DeadBolt ransomware targeted network-attached storage (NAS) devices with a highly automated campaign that locked victims out of their systems and paired encryption with a multi-tiered extortion model aimed at both end users and device vendors. The operation reportedly depended on scale rather than traditional big-game hunting, with attackers using volume and automation to compromise large numbers of internet-exposed NAS devices and demand payment for decryption.
Despite reports that roughly 92% of victims did not pay, the operators still earned about US$300,000 while inflicting an estimated US$2.69 million in economic damage. Researchers said the campaign showed how ransomware actors can remain profitable even with low payment rates by combining broad targeting, operational efficiency, and pressure on multiple parties in the ecosystem, a model that could influence future ransomware activity against appliance-like devices.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro Research authored YARA rules named deadbolt_cgi_ransomnote and deadbolt_uncompressed for detecting DeadBolt artifacts. The rules are identified in the content as having been authored in March 2022.
DeadBolt ransomware began targeting QNAP NAS devices exposed to the internet, encrypting files, appending the .deadbolt extension, and replacing the normal login page with a ransom screen demanding 0.03 BTC. The attackers also claimed to possess a zero-day vulnerability and offered QNAP vulnerability details or a universal master key for sale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.