Qlocker — Ransomware Profile

Qlocker is a ransomware operation that began hitting QNAP network-attached storage devices in the week of 19 April 2021, documented by QNAP itself in security advisory QSA-21-12. Instead of deploying a custom encryptor, the operators abused the NAS platform's own bundled 7-Zip utility to sweep victim files into password-protected .7z archives, remove snapshots and drop a !!!READ_ME.txt ransom note into each affected folder. Access was obtained through CVE-2021-28799, an improper authorization flaw in QNAP's HBS 3 Hybrid Backup Sync application, which CISA added to its Known Exploited Vulnerabilities catalogue on 31 March 2022 with a known-ransomware-use flag. Ransoms were small — 0.01 bitcoin, roughly USD 550, per device — but the volume was high enough to yield about USD 260,000 in the first five days from more than 500 paying victims, and about USD 350,000 within a single month. A weakness in the operators' own Tor payment portal briefly allowed a researcher to pull around 50 victims' decryption keys before it was closed. A second wave of Qlocker attacks against QNAP devices opened on 6 January 2022 with demands raised to between 0.02 and 0.03 bitcoin.

Vendor research

Read the full analysis on IntelFusions