SecPod

Learn Search

Search across all Learn content

← Back to Security Research
AgeLocker Ransomware Targeting QNAP NAS Devices

AgeLocker Ransomware Targeting QNAP NAS Devices

AgeLocker Ransomware targeting QNAP network-attached storage (NAS) devices have been used by attackers to encrypt user data and demand a ransom. It has been found after research that no unpatched vulnerability was found to be exploited in the use of AgeLocker ransomware attack, whereas all the known...

Sep 29, 2020By Vishesh S2 min read

AgeLocker Ransomware targeting QNAP network-attached storage (NAS) devices have been used by attackers to encrypt user data and demand a ransom. It has been found after research that no unpatched vulnerability was found to be exploited in the use of AgeLocker ransomware attack, whereas all the known affected QNAP NAS Devices are running older unpatched QNAP device firmware which needs to be updated.

AgeLocker Ransomware Details:
AgeLocker malware name originates with the use of Actually Good Encryption (AGE) algorithm to encrypt data. Researchers have warned that once data is encrypted with the malware there is no way to decrypt it without paying the ransom to the attackers.

Last week QNAP published a security advisory providing the technical details of the malware and  steps to mitigate the attack. Currently, intelligence has pointed out that AgeLocker affected systems are macOS and Linux devices. When the ransomware has encrypted the files, it leaves behind a ransom note named HOW_TO_RESTORE_FILES.txt stating the victim that their QNAP device has been targeted for a ransomware attack and data is encrypted with a special encryption algorithm as shown in the below screenshot.

Unfortunately a malware has infected your QNAP and a large number of your files has been encrypted using a hybrid encryption scheme.

AgeLocker QNAP Ransom Note
AgeLocker QNAP Ransom Note

Image Credit: bleepingcomputer

The vendor also added in an alert that older versions of the PhotoStation app are also affected by the known issue.

QNAP Product Security Incident Response Team (PSIRT) has found evidence that the ransomware may attack earlier versions of Photo Station. We are thoroughly investigating the case and will release more information as soon as possible.

Affected products
QNAP NAS devices running older versions of QTS(known as QNAP device firmware) and older versions of PhotoStation app mostly on macOS and Linux.

Impact
This issue allows remote attackers to encrypt files on the affected system and demand for ransom.

Solution
The Vendor has published a security advisory stating the technical details of mitigating the vulnerability and to make sure issues have been patched.

Featured Posts

Open CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

CVE Research

CVE-2026-31431: From 732 Bytes to Root - Anatomy of a Modern Linux Privilege Escalation

Jun 24, 2026

Open CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

CVE Research

CVE-2026-31431: The Nine-Year Kernel Bug Hiding in Plain Sight

Jun 23, 2026

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

AgeLocker Ransomware Targeting QNAP NAS Devices | SecPod