QNAP warned that its NAS devices are being hit by the AgeLocker ransomware operation and urged customers to immediately update the QTS operating system and installed applications. The company also advised administrators not to expose NAS systems directly to the internet, recommending remote access only through a trusted VPN or myQNAPcloud link. QNAP did not specify which vulnerabilities were being exploited, leaving open whether attackers were abusing older unpatched flaws in QTS and PhotoStation or a more recently fixed issue.
AgeLocker was first documented as a targeted ransomware strain that encrypts files with the open-source Age utility rather than a custom cryptographic routine, a technique identified by the age-encryption.org header in encrypted files. Researchers reported that the malware appended victim-specific extensions to filenames and, in at least one case, skipped an on-system ransom note in favor of an emailed "security audit" demand seeking 7 bitcoin while offering to decrypt a small number of files as proof. The campaign added to a broader wave of ransomware activity affecting QNAP devices, alongside earlier Qlocker and eCh0raix incidents.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
QNAP warned about AgeLocker attacks in September 2020 as customer incidents began to rise. The ransomware had previously exploited bugs in QNAP's QTS firmware and the preinstalled PhotoStation application.
In a reported incident covered in July 2020, investigators found AgeLocker-encrypted files containing an "age-encryption.org" header and observed that the attackers emailed a ransom demand instead of leaving a ransom note on the compromised systems. The victim said the attackers demanded 7 bitcoins and offered free decryption of up to five small files as proof.
AgeLocker was first spotted in July 2020 as a new targeted ransomware strain. Reporting described it as using the Age encryption utility to encrypt victim files rather than a custom encryption implementation.
QNAP said its NAS devices were under attack by the AgeLocker ransomware operation and urged customers to immediately update QTS and installed applications. The company also advised customers not to expose NAS devices directly to the internet and to use a trusted VPN or myQNAPcloud link for remote access if needed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.