QNAP warned that eCh0raix ransomware is actively targeting its NAS devices, with intrusions linked to weak passwords and the active exploitation of a zero-day in Roon Labs' Roon Server versions 2021-02-01 and earlier running on QNAP systems. The company urged customers to disable the vulnerable Roon Server app, avoid exposing NAS devices directly to the Internet, and strengthen authentication, while also disclosing a patched command-injection flaw in its Malware Remover app that could enable remote command execution.
Security researchers previously described eCh0raix as a Go-based ransomware family aimed at QNAP NAS appliances, encrypting files with AES, appending the .encrypt extension, and dropping a README_FOR_DECRYPT.txt ransom note. Analysis indicated the operators likely gained access by brute-forcing credentials and exploiting known flaws, and that the malware communicated with a Tor-hidden command-and-control service through a SOCKS5 proxy at 192.99.206[.]61:65000; researchers also noted implementation weaknesses in its key generation that suggested a decryptor might be feasible.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
A separate campaign in September 2020 targeted publicly exposed QNAP NAS devices by exploiting vulnerable Photo Station versions.
QNAP said its NAS devices were again targeted by eCh0raix ransomware in June 2020, showing the campaign's recurrence against the platform.
QNAP NAS devices were targeted by the eCh0raix ransomware campaign in June 2019. Anomali also reported observing the new ransomware family targeting QNAP devices, likely via weak credentials and known vulnerabilities.
QNAP said it fixed a command injection vulnerability in its Malware Remover app that could allow remote attackers to execute arbitrary commands on vulnerable devices.
QNAP published a security advisory warning that eCh0raix ransomware was affecting its NAS devices and that an actively exploited zero-day in Roon Server 2021-02-01 and earlier was being used on QNAP NAS systems. The company urged stronger passwords, brute-force protections, and disabling Roon Server until a patch became available.
QNAP customers were hit by AgeLocker ransomware two weeks before QNAP's later warning about eCh0raix and the Roon Server zero-day.
QNAP removed a backdoor account with hardcoded credentials from its HBS 3 Hybrid Backup Sync app. It was later confirmed that Qlocker operators used this account to compromise some NAS devices and encrypt files.
A large Qlocker ransomware campaign began targeting QNAP devices in mid-April. QNAP later confirmed some compromises used a hardcoded backdoor account in the HBS 3 Hybrid Backup Sync app.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.