:
- For critical folders: Read-only
- For work folders: Read/Write (only if necessary)
Use the read-only user for:
- Viewing photos/videos
- Listening to music
- Reading documents
Use the read/write user ONLY when:
- Copying new files
- Editing documents
- Then log in with the read-only account
Step 2: Restricting SMB access
Control Panel > File Services > SMB > Advanced:
- Max SMB protocol: SMB3
- Min SMB protocol: SMB2
- Enable: “Opportunistic locking” (helps against ransomware)
Windows additional protection:
On the Windows computer:
- Map the network drive using “Connect using different credentials”
- Map as a read-only user by default
- Unmap after working with the files
Step 3: Disable the Recycle Bin (controversial)
The Recycle Bin can help with accidental deletions, BUT:
- Ransomware can also encrypt files in the Recycle Bin
- It takes up space
Solution:
- For critical folders: Disable the Recycle Bin
- Rely on system snapshots for recovery
- For working folders: Enable (for convenience)
7. Monitoring and Alerts
Step 1: Set up email notifications
Control Panel > Notification > Email:
- Enable email notifications
-
SMTP settings:
- Service provider: select one or Custom
-
For Gmail:
- SMTP server: smtp.gmail.com
- Port: 587
- SMTP authentication: Yes
- Username: your Gmail address
-
Password: App Password (not your regular password!)
- Google Account > Security > 2-Step Verification > App passwords
- Send test email
Enable notifications for:
- System: Critical errors, updates
- Storage: Disk failures, space warnings
- Security: Login attempts, firewall blocks
- Backup: Hyper Backup success/failure
- Snapshots: Snapshot creation failures
Step 2: Log Center
- Package Center > Log Center
- Install
- Configure log archiving (stores them for a long time)
Check regularly:
- Connection logs for unusual activity
- File access logs for suspicious operations
- Security logs for failed login attempts
Step 3: Security Advisor
- Control Panel > Security Advisor
- Run a security scan regularly (weekly)
- Fix all High and Medium severity issues
Important checks:
- Default admin account (has it been changed?)
- Weak passwords
- Exposed services
- Outdated packages
8. Recovery Plan
If you suspect a ransomware attack:
STEP 1: IMMEDIATE ACTIONS
-
DISCONNECT FROM THE NETWORK!
- Unplug the Ethernet cable from the NAS IMMEDIATELY
- Do not turn off the power (this may damage the drives)
- Isolate the infected computers
- DO NOT pay the ransom!
STEP 2: ASSESS THE DAMAGE
- Log in via HDMI/USB keyboard if possible
- Or briefly connect to the network to check the status
-
Check which files are affected:
- Are there any new file extensions (.locked, .encrypted)?
- Are there any ransom note files?
STEP 3: RECOVERY FROM A SNAPSHOT
If you have snapshots (that’s why they’re critical!):
- Snapshot Replication
- Select the affected folder
- View snapshots from before the attack
-
Restore:
- Option A: Restore the entire folder
- Option B: Browse the snapshot and copy specific files
Restore process:
- Snapshot Replication > Snapshots
- Select the shared folder
- Select a snapshot from before the attack (check the date/time)
- Click Action > Restore
-
Select:
- - Restore to original location (replaces the files)
- - or Clone to new location (preserves the encrypted files)
- Confirm
STEP 4: RESTORE FROM HYPER BACKUP
If snapshots are not sufficient:
- Hyper Backup > Restore
- Select a backup task
- Select the version prior to the attack
- Restore the selected folders/files
STEP 5: CLEANUP AND PREVENTION
- Scan ALL computers with antivirus
- Change ALL passwords
- Review security settings
- Upgrade DSM and all packages
- Check firewall rules
- Check which users/applications have access
Security Checklist
Daily:
- Automatic snapshots are working
- Monitor for unusual activity
Weekly:
- Check email notifications
- Verify that Hyper Backup was successful
- Scan with Security Advisor
Monthly:
- Test a restore from a snapshot
- Test a restore from Hyper Backup
- Check disk space
- Review logs in Log Center
- Check for DSM updates
As needed:
- Change passwords (every 3–6 months)
- Review user permissions
- Update the backup strategy
Additional recommendations
For Windows computers:
Ransomware Protection (Windows 11/10):
- Settings > Update & Security > Windows Security
- Virus & threat protection > Ransomware protection
- Enable Controlled folder access
- Add NAS folders to Protected folders
Antivirus:
- Install a high-quality antivirus (Windows Defender is a good option)
- Enable real-time protection
- Regular scans
Rule:
- DO NOT open suspicious attachments
- DO NOT click on links in emails from strangers
- Update Windows regularly
For Mac computers:
- Gatekeeper: Keep it enabled
- XProtect: Built-in antimalware
- Time Machine: Back up your Mac to a separate drive
Offline backup
The most secure protection:
- Buy 2–3 external USB drives
- Perform a monthly backup to one of the drives
- UNMOUNT the drive and store it in a safe place
- Rotate the drives
That way, even in the worst-case scenario, you’ll have an offline copy!
Summary
The Golden Rules Against Ransomware:
- ✅ Locked snapshots—the most important protection!
- ✅ 3-2-1 Backup Strategy—including offsite
- ✅ Strong Passwords + 2FA—on all accounts
- ✅ Firewall + blocked ports—no direct WAN access
- ✅ Updates — always the latest DSM and packages
- ✅ Read-only access — whenever possible
- ✅ Monitoring — email alerts and regular checks
- ✅ Testing — regularly test restores
Remember:
RAID 1 protects against hardware failure, BUT NOT against ransomware!
The only true protection is:
- Snapshots (cannot be encrypted)
- Offsite backups (physically separate)
- Strong security (attack prevention)
If you follow this guide:
- ✅ Ransomware won’t be able to destroy your data
- ✅ You can recover in minutes or hours
- ✅ You can sleep soundly
Good luck, stay cautious, and stay safe!
Add Comment