AgeLocker is a ransomware family observed targeting Linux-based environments, particularly QNAP network-attached storage devices, and in some cases affecting broader mixed environments that include storage systems and Mac hosts. It is notable for using the Age file-encryption utility rather than a bespoke cryptographic implementation, leveraging strong modern cryptography to render victim data inaccessible. Reported variants include ELF builds used against QNAP systems.
AgeLocker has been associated with attacks on internet-exposed QNAP NAS devices, including campaigns linked to exploitation of vulnerabilities in QTS firmware and the Photo Station application. Public reporting also noted incidents where the precise initial access vector was not determined. After gaining access, operators encrypt files and append victim-specific extensions. In at least some intrusions, the actors did not leave an on-host ransom note and instead contacted victims directly by email with ransom demands, offering limited proof-of-decryption and promising decryptors for Linux and Mac systems upon payment.
The malware is part of the broader trend of ransomware operators expanding into Linux and NAS ecosystems, where centralized storage and backup roles can amplify operational impact. AgeLocker has been repeatedly cited in QNAP-focused ransomware activity and is recognized as a notable Linux malware discovery from 2020. Its use against NAS appliances indicates a focus on organizations and users relying on network storage, where encryption of shared data can cause significant business disruption and extortion pressure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware previously reported as affecting QNAP customers in a separate outbreak.
Ransomware targeting QNAP NAS devices, encrypting files after gaining a foothold on exposed or unpatched systems. Its name comes from using the Actually Good Encryption (AGE) algorithm to encrypt files.
Ransomware targeting Linux systems, encrypting files using the Age encryption tool.
ELF ransomware variant targeting QNAP devices; noted for adding the .kmd suffix to encrypted files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.