My computer is being hacked!

I’ve been hacked …

Sorry to hear that. It’s unclear what it is you want from this post though.

Sorry to hear that. Hopefully you have a backup and can rebuild. Personally, I would not give in to this kind of extortion.

Out of curiosity, what is your core running on, and how is it connected to your network & internet?

More likely, it’s the remote being hacked, no?

1 Like

I have Roon Rock on NUC … this is the second time it happened any one know of a fix please?

What does your setup look like? What does your network look like? What is connected to what?

You’ll need to give a lot more info in order for us to help you.

Where is your local music, and what OS do you use for Roon remotes?

Typically, ransomware is spread via email phishing, and once login credentials are disclosed, they can access parts of your network. It is unlikely that ROCK was the source of the attack.

3 Likes

Whatever worked for you the first time would seem the obvious place to start?

.sjb

How can anyone install any of this inside ROCK?

It is inside every folder of ROCK

As previously mentioned, ROCK isn’t the source of the hack. Start with your email and, most likely, Windows PC.

So, please confirm what you use for your Roon remotes, and where your music files are located.

Remote is my android phone and the files are on a HD connected using USB to NUC/ROCK

Do not expose your ROCK/Nucleus(+) to the internet. They are not considered secure devices and should only be installed in secured private networks. If you want to use ARC, create a port-forward rule for the one Port used by ARC only.

Some information about this ransomware and how it supposedly attacks computers can be found following this link: https://www.bleepingcomputer.com/forums/t/753400/0xxx-nas-ransomware-0xxx-support-topic/?p=5232606

1 Like

This have happened since i created a port forwarding set up for remote ARC access

1 Like

My bet here is that the core has been added to a DMZ and has been compromised that way.

I am a Cyber Security Analyst and would be willing to help you (for free). Direct message me if you would like to chat about what to do next and how to avoid this happening a 3rd time.

21 Likes

This.

You’re being very sparse with details here.

What did you do exactly to do the port forwarding? Was your NUC directly connected to your router by any chance?

A very good question…

That would be child’s play I’m afraid. ROCK and Nucleus expose a network share to the network that doesn’t require any form of authentication.

Anyone or anything with access to your local network can access your ROCK installation as well. And therefore also add, edit, delete files on your ROCK.

If you then also put your ROCK installation into a DMZ of your router, then the whole internet has access. It’s the equivalent of begging to be hacked.

2 Likes

Child’s play if someone has already gained access to your home network. And, to be clear we’re talking about a file share, not breaching ROCK*.

What’s needed is more relevant information from the OP.

*Edit: 0xxx ransomware affects Windows PC hosts only, and can be removed with the Sophos virus removal tool.

2 Likes