CISA and the UK National Cyber Security Centre warned that QSnatch malware compromised tens of thousands of QNAP network-attached storage devices, with about 62,000 infected systems identified globally in mid-2020, including roughly 7,600 in the United States and 3,900 in the United Kingdom. The malware targeted QNAP NAS appliances to steal administrator credentials, enable SSH backdoor and webshell access, exfiltrate files, and block firmware updates by altering host file entries, leaving affected devices exposed even after administrators attempted remediation.
Technical analysis showed QSnatch used at least two domain generation algorithm (DGA) variants to locate command-and-control infrastructure and retrieve additional malicious code. One variant generated up to 2,610 algorithmic domains across 145 TLDs using multiple time intervals, while a second simpler variant used 30 TLDs and a 15-day interval; both derived domains from the seed string IbjGOEgnuD through a SHA-1 and Base64-based process. Authorities said the more recent campaign began in late 2018 and remained active into late 2019, and advised defenders to run QNAP Malware Remover, perform a full factory reset, update firmware, and limit external exposure of NAS devices.

See affected versions and whether adversaries are exploiting it.
11 events from the most recent confirmed update back to the earliest known activity.
CISA and NCSC reported approximately 62,000 QSnatch-infected devices worldwide in mid-June 2020, including about 7,600 in the United States and 3,900 in the United Kingdom. They said infections were especially concentrated in North America and Europe.
Finland's National Cyber Security Centre published an article about QSnatch in late October 2019, bringing public attention to the malware targeting QNAP NAS devices. The bin.re analysis explicitly cites this publicity milestone.
Samples associated with QSnatch were present on VirusTotal by at least June 2019. This indicates the malware was circulating publicly months before broader government publicity.
A Version A QSnatch sample with SHA256 9526ccdeb9bf7cfd9b34d290bdb49ab6a6acefc17bff0e85d9ebb46cca8b9dc2 had a version timestamp of 2019-05-17 05:00 UTC. The same sample was later described as the one currently delivered in November 2019.
A Version A QSnatch sample with SHA256 3c38e7bb004b000bd90ad94446437096f46140292a138bfc9f7e44dc136bac8d had a version timestamp of 2019-03-20 05:00 UTC. This provides evidence of QSnatch activity and code versioning by that date.
CISA and NCSC reported that the second QSnatch campaign was still active in late 2019. Their alert also noted attackers used QSnatch against QNAP NAS devices during that period.
CISA and NCSC reported that a second QSnatch campaign began in late 2018. This later campaign was still active in late 2019 and became the focus of subsequent public reporting.
The first QSnatch campaign identified by CISA and NCSC continued until mid-2017. The agencies distinguished it from a later campaign that started afterward.
CISA and the UK National Cyber Security Centre identified an initial QSnatch campaign targeting QNAP NAS devices that likely began in early 2014. This earlier campaign continued until mid-2017 and differed from the later campaign in initial payloads and some capabilities.
CISA and the UK National Cyber Security Centre published a joint alert warning of legacy risk from QSnatch malware targeting QNAP NAS devices. The alert described two campaigns, detailed the malware's capabilities, and advised organizations to reset, update, and restrict access to affected devices.
A reverse-engineering analysis identified seven QSnatch samples using two different domain generation algorithms, labeled Version A and Version B. The research documented how the malware generated algorithmic domains for command-and-control communications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.