eCh0raix — Ransomware Profile
eCh0raix — named QNAPCrypt by Intezer — is a Go-language ransomware family that encrypts files on network-attached storage appliances. Anomali published a public analysis in July 2019, describing samples that encrypt targeted file extensions with AES, append a .encrypt extension, and write a README_FOR_DECRYPT.txt ransom note. Operators break in by brute-forcing weak credentials and by exploiting known device flaws: QNAP's own advisory ties the campaigns to vulnerabilities in earlier versions of QTS and Photo Station, and Fortinet lists the four 2019 Photo Station bugs CVE-2019-7192, CVE-2019-7193, CVE-2019-7194 and CVE-2019-7195 alongside the later Hybrid Backup Sync flaw CVE-2021-28799, an improper authorization vulnerability that allows remote attackers to log in to the devices. Palo Alto Networks Unit 42 documented a variant on 10 August 2021 that was the first the team had seen combining functionality to target both QNAP and Synology NAS devices. Intezer assesses with high confidence that a Russian cybercrime group it calls FullofDeep is behind the QNAPCrypt campaigns, noting builds that filter Belarus, Russia and Ukraine to impede operation if the ransomware is executed from one of those countries. Fortinet records the family as having been in the field since 2019, with comparatively small Bitcoin demands of roughly $1,000 to $3,000; BleepingComputer reported a sudden surge of victims from 1 June 2020 and a further wave of attacks against QNAP NAS devices in June 2022.Also tracked as
QNAPCrypt, FullOfDeep
Vendor research
- The eCh0raix Ransomware Anomali
- FullofDeep Behind QNAPCrypt Ransomware Campaigns Intezer
- New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage (NAS) Devices Palo Alto Networks Unit 42
- eCh0raix Ransomware - Security Advisory QSA-20-02 QNAP Systems