Qlocker is a ransomware family that targeted QNAP network-attached storage devices at scale beginning in April 2021. It primarily affected internet-exposed QNAP NAS systems used by small businesses and home or SOHO environments. Rather than implementing a conventional custom file-encryption routine, Qlocker abused the built-in 7-Zip utility on compromised devices to move victim data into password-protected archives, leaving victims unable to access their files without an attacker-controlled password. Infected systems typically displayed a ransom note directing victims to a Tor-based payment portal, where operators demanded a relatively low ransom, commonly 0.01 bitcoin, to retrieve the archive password.
Qlocker has been associated with exploitation of vulnerabilities in QNAP software, including flaws in Hybrid Backup Sync and Multimedia Console or Media Streaming components. Reporting also tied some incidents to abuse of a hardcoded backdoor account removed from Hybrid Backup Sync. The malware was described as Python-based and optimized for rapid, large-scale compromise of vulnerable NAS appliances. Some activity also involved deletion of snapshots, which hindered recovery efforts. Qlocker campaigns were notable for high victim volume, low per-victim ransom demands, and operational use of Tor payment infrastructure. Operators later shut down their payment sites after collecting substantial proceeds, leaving some victims without a recovery path. Qlocker is one of several ransomware families known for directly targeting NAS platforms, especially QNAP devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
they likely exploited the same security flaw (the CVE-2021-28799 remote code execution bug) to gain access to the server | a QNAP network-attached storage (NAS) device typically used by small businesses and previously infected with QLocker ransomware
10 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
QNAP NASの脆弱性悪用事例として過去の比較対象として言及されたランサムウェア。
Ransomware operation reported targeting QNAP NAS devices.
Ransomware targeting QNAP NAS devices; it places victims’ files into password-protected 7zip archives and demands a ransom payment for recovery.
Ransomware previously infecting the compromised QNAP NAS server that also hosted SockDetour; mentioned as part of the access context rather than the main subject.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.