DeadBolt is a ransomware operation that emerged in January 2022 and primarily targets internet-exposed QNAP network-attached storage (NAS) devices worldwide. It encrypts user data, replaces the device’s normal web-login interface with a ransom screen, and demands cryptocurrency payment for decryption. DeadBolt used an automated, high-volume model rather than conventional targeted enterprise intrusion, exploiting vulnerable QNAP NAS devices exposed to the public internet. Its multi-tiered extortion scheme also attempted to pressure the vendor by offering alleged vulnerability details and a purported universal decryption capability for separate cryptocurrency payments. The malware uses AES encryption and supports a payment workflow in which a victim decryption key can be delivered through Bitcoin transaction metadata, reducing the need for direct operator-victim communications. DeadBolt has been associated with repeated exploitation of vulnerabilities in QNAP NAS software and remains an example of ransomware focused on NAS appliances, which are attractive targets because they often contain centralized business and backup data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware cited only as historical context for prior campaigns targeting Synology NAS devices; the content does not link it to exploitation of these CVEs.
A separate NAS-focused ransomware operation mentioned only because its ransom note was found on infrastructure later accessed by The Gentlemen.
Ransomware mentioned only as pre-existing ransom-note evidence on NAS devices accessed by the group.
Ransomware referenced as having previously impacted ASUSTOR NAS devices (used to encrypt/deny access to data and demand payment).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.