Taking work now — the first look is freeNAS drives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
NDRNAS Data Recovery 0800 6890668 Price my job
NDR / Whatever it is saying now / QNAP Deadbolt and Qlocker

Deadbolt · Qlocker · eCh0raix · .deadbolt · 7z archives

A QNAP hit by Deadbolt or Qlocker. The array is untouched. The files on it have been replaced, and not all of them.

Deadbolt announced itself on QNAP units from 25 January 2022 by replacing the login page with a ransom note and renaming every file .deadbolt; Censys counted 4,988 infected units the next day and 7,783 in a surge that July. Qlocker arrived on 19 April 2021 through a hard-coded credential in QNAP's HBS 3 backup app, moved files into password-protected 7-Zip archives and deleted the originals. eCh0raix has been brute-forcing QNAP and Synology logins since 2019. None of them touches the RAID; they work through the file system, and what comes back is what they did not reach: snapshots taken before the attack, the originals Qlocker deleted, the tails of large files Deadbolt only partly encrypted, and files on volumes the malware never saw. What does not come back is a Deadbolt-encrypted file without the key. A QNAP set is £500 + VAT upwards after the free look, which says honestly which is which. 5–10 days at the bench.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Pull the network cable, then power down. Do not update QTS, do not reset the unit, and do not reinstall. The deleted originals live in the volume's free space, and every write reuses it. QNAP's forced update in January 2022 removed part of Deadbolt's payload, and units that took it can be harder to assess; tell us if yours did.

How each one works, and what each one leaves behind.

Deadbolt arrives through a flaw in QTS or in an app such as Photo Station, encrypts files in place with a key unique to the victim, appends .deadbolt, and rewrites the login page. It does not touch the RAID, the storage pool or the snapshots beneath the volume, because it works through the file system like any other program. A unit with Snapshot Replication on has, more often than not, a snapshot from before the attack sitting untouched under the encrypted volume, and that snapshot is the cleanest copy of the data that exists.

Qlocker did something different. It used 7-Zip, which was already on the unit, to pack each folder into a password-protected archive, and then deleted the originals. Deleting a file on ext4 marks its blocks free and leaves them where they were, so on a unit that was left alone the originals are often still on the volume, whole, and are carved from the free space on the image. QNAP's own Qlocker assistance in 2021 required an external drive that would be formatted, remote access, and came with no guarantee of the result.

eCh0raix encrypts file by file after guessing a login, and leaves the same things Deadbolt does. In every case the bench images every drive, reassembles the pool, and reads the volume read-only: snapshots first, then deleted originals, then what survives of partly encrypted files, then untouched volumes. Nothing is decrypted, because nothing can be without the key, and the free look says before any charge how much of the material is recoverable and how much is not.

What it says, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
Ransom page; files renamed .deadboltDeadboltSnapshots and untouched volumes recovered; encrypted files not decryptable
7z archives with !!!READ_ME.txtQlockerDeleted originals carved from the volume image
.encrypt files with README_FOR_DECRYPTeCh0raixSnapshots and untouched files recovered
Unit updated itself after the attackQNAP's forced updateAssessed for what the update overwrote
Snapshots were onA copy from before the attackMounted from the image and copied out
Unit reset or QTS reinstalled after the attackFree space and snapshots overwrittenLess comes back; told honestly

From the box arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on the parcel and a number on every drive the day it is opened, and an engineer settles what has actually happened before anything spins. The unit is examined on its own; each drive is assessed on our own equipment, never in a NAS that will try to rebuild. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo rebuilds, no repairs, no resets
02

The unit, and the drives, apart

The box and the disks are two different jobs. The unit is tested separately, because a dead power supply, a failed board or a bricked boot flash leaves the drives untouched more often than not. Each drive is then read on the bench: the ones that answer at full speed, and the weak or failed ones in clean air where they need head work. On units that hold an encryption key or a layout of their own, the unit is part of the data and is kept with it.

Unit and disks assessed separatelyFailing members to the clean bench
03

Every member imaged, once

The pool is reassembled from the images and the volume mounted read-only. Snapshots from before the attack are copied out first; the free space is carved for the originals Qlocker deleted; partly encrypted large files are assessed for what survives beyond the encrypted header; untouched volumes are copied whole. The encrypted files are left where they are, because nothing can decrypt them without the key.

Every drive, including the cacheWeak areas last
04

The set put back together, from the images

Order, chunk size, parity rotation and the reshape point are read from the drives' own metadata and the array is reassembled in software: mdadm and LVM under SHR, X-RAID and QTS pools; a ZFS pool imported read-only; Drobo's BeyondRAID zones reconstructed. The file system, Btrfs, ext4, XFS or ZFS, is repaired on the virtual volume, and encrypted volumes are unlocked there with the key you supply. Never on the originals.

Rebuilt in software, from imagesThe file system repaired on the virtual volume
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job5–10 days at the bench

From the bench

  • Pull the cable before the power. A unit that is still encrypting should be stopped; the network is what it arrived through.
  • Do not update, reset or reinstall. Every one of them writes, and the deleted originals and the snapshots are what writing overwrites.
  • Snapshots are the answer more often than not. Snapshot Replication, if it was on, kept copies beneath the volume that the malware could not see.
  • We do not decrypt, negotiate or pay. The free look says honestly what survives; the decision about the ransom is yours, and often unnecessary.

One job, followed all the way through.

UK · NDR-2026-0530JOB LOGGED ✓

A TS-453D in RAID 5 hit by Deadbolt, with snapshots on and a business that did not know it had them

The network cable came out the moment the ransom page appeared, and the unit was powered down. All four drives were imaged, the pool reassembled, and a snapshot from two days before the attack found beneath the encrypted volume. It was mounted from the image and copied out whole; the .deadbolt files were left where they were.

98% of the share recovered from the snapshot6 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Pull the network cable, then power down
  • Photograph the ransom page and note the file extension
  • Tell us whether snapshots or HBS backups were configured
  • Send every drive, labelled, and the unit

What sets us back

  • Updating QTS after the attack
  • Resetting or reinstalling
  • Deleting the ransom note or the encrypted files
  • Paying, at least before the free look says what survives

Questions answered before you commit.

Can you decrypt my .deadbolt files?

No, and neither can anyone else without the key. What comes back is what Deadbolt did not reach: snapshots, untouched volumes, the tails of partly encrypted files. The free look says how much that is before any charge.

Qlocker turned my files into 7z archives. Are they gone?

Often not. Qlocker deleted the originals after archiving them, and deleted files on ext4 survive in the free space until overwritten. Leave the unit off and send it.

Should I take QNAP's forced update?

If it has already run, tell us. If it has not, do not: it writes to the unit, and the deleted originals and snapshots are in the free space it can overwrite.

What does it cost?

A set is £500 + VAT upwards after the free look, fixed in writing. On most jobs no data means no bill.

How long does it take?

5–10 days at the bench.

Pull the cable. Then send the set.

Snapshots, deleted originals and untouched volumes are read from the images. The first look is free and says honestly what is there.

0800 6890668