Qlocker
Qlocker is a ransomware family that targeted QNAP network-attached storage devices at scale beginning in April 2021.
Profile source: Mallory opens in a new tabQlocker
Family profile
Qlocker is a ransomware family that targeted QNAP network-attached storage devices at scale beginning in April 2021. It primarily affected internet-exposed QNAP NAS systems used by small businesses and home or SOHO environments. Rather than implementing a conventional custom file-encryption routine, Qlocker abused the built-in 7-Zip utility on compromised devices to move victim data into password-protected archives, leaving victims unable to access their files without an attacker-controlled password. Infected systems typically displayed a ransom note directing victims to a Tor-based payment portal, where operators demanded a relatively low ransom, commonly 0.01 bitcoin, to retrieve the archive password.
Qlocker has been associated with exploitation of vulnerabilities in QNAP software, including flaws in Hybrid Backup Sync and Multimedia Console or Media Streaming components. Reporting also tied some incidents to abuse of a hardcoded backdoor account removed from Hybrid Backup Sync. The malware was described as Python-based and optimized for rapid, large-scale compromise of vulnerable NAS appliances. Some activity also involved deletion of snapshots, which hindered recovery efforts. Qlocker campaigns were notable for high victim volume, low per-victim ransom demands, and operational use of Tor payment infrastructure. Operators later shut down their payment sites after collecting substantial proceeds, leaving some victims without a recovery path. Qlocker is one of several ransomware families known for directly targeting NAS platforms, especially QNAP devices.
Capabilities
- Defense Evasion
- Extortion
- Initial Access
Operational record
Exploited software
Vulnerabilities linked to Qlocker
1 CVEsMITRE ATT&CK
Qlocker in ATT&CK
10 distinct techniquesReporting
Research mentioning Qlocker
Closing the Door DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme | Trend Micro (US)
DeadBolt ransomware targeted network-attached storage (NAS) devices with a highly automated campaign that locked victims out of their systems and paired encryption with a multi-tiered extortion model aimed at both end users and device vendors. The operation reportedly depended on scale rather than traditional big-game hunting, with attackers using volume and automation to compromise large numbers of internet-exposed NAS devices and demand payment for decryption. Despite reports that roughly 92% of victims did not pay, the operators still earned about US$300,000 while inflicting an estimated US$2.69 million in economic damage. Researchers said the campaign showed how ransomware actors can remain profitable even with low payment rates by combining broad targeting, operational efficiency, and pressure on multiple parties in the ecosystem, a model that could influence future ransomware activity against appliance-like devices.
New DeadBolt ransomware targets QNAP devices, asks 50 BTC for master key
QNAP warns of eCh0raix ransomware attacks, Roon Server zero-day
QNAP warned that eCh0raix ransomware is actively targeting its NAS devices, with intrusions linked to weak passwords and the active exploitation of a zero-day in Roon Labs' Roon Server versions 2021-02-01 and earlier running on QNAP systems. The company urged customers to disable the vulnerable Roon Server app, avoid exposing NAS devices directly to the Internet, and strengthen authentication, while also disclosing a patched command-injection flaw in its Malware Remover app that could enable remote command execution. Security researchers previously described eCh0raix as a Go-based ransomware family aimed at QNAP NAS appliances, encrypting files with AES, appending the .encrypt extension, and dropping a README_FOR_DECRYPT.txt ransom note. Analysis indicated the operators likely gained access by brute-forcing credentials and exploiting known flaws, and that the malware communicated with a Tor-hidden command-and-control service through a SOCKS5 proxy at 192.99.206[.]61:65000; researchers also noted implementation weaknesses in its key generation that suggested a decryptor might be feasible.