DeadBolt is a ransomware operation known for targeting internet-exposed QNAP network-attached storage devices at scale. The group became prominent in 2022 through automated campaigns that encrypted files on affected NAS systems, appended a distinctive extension, and replaced the normal device login page with a ransom screen rather than relying on conventional ransom-note files. DeadBolt has been associated with exploitation of vulnerabilities in QNAP software and hardware-facing services, with the operators claiming zero-day use in some campaigns. The operation is notable for a high-volume, low-touch model focused on mass compromise of exposed appliances rather than traditional big-game hunting. DeadBolt demanded relatively small per-victim payments while simultaneously attempting to extort the vendor by offering vulnerability details for one price and a universal decryption capability for a much larger amount. This multi-tiered scheme sought revenue from both end users and the manufacturer. Reporting and blockchain-based analysis have linked the operation to thousands of victims and millions of dollars in ransom revenue during 2022. Technically, DeadBolt has been observed executing on compromised QNAP devices, encrypting user data stored on shared volumes, and modifying the web interface presented to administrators. The malware has been described as using AES-128 for file encryption and as integrating payment-linked key delivery through Bitcoin transaction metadata. Multiple victims reportedly recovered data after payment, and third-party decryptors were later produced that still required a valid decryption key. DeadBolt's campaigns have been globally distributed, with no single victim geography exclusively targeted, and have disproportionately affected organizations and individuals exposing NAS devices directly to the internet. The actor's behavior is consistent with financially motivated cybercrime centered on encryption-based extortion, opportunistic initial access through vulnerable edge devices, and automated post-compromise execution designed to maximize victim volume.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
QNAP製NASを標的にしたランサムウェア活動を実施し、公開されたNASを暗号化して身代金を要求している。攻撃者はゼロデイ脆弱性の悪用を主張し、被害者には0.03 BTC、QNAPには全被害NAS向けマスターキー代として50 BTCを要求している。
Referenced as a ransomware actor previously observed exploiting QNAP NAS devices.
Ransomware operation known for targeting QNAP NAS devices for data extortion.
Ransomware operations targeting QNAP NAS devices, exploiting vulnerabilities to gain access and extort victims; reported to have generated significant revenue from thousands of victims in 2022.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.