Skip to content

Qlocker

Qlocker is a ransomware operation that targeted QNAP network-attached storage devices at scale beginning in April 2021.

Profile source: Mallory opens in a new tab

Qlocker

Family profile

Qlocker is a ransomware operation that targeted QNAP network-attached storage devices at scale beginning in April 2021. It is notable for abusing built-in system functionality rather than relying on a conventional custom file-encryption routine: victim data is moved into password-protected 7-Zip archives, leaving files inaccessible without a unique per-victim password controlled by the operators. A ransom note is then presented to direct victims to a Tor-based payment workflow for recovery.

The campaign focused on internet-exposed QNAP NAS systems and has been associated with exploitation of vulnerabilities in QNAP applications and services, including flaws affecting Multimedia Console, the Media Streaming Add-on, Hybrid Backup Sync, and related components. Public reporting linked the activity to exploitation of CVE-2020-36195 and potentially CVE-2021-28799, while QNAP issued patches and mitigation guidance during the incident period. The operators were reported to scan for vulnerable QNAP devices and remotely trigger the bundled 7-Zip utility to archive files.

Qlocker primarily impacted QNAP environments rather than general-purpose endpoints, making NAS appliances and the data they store the central target. The operation was part of a broader pattern of ransomware activity against QNAP devices, alongside other families such as eCh0raix and later DeadBolt. The campaign affected organizations and individuals worldwide whose NAS devices were reachable from the internet.

Observed behavior includes remote compromise of vulnerable appliances, execution of archiving commands, creation of password-protected archives, and extortion through a ransom note and payment portal. Guidance issued during the campaign emphasized urgent patching, restricting external exposure, running QNAP’s malware-removal tooling, and avoiding reboot of affected devices while recovery options were assessed. Qlocker is best characterized as a NAS-focused ransomware family that leveraged exposed and vulnerable QNAP services for initial access and extortion.

Capabilities

  • Exfiltration
  • Extortion
  • Initial Access
  • Scanning

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

MITRE ATT&CK

Qlocker in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.