QNAPCrypt, also known as eCh0raix, is a Linux ransomware family that targeted network-attached storage appliances and other Linux-based file storage servers, including QNAP and Synology devices. It emerged in 2019 and has been linked to campaigns attributed to the Russian cybercrime group FullofDeep. Technical analysis has also identified substantial code overlap between QNAPCrypt and the earlier Go-based SunCrypt variant, indicating shared source code or common development lineage even though the operations appear to have been run by different actors.
QNAPCrypt was distributed as ELF binaries compiled in Go for multiple CPU architectures, including ARM, x86, and x64, enabling it to affect a broad range of NAS hardware. Victim reporting indicated initial access commonly occurred through SSH brute-force attacks against exposed devices. After execution, early variants contacted attacker-controlled infrastructure through a SOCKS5 proxy and Tor hidden services to retrieve per-victim configuration data, including a cryptocurrency payment address and an RSA public key. The malware then generated symmetric key material locally, encrypted victim files with AES in CFB mode, wrapped the key material with RSA, and stored the encrypted key information in a ransom note. Encrypted files were renamed, and the ransom demand was delivered as a text note rather than an interactive screen locker.
Operational analysis revealed that early campaigns depended on a pre-generated pool of payment wallets and remote configuration retrieval. If the malware could not obtain the required wallet and RSA key material, it exited without encrypting files. Later variants changed this design by embedding the wallet, RSA key, and ransom note directly in the binary, likely to make the campaign more resilient and to bypass disruption of the earlier infrastructure. Researchers also observed similarities between newer QNAPCrypt variants and Linux.Rex through notable code reuse.
QNAPCrypt is part of the broader trend of Linux ransomware aimed at centralized storage and server infrastructure, where successful encryption can have disproportionate operational impact. Its focus on NAS platforms, multi-architecture support, low detection rates, and use of Linux-specific intrusion paths made it a notable example of ransomware adapted for non-Windows enterprise and small-business environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
QNAPCrypt- Ransomware campaign targeting Linux file storage servers. This campaign was later attributed by our researchers to FullofDeep, a Russian cybercrime group.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family included among malware classes with limited training samples in the evaluation.
QNAPCrypt, also known as eCh0raix, is a ransomware family used against NAS devices, especially QNAP and Synology systems. It shares highly similar encryption, key-generation, victim-exclusion, extension-list, and Tor/C2-related code and logic with SunCrypt, indicating common source-code lineage.
Linux-targeting ransomware aimed primarily at NAS/file storage systems. It encrypts files, drops a README_FOR_DECRYPT.txt ransom note, retrieves or embeds an RSA public key and Bitcoin wallet information, uses AES CFB for file encryption, communicates with C2 infrastructure over SOCKS5/Tor, and renames encrypted files with a '.encrypt' prefix.
Ransomware targeting Linux file storage servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.