Synology BackUP
Case Study: Recovery of 5 TB of Encrypted Synology Hyper Backup Data Following a Booba Ransomware Attack
On June 29th, an IT service provider and its Swiss-based clients suffered a major cyberattack orchestrated by the Booba ransomware group. The client had a total of 3 Synology NAS units.
📌 At a Glance (TL;DR)
- Infection: Booba ransomware attack on a company based in Switzerland.
-
The Challenge: A portion of the backup data could not be recovered by another lab. Recoveo—having deeper expertise in this specific type of backup (Synology Hyper Backup)—was brought in to take over. The Booba ransomware had encrypted part of the Hyper Backup files.
-
SOS Ransomware / Recoveo Solution: Custom R&D (2 days of dedicated development) enabling the recovery of
.bucketand.chunkfiles. -
Final Result: 5 TB of restored data (1.8 million files), representing 98% of the data recovered and returned to the client.
Context
The client operated a total of 3 Synology NAS units:
1 Data Center NAS: Completely encrypted.
1 On-site Backup NAS: Hit by the ransomware.
1 NAS dedicated to virtual machines (4-bay compact model): Unaffected and fully functional.
Fortunately, the client’s Proxmox infrastructure with Proxmox Backup Server was not compromised, allowing them to bring all affected virtual machines (approx. 50) back online in less than 8 hours.
Only two of their clients, along with the IT provider itself, were still facing data loss. One virtual machine (Virtual DSM) belonging to a client remained completely encrypted.
Proactive Measures Taken by the Client to Mitigate the Impact
The client had managed to recover a portion of their data through another data recovery lab. As a precaution, they had also copied the backup data from the undamaged NAS to another system using a rsync command line interface.
However, a portion of the backup data could not be restored by the first lab. Recoveo was contacted due to our advanced mastery of Synology Hyper Backup. The Booba ransomware had encrypted several Hyper Backup files. In total, there were 8 nested shared folders within the Hyper Backup container (.hbk), 2 to 3 of which were critical for the client.
The client had also managed to stop certain ransomware processes early on, which significantly maximized our chances of recovery. Key file types and extensions had remained untouched by the ransomware.
The client was looking to recover raw data files—files without extensions, or with extensions such as .bucket, .chunk, as well as files named with long strings of numbers and letters. These represent the deduplicated data “blocks”: real files, but fragmented, mixed together, and encrypted.
The Solution: A Tailored Technical Response
A Proprietary Tool Proven on Multiple Cases
During the initial recovery phase—using an in-house tool previously deployed on a dozen similar cases—our engineering team successfully recovered 3.89 TB of chunks, amounting to 1.5 million files.
The Result: 98% of Data Recovered in 4 Business Days
Following 2 days of custom development dedicated specifically to this case, our R&D team generated the final dataset: 5 TB of data (1.8M files), representing a 98% recovery rate delivered back to the client.
Client Testimonial
"Thanks to Recoveo and their SOS Ransomware team, we were able to recover nearly 100% of the target data following what was a mentally exhausting few days for us after the attack."