Skip to content

Deadbolt

DeadBolt is ransomware targeting internet-exposed network-attached storage (NAS) systems, particularly QNAP and ASUSTOR devices.

Deadbolt

Family profile

DeadBolt is ransomware targeting internet-exposed network-attached storage (NAS) systems, particularly QNAP and ASUSTOR devices. Its campaigns began in January 2022 and affected victims worldwide. Operators compromise vulnerable NAS systems through software vulnerabilities and encrypt stored user data. The malware combines Go, HTML, and Bash components, uses AES-128 encryption, and replaces the NAS web login page with an interactive ransom screen rather than distributing conventional ransom-note files.

DeadBolt uses a heavily automated, high-volume extortion model directed at both device owners and NAS vendors. Individual victims are asked to pay Bitcoin for a decryption key, while vendors receive separate demands for vulnerability information or a purported universal decryption key. Victim-specific keys can be delivered through the OP_RETURN field of a Bitcoin transaction, enabling payment and key delivery without direct negotiation. The ransom interface validates submitted keys against stored cryptographic hashes and initiates decryption when a valid key is supplied. The operation is associated with actors identifying themselves as the DeadBolt Team and targets NAS deployments rather than a specific industry or geographic region.

Capabilities

  • Extortion

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

Deadbolt in ATT&CK

9 distinct techniques

Reporting

Research mentioning Deadbolt

Feb 26
Ncsc Nl News

Jaarbeeld Ransomware 2025 | NCSC

Ransomware continued to cause substantial harm to Dutch organizations in 2025, with attackers encrypting systems and increasingly stealing data for double extortion; some campaigns now steal data without deploying encryption. Dutch authorities warn that backups and cyber insurance do not eliminate the operational, financial, and privacy impact, and urge victims to report every incident—including those involving ransom payments—to police. Information sharing under the public-private Project Melissa partnership provided monthly visibility into ransomware incidents affecting the Netherlands and supports investigations, potential decryption opportunities, and suspect identification. The threat remains driven primarily by preventable access failures rather than novel techniques: exploitation of unpatched vulnerabilities and compromised accounts are the leading intrusion paths. Earlier Dutch assessments recorded 178 successful ransomware attacks in 2023 affecting hundreds of organizations and millions of individuals; two-thirds of 90 examined victims lacked sufficient fundamentals such as MFA, strong password controls, timely patching, and network segmentation. Organizations should prioritize these controls, maintain tested and segregated backups, prepare and exercise incident-recovery procedures, and avoid paying ransoms, as payment neither guarantees recovery nor prevents further extortion.

Feb 17
Ncsc Nl News

Ransomware-aanvallen kunnen vaak voorkomen worden door invoering basis-beveiligingsmaatregelen | NCSC

Oct 22
Ncsc Nl News

Organisaties onvoldoende weerbaar tegen ransomware | NCSC

Oct 3
Ncsc Nl News

Melissa: samenwerkingsverband ransomwarebestrijding | NCSC

Feb 23
Ncsc Nl News

Meerderheid ransomware-slachtoffers had geen back-up | NCSC

Oct 3
Politie

Melissa: samenwerkingsverband ransomwarebestrijding | politie.nl

Jun 6
Trend Micro Research

Closing the Door DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme | Trend Micro (US)

DeadBolt ransomware targeted network-attached storage (NAS) devices with a highly automated campaign that locked victims out of their systems and paired encryption with a multi-tiered extortion model aimed at both end users and device vendors. The operation reportedly depended on scale rather than traditional big-game hunting, with attackers using volume and automation to compromise large numbers of internet-exposed NAS devices and demand payment for decryption. Despite reports that roughly 92% of victims did not pay, the operators still earned about US$300,000 while inflicting an estimated US$2.69 million in economic damage. Researchers said the campaign showed how ransomware actors can remain profitable even with low payment rates by combining broad targeting, operational efficiency, and pressure on multiple parties in the ecosystem, a model that could influence future ransomware activity against appliance-like devices.

Jan 25
Bleeping Computer

New DeadBolt ransomware targets QNAP devices, asks 50 BTC for master key