eCh0raix, also known as QNAPCrypt, is a Linux ransomware family that targets network-attached storage appliances, primarily QNAP devices and later Synology systems. It has been active since at least 2019, with reporting also linking it to earlier activity, and is notable for focusing on internet-exposed NAS environments used by home users, SOHO operators, and small businesses where centralized security administration is often limited.
The malware is a Go-based encryptor that traverses NAS storage, selectively skips files and directories needed to preserve device operability, and encrypts victim data using AES in cipher feedback mode before appending a new extension to affected files. It drops a ransom note and relies on Tor-hidden infrastructure, typically through SOCKS5 proxying, to obtain operational data such as encryption material, ransom text, and payment information. Older variants generated encryption keys locally and encrypted them with an RSA public key, while later variants retrieved AES keys directly from command-and-control infrastructure. Some variants include logic tailored for Synology path structures, reflecting the family’s expansion beyond QNAP-only targeting.
Observed intrusion vectors include brute-forcing weak credentials on exposed NAS devices and exploitation of known vulnerabilities in QNAP software and applications. High-confidence reporting links delivery in some campaigns to exploitation of CVE-2021-28799 in QNAP Hybrid Backup Sync 3, and other campaigns have been associated with vulnerable QTS and Photo Station components. Operators have also been described as scanning for unpatched QNAP devices. QNAP has specifically warned that weak administrator passwords increase exposure to eCh0raix attacks.
The ransomware has been associated with targeted attacks against NAS appliances rather than indiscriminate mass endpoint campaigns. Victimology centers on internet-facing storage devices that often contain backups and business-critical files, making them attractive extortion targets. Successful extortion events have been reported, and the family has remained a recurring threat in the broader wave of ransomware activity against NAS ecosystems alongside operations such as Qlocker, DeadBolt, and AgeLocker.
Technical analysis has identified implementation weaknesses in some samples, including non-cryptographic randomization for key generation in earlier variants and locale checks that avoid encrypting systems associated with Belarus, Ukraine, or Russia. These traits suggest iterative development and operational adaptation over time, but do not change its core role as a NAS-focused ransomware family built to encrypt stored data and coerce payment from device owners.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers are also leveraging CVE-2021-28799 to deliver the new eCh0raix ransomware variant to QNAP devices. QNAP disclosed the flaw in Hybrid Backup Sync (HBS 3) as an improper authorization vulnerability that allows remote attackers to log in to devices. On June 21, researchers caught an attack targeting QNAP HBS3 with an exploit of CVE-2021-28799. | Unit 42 researchers have discovered a new variant of eCh0raix ransomware targeting Synology network-attached storage (NAS) and Quality Network Appliance Provider (QNAP) NAS devices.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack tried to utilize a hard-coded session ID " jisoosocoolhbsmgnt " to bypass authentication and execute a command on the device
If found, the ransomware tries to read an integer value from this file and kill the corresponding process ID on the system.
the ransomware attempts to connect to a Tor URL via a hard-coded SOCKS proxy
The malware establishes a connection using one of the following SOCKS5 proxy to be able to access an .onion domain.
MITRE ATT&CK TTPs: Exploit Public-Facing Application - T1190 Exploitation for Client Execution - T1203 Brute Force - T1110 Connection Proxy - T1090 Multi-hop Proxy - T1188 Standard Application Layer Protocol - T1071 Standard Non-Application Layer Protocol - T1095 ...
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
QNAP NASの脆弱性悪用事例として過去の比較対象として言及されたランサムウェア。
Ransomware targeting Internet-exposed NAS devices (notably QNAP and Synology), encrypting files and extorting owners for payment to regain access.
Ransomware strain reported as targeting QNAP customers (notably NAS environments).
Older ransomware operation focused on infecting QNAP NAS systems; reported to be scanning for and exploiting unpatched QNAP devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.