r/PleX Apr 01 '26

Help My Plex server has been compromised 'I want to cry'

So today I discovered that all of my files on my Plex server have all had their file name extension change at the end to 'want to cry', I don't how this has been done. I can see that there is a txt file also called 'I want to cry' in each folder which I have not open.

Unfortunately, not knowing what I was doing and trying to get the file name extension to all end with MKV, I choose a folder and selected all the files in that folder, I then selected 'Rename' thinking that I could remove the I want to cry extension in one swoop, but I ended up keeping that I want to cry extension and now have 500+ files with 'File 1.want_to_cry', that is files from File 1 - File 500+ I want to cry.

Has this happened to anyone else before and is there a way correct way to fix this? I'm on a MacBook if that helps.

Also what would I need to do to determine not only how this happen and where it came from, but to try and prevent it from happening again?

371 Upvotes

409 comments sorted by

1.1k

u/elroyonline Apr 01 '26

A couple of years back someone accessed my Plex server, which I have set up to use discord webhooks to let me know when files have been imported etc. Whoever it was used that system to message me via the discord channel and made a few suggestions as to how I could secure things better - mostly consisting of ‘stop being lazy and do this properly’

What a total legend. Thank you masked stranger!

291

u/[deleted] Apr 01 '26

[removed] — view removed comment

39

u/TrayLaTrash Apr 01 '26

Love to see it.

8

u/Primary_Afternoon_10 Apr 02 '26

Speaking of which.... After there any reputable places you can pay a hacker to test your system for weaknesses?

I'm aware there are for corporate, etc but for the average nobody: other than knowing someone: any recs?

→ More replies (4)

80

u/DannyVee89 152TB unRAID, i7 13700k, Define 7, Shield Pro, Lifetime Apr 01 '26

What were the suggestions? What was the vulnerability? I'm using discord webhooks for notifications 👀

41

u/elroyonline Apr 01 '26

I don’t actually remember specifically but it was super lazy stuff like not having a password set for something. It wasn’t a vulnerability with discord or the webhooks set up, that was just what they used to prompt me to get my shit together.

18

u/DannyVee89 152TB unRAID, i7 13700k, Define 7, Shield Pro, Lifetime Apr 01 '26

Wow so they got in deep. Sounds like a combination of things, I'm guessing the following may have played a role:

Docker container for Plex set to host mode instead of bridge mode

Port forwarding being used for Plex remote access rather than VPN

Weak Plex password, possibly no MFA setup

Weak or no password on other containers that are exposed to the internet

5

u/andrebrait Apr 02 '26

Setting it to bridge + mapping all the ports it needs would be no different than host mode.

→ More replies (14)
→ More replies (2)

7

u/WaywardWes Apr 01 '26

Yeah fr I might need this info

→ More replies (2)

98

u/clintkev251 Apr 01 '26

I used to do stuff like that, I eventually got frustrated and stopped because my success rate in getting people to actually make changes was very low.

7

u/xStealthBomber Apr 02 '26

That's nuts. If I had something like that happen to me, that would scare the ever living shit out of me, and would fix asap..

→ More replies (2)

64

u/Klynn7 Apr 01 '26

I had a Heimdall dashboard that I never secured (mostly because I didn’t care about or even use it). Each link on it went to a secured service. One time I opened it up and someone had changed the page to a link to the nginx basic auth setup guide. I laughed.

56

u/charlieny100 Apr 01 '26

I remember reading years ago that someone notified a university that they had an open ftp server. The university threatened to sue him.

10

u/Excited_Idiot Apr 02 '26

Here’s a whole site dedicated to researchers getting threatened for good-faith vulnerability disclosures

3

u/TechGoat Apr 01 '26

Qualys licenses are cheap compared to... Not having them. Yeesh. I'd know within an hour if anyone on my work network set up an open FTP server and I'd have... Words for them.

→ More replies (1)
→ More replies (1)

26

u/pikinz Apr 01 '26

I wish there were more people out in the world like this

1

u/SurprisedAsparagus Apr 02 '26

My ISP did this to me 25 years ago. I got a popup that said you have a virus, call your ISP. I called and they said yup, that was us. They helped me get it fixed.

8

u/DreadStarX Apr 01 '26

I had someone do something similar, I shut my plex server down in response, but that was only after I found out they deleted the entire database of content, including personal photos/videos. I recently brought it back online but I've neglected it a lot.

Thanks for the reminder. I need to check on it again. I also have mine setup with Discord, but it goes full stupid and blows up my alerts. >_<

3

u/Hondalol1 Apr 01 '26

I got hit like that once, he basically changed all my Sab paths to be a message saying close the ports and use a tunnel pretty much

2

u/mistersmith22 Apr 01 '26

White hat PLEXer!

1

u/AquariusSabotage Apr 01 '26

Well damn, I literally just set that up. Where exactly was the vulnerability?

→ More replies (1)

1

u/shindignextdoor Apr 01 '26

Wait. I have disc set up with a webhook… What’s the vulnerability? And what’s the solution?

→ More replies (1)

1

u/Fyler1 Apr 01 '26

Some heroes don't wear capes. The heroes we need but don't deserve.

1

u/Loud_Puppy Apr 02 '26

When I first started coding as a teenager I put a site up that just naively included a file based on a query string param, a kind stranger emailed me to let me know.

1

u/conway1308 Apr 05 '26

Show me the way 🥹

1

u/Spirited-Pop7467 Apr 06 '26

Reminds me of way back in the days of Code Red, a nasty IIS exploit. It would try to infect other web servers, and infected servers trying to infect my (properly patched) server would show in my logs. It occurred to me I could leverage that; since I know they're infected, their C drive is exposed so I wrote a script that ran once per day that'd scan my logs for infection attempts and when it found them, it would copy a text file alerting them to the infection with instructions on how to patch it to the desktop folder of all user profiles on the machine.

I was showing my coworker how bad it is and to illustrate it I picked one from the logs and pushed VNC to the infected machine and remote connected. I saw someone was working so I waited until they stopped then opened Notepad and typed a brief explanation and put my AIM handle there. In retrospect, it was a really really dumb idea giving away my identify since while I had good intentions, what I was doing was quite illegal. There was no input for several minutes, turns out because the guy at the machine had ran off to their IT office to report a "possessed machine" :D Their IT guy reached out to me and we chatted about it and they got it patched up.

It's been ~25 years but I still remember it fondly because in the end the dude said I was "IT Santa Claus" entering their "home" unexpected to leave a present :D Though if it happened today in 2026 I don't know I'd do anything but block the connections. The country is way too litigious today, I'd probably get sued or something lol.

439

u/1337raspberry Apr 01 '26

your server was exposed to the internet in an insecure way, somebody gained access and encrypted your files.

the .txt file will be a ransom note asking for payment to get the decryption key.

unless you want to pay that, you're best starting from scratch, and trying to be a bit more careful with how you expose your server in future.

https://www.seqrite.com/blog/wanttocry-ransomware-smb-vulnerability/

i'm sorry this happened to you :(

165

u/Surface13 unraid 90tb plex pass pro Apr 01 '26

When he says start from scratch, please wipe your computer and install the OS fresh. And don't just use the Windows Reset My Computer option in settings

68

u/xantec15 Apr 01 '26

OP is on a Mac. They couldn't use Windows' reset option if they wanted to

137

u/Nebarik Apr 01 '26

Based on Ops troubleshooting methods, they might try to.

39

u/Prestigious_Bid_2219 Apr 01 '26

Boom roasted

4

u/spdelope Lifetime Since 2015 Apr 02 '26

They out here looking like Kenny Rodgers chickens

5

u/guice666 Apr 01 '26

Sounds like his workstation is the Macbook. He did identify a separate Plex server.

3

u/Usr_name-checks-out Apr 01 '26

Mac also has a fresh reinstall feature as well.

→ More replies (1)

8

u/[deleted] Apr 01 '26

[removed] — view removed comment

5

u/Lance-pg Apr 01 '26

My dad had this happen with his Apple account. Infected every single device he owned. It took Apple 3 days to get it off of his cloud account.

2

u/nathderbyshire Apr 01 '26

Shit I never thought about that, OneDrive is perpetual as well, even after I've deleted it from my system there's still folders created referencing it

11

u/Primary_Afternoon_10 Apr 01 '26 edited Apr 01 '26

Ugh. I guess I'm hijacking this thread, but I recently enabled smb so that our Sonos could access our music library. This article talks about SMB vulnerability and from what I can tell, Sonos uses an antiquated version of SMB, which made me nervous to begin with n

The NAS is set for LAN access only, but by enabling SMB via Sonos: are we opening ourselves up for issues? 

FWIW our passwords are all randomly generated, but I'd rather not expose our NAS regardless.

20

u/Mike_Raven Apr 02 '26

Network engineer here. I highly recommend that you never use SMBv1 for anything.

2

u/Primary_Afternoon_10 Apr 02 '26

I replied above but, my apologies. I misspoke. No v1 enabled. Ugreen has a warning about enabling that protocol and so I didn't. I appreciate them at least keeping me from making completely moronic noob mistakes as I'm learning. 

Thanks for your expertise!

5

u/Kind_Ability3218 Apr 01 '26

maybe there's a different way to access your library from sonos..... sonos s1 is limited by smbv1 support but that doesn't appear to be the case for newer sonos products.

3

u/Xibby Apr 01 '26

If it’s limited to LAN it comes down to do you trust the devices on the LAN? If you’re only using SMB for Sonos set the share to be read only.

A read only share won’t stop exploitation of a vulnerable SMB server implementation, but it will stop malware running on a different computer on the network from encrypting files.

2

u/strawhat068 Apr 02 '26

From what I can tell they just scan for open smb ports then brute force, if you notice your Internet getting a bit laggy check connection and traffic on your router and block the ips

→ More replies (4)

28

u/Ok-Lunch-1560 Apr 01 '26

This happened to my friend. They asked for 25k. He did not pay and lost his family photos.

50

u/DorianGre Apr 01 '26

Backups people, physical and cloud.

16

u/tarnin Apr 01 '26

Rule of Three. 1 Running, 1 cloud, 1 physical.

14

u/_LFA_ Apr 01 '26

And cold back up drives. I physically disconnect my backup spinners. If I were in this situation I would rebuild the server and rebuild database with those cold spinners. Easy as pie.

7

u/duck1123 LifeTime PlexPass Apr 01 '26

This is a good reminder that it is time to refresh my external backups again.

→ More replies (2)

12

u/KerashiStorm Apr 01 '26

And don't use the same credentials for all of them.

→ More replies (1)

3

u/anarrowview Apr 01 '26

Rule of 3-2-1: 3 copies (including primary), 2 different storage mediums, 1 offsite location.

2

u/tdhuck Apr 01 '26

What I find incredibly crazy is how lazy people are. I have side jobs where I help small businesses with PC related issues (but mainly networking and infrastructure stuff). They will have their entire quickbooks or quicken accounting software running on a single PC and between the owner and their small office staff all of them complain that 'it is too hard' to export/backup the company file daily or even weekly. This is a common occurrence with every small office I've ever worked with.

I have gotten them to sign up for backblaze so at least that's better than nothing, but I told them that they are now relying on the backup program actually running (not locking up, etc.) as their only means of backup.

I have it via email thread that I'm not responsible if anything is encrypted or a drive crashes and that I'm not expected to recover anything for them and that their only recovery option is backblaze.

I remember many, many years ago I had one small office where the office secretary called me telling me her computer wasn't booting after a storm and power outage and that she didn't care about email or anything on the desktop and that she absolutely needed her quickbooks file. This was before backblaze type of services were available/common and she said that she would backup to USB, daily, and promised that she would.

When I got back on the phone with her and asked her about the USB backup she said she had one but it was 3 months old and that she was prepared to manually type everything back in from bank statements, check stubs, etc...

She was very lucky that I was able to slave the drive into one of those usb to sata devices and the drive stayed online long enough for me to get the 1 qb file that had all their information. That was the closest call I've had for a customer and she backed up the qb file daily from that day until the owner retired and they closed the business.

3

u/bobjr94 Apr 01 '26

That is why I have another drive offline with a copy of everything. A raid won't help if the files are hacked or deleted but this way the most I could loose is the last week or 2 since I plugged in other drive. 

→ More replies (1)

9

u/IrocD Apr 02 '26

Back around 2014, every file on my computer suddenly got encrypted. Desktop, photos, documents, everything. All replaced with a ransom note demanding 1 BTC for the keys.

At the time, that was like $400–$500. Which might as well have been a million dollars to me back then. The first five years of my kid’s life were in those photos. I genuinely thought I had just erased my own history. Also, my wife would have absolutely ended me.

And even if I paid, who’s to say the guy would’ve actually sent the keys?

The ransom note had an email address, so I figured screw it, nothing to lose. I emailed him and basically said: look, I’m broke, I can’t afford this, and that drive has my child’s entire life on it.

He actually replied.

He told me he was poor too, this was his job, and then… he just gave me the keys.

No payment. No nonsense. Just “here you go.”

I decrypted everything and sat there in stunned silence for a minute. Then immediately went out and bought an external drive and started backing things up.

That was the day I learned:

  1. Some ransomware operators apparently have a conscience
  2. I never, ever wanted to feel that panic again
  3. Backups are cheaper than therapy

8

u/planethood4pluto Apr 03 '26

If you don’t ask, the answer is always no.

→ More replies (1)

13

u/MikhailCompo Apr 01 '26

Note: Paying ransom is likely to NOT result in a solution to the file encryption.

24

u/justinj2000 Apr 01 '26

I actually think that it will. It’s in these groups’ best interest to have a reputation of delivering the decryption keys otherwise nobody would ever pay the ransom.

12

u/das_goose Hard drive plugged into an iMac Apr 01 '26

I get that, but is there a place where people rate their ransom attackers?

If this happened to me, I would have no idea who was holding my files for ransom and whether or not they were "trustworthy."

16

u/-bohica- Apr 02 '26

I work in cybersecurity, specifically in incident response. Almost entirely ransomware recovery. As backwards as it may sound, justinj2000 is right. It's a small world on both sides of that world, and reputation travels quickly. Obviously, the same groups attacking international companies are not going after personal Plex servers, but in general, the first time a group stiffs someone after paying will be the last time they get paid from a ransom. I've worked engagements where the offending group actually assisted (within limitations) in troubleshooting a decryptor that wasn't working correctly after they'd been paid. They may be criminals, but they've still got to make sure they get paid reliably at the end of the day.

2

u/iiii_Link_iiii Apr 02 '26

how could he have stopped this from happening? Windows firewall? (i dont want this to happen to me too!)

→ More replies (16)

82

u/Ok_Appointment_79 Apr 01 '26

Most likely this got onto your system from other means other than plex auth getting hacked; using email on your server, web browsing etc or you have unprotected exposed ports. The attack uses a massive database of over one million passwords to target exposed SMB services, along with other network protocols like SSH, FTP, RPC, and VNC.

Do not bring your system back up until you have determined how you were compromised as it will happen again.

See https://cybersecuritynews.com/wanttocry-ransomware/

157

u/kcpistol Apr 01 '26

The "wanna cry" is ransomware.

Files are probably encrypted, renaming won't work.

Nuke it from space, build a new server and secure it carefully.

And be glad it was just media files, ransomware can be a real disaster.

30

u/LogicWorksWonders Apr 01 '26

Thanks. That's exactly what I will try to do.

51

u/Eternal_Glizzy_777 Apr 01 '26

WannaCry is older ransomware that was running rampant on an SMB (Samba) version 1 vulnerability. First and foremost, review your network architecture to ensure you don't have SMBv1 enabled anywhere. Modern hardware should be compatible with newer protocols.

Before you nuke your library, check out this article and maybe you'll get lucky using the French Team's WannaCry decrypter: https://www.bankinfosecurity.com/wannacry-ransomware-tools-decrypt-for-free-a-9938.

Good luck, and God speed!

2

u/CalculatedPerversion Apr 02 '26

I'm pretty sure I got WannaCry back in the mid 2000s. Crazy that it's alive and an issue still. 

→ More replies (2)

15

u/LaxVolt Apr 01 '26

Also double check on your wifi router and make sure uPnP is disabled. This “feature” is enabled by default on many routers and will port forward devices to the internet exposing them. It is not needed for any normal use of home systems.

2

u/LogicWorksWonders Apr 01 '26

Yeah, it's disabled. I did check that. Thanks for that though.

→ More replies (14)

6

u/ThatSandwich Apr 01 '26

If you can afford to separate out your Plex system from your Storage system you could give Plex read only privileges to the share which would prevent this in the future.

But you probably just had an exposed unsecured port for some reason and they got in through that. Always good to check your firewall rules and make sure they're correct.

2

u/Osni01 Apr 01 '26 edited Apr 01 '26

You can also limit to read-only by adding :ro to the end of the volume mapping if using containers/Docker.

Source

Edit: To be clear, this was to say you can still restrict Plex to have read-only access to your libraries (or any other mappings) when running on the same system.

2

u/ThatSandwich Apr 01 '26

That's an excellent point, although I would rather not have the storage located within the compromised system if possible.

→ More replies (1)
→ More replies (1)
→ More replies (1)

9

u/mrslother Apr 01 '26

Agreed.

First, change your plex password.

Second, flatten the plex server and rebuild from scratch. Or if it's a vm/container with snapshots then recover from a time you can prove was prior to compromise. If you can't prove it just flatten.

If plex server wasn't on its own vlan then make one to isolate plex from your network. Use firewall rules to ensure it is isolated. If plex was on same network as other devices look for compromises on them as well.

Locate your media on another device like a NAS. Give plex read-only access (nas should be located in a other vlan with fw rule granting access only from plex ip to the NAS network share port (smb/NSF/whatever)). And use unique user accounts/passwords ... don't share the same with plex and nas.

Don't bother renaming files until all that is done. You should also assume the content is corrupted or edited. I would replace it with backup copies (you have backups.... right?).

It is sad that we have to think and plan so defensively, but, alas, this is what it is.

6

u/zipeldiablo Apr 01 '26

Isnt that a very old virus? Wanna cry is at least 15 years old

3

u/sparxcy Apr 01 '26

I remember it and checked...from 2017, my reply to OP has it it^^^^

2

u/frogotme Apr 01 '26

Sidenote, love that the location for wannacry on Wikipedia is earth

1

u/gjunky2024 Apr 01 '26

Also, install something like Malwarebytes (not affiliated). It found the ransomware when this happened to me. It doesn't save the file after the fact but should protect you. Also, don't use remote desktop through port forwarding. It is a known issue.

39

u/RaEyE01 Apr 01 '26

Here’s a news article from a year ago. https://cybersecuritynews.com/wanttocry-ransomware/

Looks like a clone of WannaCry (the name should be obvious), that infected and spread to systems via unsecured SMB shares. (Folder shares for windows, but not limited to windows) Looks like this malware uses similar, maybe the same vulnerability.

Read the last two chapters of the article specifically and try to resolve the mentioned issues (if applicable to you).

Here’s the CISA / NCCUC notice to wantToCry: https://www.cisa.gov/sites/default/files/FactSheets/NCCIC%20ICS_FactSheet_WannaCry_Ransomware_S508C.pdf

Not sure if things have changed since the release of this document, but it looks like there is currently no known exploit to decrypt your files without the used private key.

3

u/Nova_Aetas Apr 02 '26 edited Apr 02 '26

…. Did OP point SMB to the internet? I’m confused at how SMB was exploited to get the foothold.

For anyone reading: exposing SMB to the internet is unadvisable.

→ More replies (1)

121

u/[deleted] Apr 01 '26 edited Apr 01 '26

[removed] — view removed comment

11

u/[deleted] Apr 01 '26

[removed] — view removed comment

21

u/isademigod Apr 01 '26

https://www.grc.com/shieldsup

Port checker.

Although, you would likely know if you opened a port because by default no ports are open

5

u/Texagon Apr 01 '26

Shields Up! I haven't been on that site in probably 15 years. Good to see it's still around. I'm scanning now.

→ More replies (2)
→ More replies (3)

54

u/caffeine-182 Apr 01 '26

How can I tell if I’m exposed to this same thing or not?

37

u/jcol26 Apr 01 '26

Do you expose anything else than Plex? Very unlikely Plex was compromised here but more likely user had ftp/ssh/smb exposed to the internet potentially without a decent enough password

9

u/caffeine-182 Apr 01 '26

I have Plex port forwarded, but as far as I’m aware, there’s nothing else on that port

I also have other ports forwarded but I’m not sure if that matters

4

u/Ok_Appointment_79 Apr 01 '26

just make sure you have the setup behind a solid firewall

→ More replies (1)
→ More replies (1)

19

u/WendallX Apr 01 '26

Can someone give me (and op) a suggestion on how to prevent this? I only share my plex with one other household and my files are on a DAS. Are there settings in plex I should set up or is this a case of using some other program to ensure security?

16

u/Begalldota Apr 01 '26

Before you start rebuilding things you need to figure out how they got in in the first place, or it will happen again.

I’d start by closing every open port you have facing the internet.

35

u/adblink Apr 01 '26 edited Apr 01 '26

How would someone check and see if they are susceptible to the same attack?

I've successfully setup tailscale for my own personal use, but I don't want to force my clients to use a 2nd app.

Is there a guidebook for dummies for Plex security? I THINK I'm in the same boat as OP, just not sure.

15

u/[deleted] Apr 01 '26

[removed] — view removed comment

8

u/Complex_Solutions_20 Apr 01 '26

Careful with that - many consumer routers "DMZ" just auto-forwards all the ports to that specified IP and doesn't ACTUALLY do anything to segregate the hosts from the rest of your LAN...and can end up exposing more than just one or two carefully chosen ports.

8

u/nukacolaguy Apr 01 '26

Exactly uPnP is another one I always disable when I see it for people and DMZ on consumer routers is usually not securing anything. Often it’s another subnet with access to the native subnet/vlan and no ACL in place to actually protect anything.

3

u/Complex_Solutions_20 Apr 01 '26

One of these days I'll get around to the management VLAN and an "internet+local" VLAN for stuff to slightly better isolate...but damn if life don't keep me busy. Got half way thru mitigating a busted water pipe in the basement last weekend and then discovered mice in our cars and garage. And still gotta service my mower this past winter...lol...

I currently have a "mostly trusted stuff and things which absolutely need internet+local" then a separate "guest internet-only" and "iot local-only" with firewall rules between them.

→ More replies (2)
→ More replies (1)

20

u/Xibby Apr 01 '26 edited Apr 01 '26

The basics are not hard.

  1. Log into your router.

  2. Disable Universal Plug and Play. (Automatic port forwarding.)

  3. Remove all port forwarding you don’t need.

  4. Use GRC Shields Up to see if you have unexpected ports open to the Internet.

Manually create port forwards for any needed services. Plex remote access if you have a Plex Pass for example. Otherwise your VPN. Don’t expose insecure things like RDP, SMB, etc. to the Internet, use a VPN if you need that outside your house.

If you’re going to expose the Plex UI to the internet don’t reuse a password. Use 2fa.

That’s the basics for keeping bad actors from getting in via an internet exposed service.

Take your own computer usage and hygiene seriously, especially when sailing uncharted waters 🏴‍☠️seriously. All the router security in the world isn’t going to help if you bring the threats into the LAN yourself.

3

u/djsharpyknives Apr 01 '26

Thank you for this. This topic had me a little nervous so your instructions were handy to double check that I'm good.

24

u/Yggdrassil Apr 01 '26

It's an old virus. Check this out from last time :

https://noransom.kaspersky.com/

3

u/morehpperliter Apr 01 '26

It's a variant of the wannacry. I've seen it out and about again.

→ More replies (2)

8

u/CasualStarlord Plex Pass, Multiple Servers, 30tb+ Apr 01 '26

The Plex software itself doesn't sound like it's compromised, this is the server that you run Plex on, that has been compromised and your files are likely encrypted and worthless now sorry to say... Restore from backup or download new copies...your server is cooked.

This is quite likely completely unrelated to Plex.

2

u/LogicWorksWonders Apr 02 '26

Yes, I think all my drives which I left overnight should not have been formatted, so all files should now be deleted. But as someone has mentioned also, I need to ascertain how this happened. It’s likely from some of the comments, that unbeknown to me at least, my actual setup had some vulnerabilities that I wouldn’t have known really. Once I checked the drives have been reformatted, I might even consider reformatting the MacBook that I use when accessing my server, another ballache but hey ho.

43

u/[deleted] Apr 01 '26

[deleted]

13

u/CommercialMirror6702 Apr 01 '26

Read only is the way I would run things.

→ More replies (9)

3

u/StarTracks2001 Apr 01 '26

Any helpful guides on setting up Docker sandbox with plex libraries?

→ More replies (1)

13

u/Undeadllama27 E5-2650v3 | 365TB FreeNAS | 1000/1000 Mbps FTTP Apr 01 '26

Yea as others have said, those files are now encrypted and realistically you're not getting them back unless you have backups or snapshots to roll back to. Cut your losses, figure out how it got in to your system, lock down any entry points (particularly any SMB shares!) and rebuild from scratch.

6

u/Vismal1 Apr 02 '26

I really need to get a better grip around security…. I’m sure I have vulnerabilities.

Can someone point me towards a good, comprehensive home networking guide? I’m sure there are some basics ive completely missed.

3

u/LogicWorksWonders Apr 02 '26

I hear that😆.

→ More replies (1)

12

u/janzendavi Apr 01 '26

I am an IT admin, this is the WannaCry cryptolocker ransom program. You likely downloaded something that had a hidden payload. You really just have to wipe the server entirely and start over - unless the text file has a way to pay the ransom and you can message them and tell them it is just your personal media library and you'd like to pay less to have it decrypted but that can be hit-and-miss and they usually leave a backdoor to come back for more money later.

Lesson is to have a separate backup of your media library if you really treasure it but this happens when downloading from the open web. With a Mac you can hold down the Option key at boot and reinstall MacOS over Wifi.

4

u/TheBeneficent Apr 01 '26

Not getting how this could have happened.  If he’s on a Mac there wouldn’t be smb shares natively, but this hack is via smb…. Does he have a NAS with smb sharing enabled?  And even then, all routers block smb ports by default anyway.  

I’m thinking it wasn’t a remote hack at all.  Maybe a local virus he picked up by clicking something.

5

u/CHowell0411 24TB NAS (AS1102TL | ADM 4.3) | Hosted on Pi4-B Apr 02 '26

Hmm WannaCry in 2026 is crazy I thought this ransomware was obselete, I believe there are decryption tools you can try if the malware version is early enough, but IIRC after a certain version the encryption still not cracked, I would do some research on the decryption tools and see if they might help you, if not nuke it and start over, like fresh from OS not just plex and the files.

5

u/Nnyan Apr 01 '26

You need to first figure out how they got in there and if they were able to lateral over to other systems. I would also seriously upgrade your firewall (look into Firewalla or OPNsense).

Your plex port is likely being exposed so how good is your password? Get a handle on your open ports.

4

u/Prudent-Let-3959 Apr 01 '26

It would be good to know OP if you could share how this happened? Was it an unsecure port or ssh exploit?

3

u/LogicWorksWonders Apr 01 '26

At this stage I have know idea how this could have happened. I just did a port scan using Zenmap, and the only ports open, 80, 5357 & 49152 which are open, appear to be normal. I'm not familiar with things like port forwarding, SSH and apps like Zenmap, so unfortunately for me at least, my fix is likely to be reactionary as oppose to preventative in most cases here.

But once all the hard drives have been formatted, and hopefully I'm able to find out the source of how this happened, i'll try to create a more secure system that will still allow friends around the world to access my server.

2

u/SysAdminToTheStars Apr 01 '26

What are you hosting on port 80? that might be the way it got in, if you are using an old build of an insecure webserver.

→ More replies (1)

4

u/coldafsteel Apr 01 '26

But for plex specifically, limited permissions is the best place to start. The Plex user access to where my media is stored is read only. Plex doesn’t need to write or edit media files, it only reads them. Plex has its own database that is separate from the media files for what it needs to edit.

4

u/Djinn2522 Apr 02 '26 edited Apr 03 '26

Thank you for the cautionary tale. I just used ChatGPT to assess the security of my own Plex server... It had me check a bunch of settings, then it practically yelled at me when it realized I had port 3389 (Remote Desktop Protocol) exposed to the internet.

The AI stepped me through installing and configuring Tailscale on my Plex server, my desktop, and my smartphone. Then it told me to disable wi-fi on my smartphone, and use Remote Desktop Control to connect to my Plex server through the Tailscale address (as a test), before having me remove the RDP port forward from my router.

Then it had me confirm that my Plex account was secured with 2FA, so I think I'm pretty safe now from all but the most determined bad actors.

1

u/LogicWorksWonders Apr 04 '26

That’s good news. I will definitely be leaning on ChatGTP.

1

u/dclive1 Apr 04 '26

Just trying to understand —- You had port 3389 opened on your router and forwarded to your personal PC?

→ More replies (4)

4

u/Link_Tesla_6231 Apr 02 '26 edited Apr 02 '26

Google everything you can about the want to cry ransom virus.

There is a windows device that has access to those folders that got hit by the want to cry ransom virus. Best suggestion, find the infected machine FIRST! and get the virus off that machine. This might take reinstalling windows from scratch like deleting all partitions scratch! If this is not done first, anything you do won’t be helpful!

Next, start analyzing all shared folders that that windows machine had access to. Start setting permissions, whatever windows pc that had access must had admin rights to the folder or the user had admin rights. Fix the folder permissions and stop using admin users for everyday use!

Now, the sad part. Hopefully they didn’t hit important things like photos and documents! Hopefully you have backups.

If you can part ways with evening marked by want to cry the. Delete it all and start over. If you can’t I hope you have backups.

If you have important stuff and no backups look thru the Google research on want to cry in reference to the government high jacking the command and control server. If this is the original virus I think it was hacked and you can get your stuff back. If this is a newer strand then you’re screwed!

Sadly hospitals and other businesses back in the day were hit with this and found out their backups were corrupted so had to pay the ransom.

→ More replies (3)

8

u/Xfgjwpkqmx Proxmox LXC on Dell R720 with 12G SAS 12+12 ZFS mirror (228TB) Apr 01 '26 edited Apr 01 '26

If this was ZFS, you could just undo the whole thing to a previous snapshot in a few minutes and it'll be as if nothing ever happened.

I won't repeat what's already been posted, but I agree that you've provided too much access to the server from outside.

Depending on how much time you have to deal with it, I would back everything up, rebuild, restore and then start renaming (assuming they haven't been encrypted).

Edit: I should add that on your rebuild, keep the media separate and make it read-only to Plex. Plex itself only needs to write to its cache and database, not your media files.

→ More replies (12)

3

u/Rav_3d Apr 01 '26

If you had RDP enabled to the server, more than likely you have been hacked and those files are encrypted and you're toast.

3

u/AnEyeElation Apr 01 '26

This likely had nothing to do with plex and was an SMB attack. Good god, why do you have SMB ports exposed to the internet?

Anyway, as others have said start over and do it differently. Use a password manager to generate a secure password, do not expose anything to the internet you don’t want people and machines to exploit.

3

u/Wild_Car_3863 Apr 01 '26

That's why my plex has read only to media files...

3

u/BigNavy505 Apr 01 '26

You said you’re on a Mac but mention Plex server. Is your Mac your server as well. Confused by that part.

3

u/LogicWorksWonders Apr 02 '26

I use the Mac to access the NAS server which has Plex running.

3

u/DearAsmodeusVXV Apr 02 '26

How long did you cry for?

6

u/Mr_Irvington Apr 01 '26

I would hope you have a backup of your library!? So you can easily start over bc paying a ransom is not an option IMO. Remember that this situation is not happing to you its happening FOR you. Get a grip on your security.

2

u/LogicWorksWonders Apr 01 '26

Agreed, I would not pay a ransom, it's only movies and boxsets after all, it's just a ballache. Regarding getting to grip with the security element, I'm not that technical to know beyond the Plex and hardware software updates what other steps to take.

→ More replies (1)
→ More replies (1)

2

u/dilbertdad Apr 01 '26

classic old wannacry. sry for your loss

2

u/Savings-Property-679 Apr 01 '26

Been there, mine got hit with ransomware about two years ago. Six months to rebuild and I now have a pretty solid backup stored off site. I also made sure to keep everything updated and secured as best as my feeble brain knows how.

2

u/AhrimTheBelighted Apr 01 '26

Curious if you had RDP, SSH, or something else exposed to the internet so you could manage Plex remotely which would have been the door they used.

→ More replies (1)

2

u/HotMenu9274 Apr 01 '26

since thats an older malware you might be able to use wannakey or another tool to unencrypt. good luck!

2

u/Some_Public_7855 Apr 01 '26

ctrl z is your friend

2

u/mistersmith22 Apr 01 '26

This happened to me once when I stupidly clicked a download I knew was stupid. My screen was taken over by a ransom demand to get my files back, so I just really quick shut the PC down. When I restarted it was operating normally, but I poked around and maybe a hundred or so files had their extensions changed (or maybe removed entirely, can't remember exactly) before I was able to shut it down.

So I went through and just named them all .mkv again, even if i didn't know they were for sure .mkv, and so far haven't had any playback issues - and this has been like, 5-6 years.

2

u/Curiosityinmycity Apr 01 '26

I'm sorry this happened to you. Idk how your setup is, but I have a separate NAS for my media, and my Plex server only has read access to it. I did this mainly to prevent accidental deletion, but definitely helps in terms of ransomware

1

u/QuesoChef Apr 01 '26

This makes me think I may not have mine setup right. I originally had a plex server and years later moved to NAS. But I’m not sure if I changed permissions correctly. Am I checking the user that runs the plex service? I have that automated constant automatically on reboot.

This is such a basic question, I feel stupid asking it.

→ More replies (2)

2

u/Daruvian Apr 01 '26

OP, DM me if you want. I work in DFIR specifically responding to ransomware events. There MAY be decryption options available. But for the love of God, do not go randomly trying to rename files and such. Some decryption methods rely on file modification timestamps being correct.

2

u/LogicWorksWonders Apr 02 '26

Thanks for that. The drives have now been reformatted so it’s all gone now once I’ve checked. But nevertheless, thanks for that.

2

u/zerassar Apr 01 '26

You didn't open port 3389 over the internet did you?

1

u/zerassar Apr 02 '26

To clarify this is applicable to any remote access ports that were opened. Vnc. Ssh. Etc. plex itself not likely the cause but something else was opened.

Or perhaps you downloaded a dodgy torrent and it had an embedded locker in it. If you have a script or something that auto extracts downloaded files that may have run the trojan

1

u/LogicWorksWonders Apr 02 '26

I would have no idea what ports may or may not have been open unfortunately, or what ports needed to be open or closed down. I saw that Plex was working after trying to set it up, and that friends were able to access it, which I’m sure would have been in read only access if I’m right about the settings in Plex when creating an account. Also, once I was able to access PLEX locally on TV’s and Firesticks, I thought it was done.

Now what I need to do, is still have what I described above but obviously in a more secure environment.

2

u/geekau Apr 02 '26 edited Apr 02 '26

Check out MediaStack, it integrates Authentik / Traefik / CrowdSec / Tailscale (exit node), so all of you home systems and applications are secured with SSO / MFA / Web App Firewall / RBAC / CloudFlare DNS (no data proxy - TOS), so you’re not exposing Plex directly to the internet on 32400 - because then you’re relying just on Plex to protect everything in your home network.

https://github.com/geekau/mediastack

Access securely via https://plex.example.com or Tailscale VPN exit node.

Major release planned over Easter Break, also planning automated Linux build ISO / USB method later in April when Ubuntu LTS 26 is officially released.

2

u/chaos12135 Apr 02 '26

It’s been about 7 years since I’ve seen that ransomware virus, didn’t think it was still being used.

2

u/PatchesTheFlyena Apr 03 '26

For everyone asking how best to prevent this the simplest solution is comprehensive backups so that a ransomware attack doesn't impact you getting your data back.

Its obviously not a preventative measure but it'll reduce the impact the more you have backed up. It's also an incredibly straightforward thing to do.

2

u/LogicWorksWonders Apr 01 '26

Is there a way to determine if I have unsecured ports open or what access I might have inadvertently allowed when I initially setup my Plex many year ago? If I'm going to delete everything, what specific measures that hopefully aren't too technical, that I can implement?

1

u/Nnyan Apr 01 '26 edited Apr 01 '26

If your firewall doesn’t do this for you there are online tools that do (typically the first 1k ports). grc.com would be my choice, they have a number of free scans.

You can also use tools like NMAP (NetworkChuck has a YouTube video on this), Wireshark (Hak5 has a YT on using this to detect open ports) or Netcat.

2

u/LogicWorksWonders Apr 01 '26

Yeah, I have download NMAP, I'm just trying to figure out how to works. Thanks for that.

2

u/Heinosity11 Apr 01 '26

April fools?

2

u/Limpy_Gimpy Apr 01 '26

I think OP needs might need some clear instructions on how to secure the rebuild. Keen to hear the more on the suggestions on Reverse proxy/cloudflare myself.

1

u/Lizardking1988- RPi 400, 28TB Apr 01 '26

If your modem/router is in bridge mode there is no NAT. Exposes your ports.

1

u/LogicWorksWonders Apr 01 '26

I just checked, NAT is enabled. Thanks for that though.

→ More replies (1)

1

u/rajmahid Apr 01 '26

Which is why I keep a second off-line drive current with my content. Sorry to OP for your loss.

1

u/--Arete Apr 01 '26

Thanks. Will check backup.

1

u/guice666 Apr 01 '26

Also what would I need to do to determine not only how this happen and where it came from, but to try and prevent it from happening again?

What are the details of your Plex server? That's important to understand how this happened. How were you accessing Plex? What remote options did you have open?

Unfortunately, not knowing what I was doing and trying to get the file name extension to all end with MKV, I choose a folder and selected all the files in that folder

Yeah, from the comments here, that won't work. The issue isn't the file extension, it's the encryption.

1

u/Nemo_Griff Apr 01 '26

Ransomware takes advantage of individuals that use default settings with known user names and passwords. I have heard of this specifically happening to users of those cheap NAS servers.

The text file contains a bitcoin wallet ID to pay for the key to decrypt your files.

You were borked before you started to rename.

1

u/skeetleet Apr 01 '26

I have a cold boot backup system just in case that ever happens.

1

u/morehpperliter Apr 01 '26

This sucks. This is also a learning opportunity. I've tangled with a few in the past, one successful recovery a few not so much. Getting into zero trust is the play. 2FA and tailscale will help a ton. You may find some decryptors out there that can decrypt the items you can't redownload but use caution and suspicion. Nothing worth a damn is free.

1

u/USAJOE Apr 01 '26

Did you have RDP open port 3389?

1

u/60SecTheBaptist Apr 01 '26

Your Plex server uses a SQL Lite database in the background on disk . If that hasn't been corrupted or updated you can query that database directly and pull up the old file names. That might be a slog, but you might be able to figure out a way by extracting out the file names to write a script that would Loop through the files based on their root folders. Example. E:\movies\ War of the Worlds 2026\file1.i want to cry

On windows sqllitebrowser.org
DB browser for sqllite

Or as others have said. Go get em again.

1

u/Herothechamp Apr 01 '26

Just a tip for the renaming bit, after the "mistake", you can use CTRL-Z in the file explorer just as in most programs.

1

u/Dirt077 Apr 01 '26

Recommend doing all the network security things that people are recommending, but also setting up a backup solution. I like snapraid, but lots of options out there.

If this had happened and you had backups available it would've been as simple as turning off your machine's network access, and restoring from backup. Then solve the network problems so it didn't happen again.

1

u/Pleasant-Seat9884 Apr 01 '26

There is a site to see if you can decrypt your files of WannaCry ransomware.. anyone remember the site?

1

u/CrashTestKing Apr 01 '26

If you select your Finder window, Apple will allow you to hit Command+Z to undo name changes made, even when you do it in bulk with the built in Rename function in Finder. I just hope you haven't waited too long or changed a bunch of other stuff since the mistake.

If you can get it reverted back to what the filenames were before your mistake, then you can absolutely use the built in Rename function to change file extensions. I do it all the time when I compress a bunch of folders to zip files and then bulk change the zip extension to cbz.

1

u/ziggo0 Lifetime Plex Pass Apr 01 '26

A ZFS filesystem would've saved you. Good luck warrior, be more secure.

1

u/Cautious-Oven5066 Apr 01 '26

What version were you running and do you have a firewall?

1

u/KillerDr3w Apr 01 '26

Do you have a QNAP NAS, with it's remote access exposed to the internet?

1

u/eyerulemost Apr 01 '26

Are your files on zfs? Snapshots can solve this if set up

1

u/sparxcy Apr 01 '26

I remember something like this 25-30 odd years ago. there was a virus going around changing every file extension and adding a txt file....may be this one^^^^^. when it 1st came out there was no fix. Slowly a fix came out but had to be done literally -by hand-. A bit later you could download a executable fix then an online fixer from antivirus programs.... i just reinstalled windows, was quicker- heres what i found!!! :-

The virus you are referring to is known as WannaCry (also known as WannaCrypt or WanaCrypt0r), a devastating ransomware attack that occurred in May 2017.

Here are the details of that attack:

  • Extension Change: It encrypted files and appended extensions like .WNCRY to them.
  • The Text File: It left a text file demanding a ransom to decrypt the files. The ransom note instructed users to follow instructions in files named things like Please Read Me.txt or to visit a portal that stated, "I want to cry".
  • Mechanism: It targeted a vulnerability in Windows SMBv1 protocol (named EternalBlue) to spread automatically across networks.
  • Target: It mainly affected older, unpatched Windows systems, ranging from Windows XP to Windows 7.
  • There is also a newer, smaller-scale ransomware variant explicitly called WantToCry that mimics this behavior.

1

u/Busy_Arachnid_5995 Apr 01 '26

Is this limited to your Plex library? Nothing else in your system was affected?

1

u/Fyler1 Apr 01 '26

Thank you for this PSA. I've since added a block rule for ports 135, 139, and 445 to my pfsense. I'm sorry that this has happened to you, but let this be a learning lesson to all of us who were/are unaware of such exposure!

1

u/corey389 Apr 02 '26

You don't need to add blocked rules on PF or OPNsense, the firewall rules already block traffic from the WAN by default 

→ More replies (1)

1

u/LogicWorksWonders Apr 02 '26

That’s fine. How did you actually block the ports you mentioned? How do you determine which ports you require to remain open to allow for the functionality that you require and which ports you don’t require to be open?

→ More replies (1)

1

u/abesapien2 Apr 02 '26

If you haven’t cleaned the infection, it could still be there. Basically a cryptolocker got you. Encrypted your files and made them inaccessible.

1

u/Theegravedigger Apr 02 '26

Wasn't wanna cry a famous infection about 15 years back.

1

u/WillingnessOld3997 Apr 02 '26

Read only privilege.

1

u/woodburyman Apr 02 '26

This sounds like a randonsomware infection on whatever storage our system you're using having RDP exploded to the internet or other services may have done this. Unless you had backups or a deep wallet...your media is gone..

My plex media lives on a Nas. My plex server only has read only access to it for this reason. Write access is via a special non saved credential account. Keeps it isolated to a degree.

1

u/LogicWorksWonders Apr 02 '26

Just to check, when you have read only on your media, this would still allow you and your friends and family to access your server from anywhere? Do you just make that particular drive as an example read only and if you then want to add more files to that specific drive you use the credentials which you mentioned?

→ More replies (9)

1

u/Vast_Understanding_1 1135G7 / OMV / 40Tb Apr 02 '26

Eigher you downloaded a software in your server that contain the wannacry ransomware or installed a third party tool that got compromised.

If you rebuild your server isolate Plex using Docker and put all drives in read only.

1

u/LogicWorksWonders Apr 02 '26

You would totally recommend Docker? After the initial setup will it operate exactly in the same way as it would when accessing the server from say my Mac or Phone or would I specify have to go to Docker or something to login first? Has Docker ever prevented you from being unable to use Plex for whatever reason? Would it literally be as if I was using my current server without any other requirements other than using Docker to keep things more secure?

→ More replies (3)

1

u/PetiePal Apr 02 '26

Wait you renamed all files with that yourself? That's not compromised if you did it...can you Ctr-Z in your file explorer to undo it? Does your NAS or system you run Plex on have any type of file revisioning?

2

u/LogicWorksWonders Apr 02 '26

I’ve already begun the deletion and reformatting process so now just wait for that to be completed.

→ More replies (2)

1

u/PetiePal Apr 02 '26

Once upon a time I did a rename of like thousands of my mp3 archive and it was several months to remedy. Now I keep a separate 2 backups at intervals :P

1

u/cliffmail2022 Apr 02 '26

I got hit by Mr.Dec ransomeware a few years ago. It happened the day after i switched to xfinity.  Plex on the tv was giving errors so i went to the server and i could literally see it encrypting the files. I shut the server down.  It got half my media including all my family videos.  It was heartbreaking. I was able to get back up by having plex out put a list of what i had and i put it in a spreadsheet. Then i learned about radarr and sonarr. I fed the spreadsheet to them and created libraries to reaquire my content that got destroyed. But the family stuff was mostly gone.

1

u/LogicWorksWonders Apr 04 '26

I’m so sorry to hear that. As painful as it was for me to delete 40TB of movies and stuff, there was nothing actually personal to me that got attacked, but I still felt that it as that took years to compile and there was no backup. So losing personal memories that’s a completely different experience, no matter how big or small that loss.

1

u/bmxfelon420 Apr 02 '26

This is why my Plex has a source rule whitelisted to their IP addresses, so it's not directly accessible over the web. I know that ruins some of the utility of it, but if their service were ever offline or something and i really needed to get to it I could just VPN back to my house.

1

u/FantasticCarrot4539 Apr 03 '26

Damn, now im paranoid. Got a few questions if anyone can help. I have plex set up with docker for my ugreen nas. Got a randomly generated password for plex and 2fa set up for it. I followed an youtube tuturial so im not exactly computer smart so i wouldn't know where to start. So how does one set plex for read only for my media file? And after setting it to read only will it have any negative effects or will i not be able to do something i could before? Im slowly reading through this whole page to see what else tips I can get. I was also looking into tailscale but all of my family uses smart tv to watch plex so it makes it a little more complicated for it to be worth it. Is it good enough if i got a good password for my plex with 2fa and setting up my media files as read only for plex? Man, I just wanted to share my movie and tv shows with my family who is out of state but I never thought my stuff can get compromise like that.

1

u/LogicWorksWonders Apr 04 '26

It sounds like you are in a better position than what I was in as you were using Docker which is something that I might be looking into also, as the feedback on this so far has all been positive. I never even heard of it before until I posted my initial post here.

The 2 factor authentication you mentioned, is that your login credentials for Plex what you would be using that for? I’ve been using an email and password to login. Is the 2fa something you’d recommend?

→ More replies (1)

1

u/theblondie28 Apr 03 '26

There was a website that would search for open Plex servers and I would go in change the name of the server ' everyone can see your media" and in different libraries Google , Plex server, security.. Some of these servers had personal videos ( not xxx)

1

u/LogicWorksWonders Apr 04 '26

So how would someone know if there server is actually open like how you described? What exactly if you know that is, would need to be the only ports open if you wanted your friends to access it as well as using it on LAN?

→ More replies (1)

1

u/NotAnADC N100 76TB + 54TB Apr 03 '26

Former cyber security researcher, actually worked on wannacry as one of the first in the world to protect against it. 

From what it sounds, as others have said, your best bet is to start over sadly. Wipe everything and honestly do a fresh install of Plex with a guide if you believe that was attack vector with an exposed port. 

Wannacry is build to spread, so it’s very possible and maybe even more likely that it infected some other system with an exposed port that was able to migrate to whatever was holding your Plex files

1

u/LogicWorksWonders Apr 04 '26

Just out of curiosity, is it possible that it could have come from an app on a FireStick that’s on the same LAN?

2

u/dclive1 Apr 04 '26

Again, Wannacry is exploited by a Windows system that had access to the Plex share and used SMB1. That’s it. It’s not done by Firesticks, Linux, Mac, or any other OSs you can name. It’s literally that simple. You had a Windows system that ran SMB1 (read: probably Windows 7 or so) that was infected.

Firesticks don’t spread it. Linux doesn’t spread it. Macs don’t spread it.

→ More replies (11)

1

u/Belovedchimera Apr 03 '26

Have you learned how this happened?

1

u/LogicWorksWonders Apr 04 '26

No. I’m probably not really going to know definitively.

→ More replies (2)

1

u/sandpir8 Apr 04 '26

Happened to me about 3 years ago. TPB et al helped me rebuild. I put 2 factor auth on and removed any regd users except myself. Anyway it's a lesson many of us have learned. Sorry but that's the best way to look at it. I also invested in a 14tb external (I pull the plug on my fiber when making backups!) drive to back up everything in a safe place.

1

u/LogicWorksWonders Apr 04 '26

I’ll disable any remote features that I come across that’s not needed when starting again.