Skip to content

Qlocker

Qlocker is a ransomware family that targeted QNAP network-attached storage devices at scale beginning in April 2021.

Profile source: Mallory opens in a new tab

Qlocker

Family profile

Qlocker is a ransomware family that targeted QNAP network-attached storage devices at scale beginning in April 2021. It primarily affected internet-exposed QNAP NAS systems used by small businesses and home or SOHO environments. Rather than implementing a conventional custom file-encryption routine, Qlocker abused the built-in 7-Zip utility on compromised devices to move victim data into password-protected archives, leaving victims unable to access their files without an attacker-controlled password. Infected systems typically displayed a ransom note directing victims to a Tor-based payment portal, where operators demanded a relatively low ransom, commonly 0.01 bitcoin, to retrieve the archive password.

Qlocker has been associated with exploitation of vulnerabilities in QNAP software, including flaws in Hybrid Backup Sync and Multimedia Console or Media Streaming components. Reporting also tied some incidents to abuse of a hardcoded backdoor account removed from Hybrid Backup Sync. The malware was described as Python-based and optimized for rapid, large-scale compromise of vulnerable NAS appliances. Some activity also involved deletion of snapshots, which hindered recovery efforts. Qlocker campaigns were notable for high victim volume, low per-victim ransom demands, and operational use of Tor payment infrastructure. Operators later shut down their payment sites after collecting substantial proceeds, leaving some victims without a recovery path. Qlocker is one of several ransomware families known for directly targeting NAS platforms, especially QNAP devices.

Capabilities

  • Defense Evasion
  • Extortion
  • Initial Access

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Exploited software

Vulnerabilities linked to Qlocker

1 CVEs

MITRE ATT&CK

Qlocker in ATT&CK

10 distinct techniques

Reporting

Research mentioning Qlocker

Jun 6
Trend Micro Research

Closing the Door DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme | Trend Micro (US)

DeadBolt ransomware targeted network-attached storage (NAS) devices with a highly automated campaign that locked victims out of their systems and paired encryption with a multi-tiered extortion model aimed at both end users and device vendors. The operation reportedly depended on scale rather than traditional big-game hunting, with attackers using volume and automation to compromise large numbers of internet-exposed NAS devices and demand payment for decryption. Despite reports that roughly 92% of victims did not pay, the operators still earned about US$300,000 while inflicting an estimated US$2.69 million in economic damage. Researchers said the campaign showed how ransomware actors can remain profitable even with low payment rates by combining broad targeting, operational efficiency, and pressure on multiple parties in the ecosystem, a model that could influence future ransomware activity against appliance-like devices.

Jan 25
Bleeping Computer

New DeadBolt ransomware targets QNAP devices, asks 50 BTC for master key

May 14
Bleeping Computer

QNAP warns of eCh0raix ransomware attacks, Roon Server zero-day

QNAP warned that eCh0raix ransomware is actively targeting its NAS devices, with intrusions linked to weak passwords and the active exploitation of a zero-day in Roon Labs' Roon Server versions 2021-02-01 and earlier running on QNAP systems. The company urged customers to disable the vulnerable Roon Server app, avoid exposing NAS devices directly to the Internet, and strengthen authentication, while also disclosing a patched command-injection flaw in its Malware Remover app that could enable remote command execution. Security researchers previously described eCh0raix as a Go-based ransomware family aimed at QNAP NAS appliances, encrypting files with AES, appending the .encrypt extension, and dropping a README_FOR_DECRYPT.txt ransom note. Analysis indicated the operators likely gained access by brute-forcing credentials and exploiting known flaws, and that the malware communicated with a Tor-hidden command-and-control service through a SOCKS5 proxy at 192.99.206[.]61:65000; researchers also noted implementation weaknesses in its key generation that suggested a decryptor might be feasible.

Jul 10
Anomali

Ech0Raix Ransomware Targets QNAP NAS | Anomali

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.