eCh0raix, also known as QNAPCrypt, is a ransomware operation focused on network-attached storage devices. It initially concentrated on QNAP NAS systems and later expanded to target Synology devices. The actor has been associated with campaigns against internet-exposed and unpatched NAS appliances, reflecting an opportunistic targeting model centered on storage platforms that often contain backups and other high-value data. The malware is designed to encrypt files on NAS devices while excluding selected files, directories, and extensions in order to preserve core device functionality and web interfaces. eCh0raix has been reported to use Tor-hidden infrastructure together with SOCKS5 proxy communications to obtain encryption keys and victim cryptocurrency wallet information from command-and-control systems, and encryption may be aborted if that communication path is unavailable. Activity attributed to eCh0raix has included scanning for vulnerable QNAP devices and exploiting unpatched exposure in NAS application ecosystems. The operation is best characterized as financially motivated ransomware. Public reporting directly supports encryption-based extortion against NAS owners, but does not firmly establish broader extortion practices such as leak-site operations or multi-stage coercion. Known naming overlaps are limited, with QNAPCrypt being the principal alternate name in common use.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older ransomware operation focused on compromising QNAP NAS devices; activity reportedly spiked and may be leveraging the same newly patched bugs as Qlocker.
Mentioned only as another ransomware family previously targeting QNAP owners.
Ransomware group targeting NAS devices, initially QNAP and later Synology, using Tor-hidden C2 infrastructure to obtain encryption keys and payment wallet details.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.