Qlocker is a ransomware operation focused on compromising QNAP network-attached storage devices, particularly internet-exposed and unpatched NAS systems. The group became active in April 2021 and is known for exploiting vulnerabilities in QNAP applications and software components to gain remote access to victim devices at scale. Rather than using a conventional custom file-encryption routine, Qlocker placed victim data into password-protected 7-Zip archives and then demanded payment in exchange for the archive password. The operation primarily targeted QNAP owners globally, including businesses and other organizations that relied on NAS appliances for centralized storage. Reporting associated Qlocker with rapid, high-volume compromise of hundreds of devices per day during peak activity, indicating effective automation and broad opportunistic targeting rather than narrow victim selection. The campaign was financially motivated and used relatively low ransom demands, which likely increased payment rates among affected victims. Qlocker operated extortion infrastructure through anonymized payment portals and was observed using deceptive payment practices, including demanding additional funds from some victims after an initial payment. Public reporting indicates the operation shut down after roughly a month, having generated substantial ransom revenue from a large number of victims. Qlocker is widely recognized as part of a cluster of ransomware activity that has repeatedly targeted QNAP NAS ecosystems, alongside other families such as eCh0raix, DeadBolt, and Checkmate.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation known for targeting QNAP NAS devices, conducting attack waves against NAS users for extortion.
Ransomware operation targeting QNAP NAS devices, encrypting/locking data by moving files into password-protected 7zip archives and demanding a ransom payment.
Mentioned only as another ransomware family previously targeting QNAP owners.
Conducted ransomware attacks against QNAP NAS device owners worldwide by exploiting recently disclosed QNAP vulnerabilities and remotely encrypting files using the built-in 7-zip application, then demanding Bitcoin ransoms via Tor sites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.