Diskstation is a ransomware group/malware operation that encrypts data on victims’ Synology Network-Attached Storage (NAS) devices and then demands payment for recovery. Reporting states the group recently targeted organizations in Italy’s Lombardy region, including businesses, NGOs, and media firms, causing data encryption and operational disruption. Ransom demands reportedly ranged from $10,000 to hundreds of thousands of dollars in cryptocurrency. The operation has been described as Romanian-based, with Italian police and Europol identifying several Romanian nationals as participants; a 44-year-old Romanian national was suspected of leading the activity, and a suspected primary operator was arrested in Bucharest during Europol-led Operation Elicius. High-confidence behavior directly mentioned in the content is limited to ransomware encryption of Synology NAS devices and subsequent extortion. No specific technical indicators of compromise were provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware targeting Synology NAS devices, encrypting data and demanding cryptocurrency ransoms from affected organizations.
Ransomware operation targeting Synology NAS devices, encrypting victim data and demanding ransom.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.