22 April 2021

Qlocker ransomware campaign targets QNAP devices across the globe


Qlocker ransomware campaign targets QNAP devices across the globe

A new ransomware campaign targeting QNAP NAS devices has been spotted recently. Dubbed Qlocker, the campaign uses 7-zip to move files on QNAP devices into password-protected archives.

The attacks came to light on April 19, when multiple users found their devices were encrypted and took to technical forums and the ID-Ransomware service to find out more about the threat.

According to Bleeping Computer, while the files are being locked, the QNAP Resource Monitor will display numerous '7z' processes which are the 7zip command-line executable. After the encryption process is finished the QNAP device's files will be stored in password-protected 7-zip archives ending with the .7z extension. To extract these archives, victims will need to enter a password provided by the attacker.

A ransom note left by the attackers includes a unique client key that the victims need to enter to log into the ransomware's Tor payment site. To receive the password for the encrypted archives the victims must pay 0.01 Bitcoins (~$533).

QNAP said it believes that the attackers are exploiting the CVE-2020-36195 vulnerability to execute the ransomware on devices.

Earlier this month QNAP addressed a high risk vulnerability (CVE-2020-2509) in QNAP QTS that allowed remote hackers to execute arbitrary shell commands on the target system.

Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024