Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Case study

Makop encrypts a university research group's Synology NAS

A lab's Synology NAS, exposed to the internet with weak credentials, was encrypted by Makop, affecting years of research data. Recovery layered NAS snapshots, local copies on workstations and remnant extraction.

Industry
Education and Research Ransomware Response
Family
Makop
Scenario
Synology Encrypted
Handled
2026-07

This case study is composed from typical scenarios to illustrate our approach and the recovery paths involved. It does not describe a specific customer incident; real cases involving customer data are published only with authorization.

  • 约 93%

    Research data recovered

  • NAS 快照 + 本地副本

    Primary recovery sources

  • 约 4 天

    Time to delivery

  • 0

    Ransom paid

Incident background

The client is a university research group using a Synology NAS to store experimental data, measurement records, paper drafts and figure assets — several years of accumulation across tens of terabytes. The NAS was administered by students on rotation, and to allow off-campus access, port forwarding and quick-connect features were enabled, the administrator account kept a simple password, and two-factor authentication had never been turned on.

Snapshots had been enabled on the NAS but, when capacity got tight, were reduced to a short retention period. A plan to sync to an external drive was never carried out; that drive stayed permanently mounted on the NAS as extended storage.

One weekend a team member found files in the shared folders would not open: filenames carried an appended suffix containing random characters and a contact email, and a short ransom note text file sat in every directory. The management interface still logged in, but packages and some system directories were affected too. The mounted external drive was encrypted as well.

With a project nearing its final review and some raw measurement data impossible to re-collect, the team was under real pressure, and paying the ransom was raised as an option.

What we did

Two things were settled on the first call: do not reset the NAS, do not remove and reinstall packages, and do not rush into paying — inventory the available data sources first, then decide.

  • Containment. Port forwarding and quick-connect were disabled, all sync and package tasks stopped, the external drive unmounted to prevent further writes, and the ransom note plus one encrypted sample preserved.
  • Family confirmation. The suffix structure and note format identified a Makop variant with no usable public decryptor, ruling out decryption.
  • Source inventory. First, the most recent snapshot still held on the NAS — short retention, but it happened to cover the day before the incident. Second, local copies cached on members' workstations from routine analysis. Third, attachments from submitted papers and intermediate versions in shared cloud documents. Fourth, remnant data in the volume's unallocated space.
  • Layered recovery. Most shared directories were rolled back from the snapshot; workstation copies filled in what had been added since; for raw measurement files still missing, remnant scanning and file-signature reassembly on the volume image restored files in bulk by type; finally the team confirmed completeness directory by directory.
  • Access control rebuilt. Direct internet exposure removed in favour of the university VPN, administrator and user accounts separated, and two-factor authentication enabled.

Recovery result

The large majority of research data and paper assets were recovered: the bulk of the shared directories came from the snapshot rollback, data added after the snapshot came mainly from workstation copies, and remnant scanning retrieved a further batch of raw measurement files. What was ultimately confirmed unrecoverable was a small set of intermediate result files that existed only on the NAS and were created outside the snapshot window — most of which the team rebuilt by recomputation. No ransom was paid.

Attribution was straightforward: the management interface had been exposed through port forwarding for a long time, logs showed days of automated password attempts, and a common weak password eventually succeeded, after which encryption ran from inside the NAS. This is the most common path in NAS incidents at universities and small teams in China — the device itself is not fragile; the fragile part is the combination of exposing it publicly for convenience, a weak password, and no two-factor authentication.

Afterwards the team adopted three basic rules: the NAS is never exposed directly to the internet; the administrator account uses two-factor authentication and a rotated password; and important data keeps at least one external copy that is refreshed periodically and disconnected afterwards rather than left mounted. Snapshot retention was also restored to a sensible length.

This is an illustrative case compiled from typical scenarios and anonymized; it does not refer to any specific institution or team.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.