Deadbolt arrives through a flaw in QTS or in an app such as Photo Station, encrypts files in place with a key unique to the victim, appends .deadbolt, and rewrites the login page. It does not touch the RAID, the storage pool or the snapshots beneath the volume, because it works through the file system like any other program. A unit with Snapshot Replication on has, more often than not, a snapshot from before the attack sitting untouched under the encrypted volume, and that snapshot is the cleanest copy of the data that exists.
Qlocker did something different. It used 7-Zip, which was already on the unit, to pack each folder into a password-protected archive, and then deleted the originals. Deleting a file on ext4 marks its blocks free and leaves them where they were, so on a unit that was left alone the originals are often still on the volume, whole, and are carved from the free space on the image. QNAP's own Qlocker assistance in 2021 required an external drive that would be formatted, remote access, and came with no guarantee of the result.
eCh0raix encrypts file by file after guessing a login, and leaves the same things Deadbolt does. In every case the bench images every drive, reassembles the pool, and reads the volume read-only: snapshots first, then deleted originals, then what survives of partly encrypted files, then untouched volumes. Nothing is decrypted, because nothing can be without the key, and the free look says before any charge how much of the material is recoverable and how much is not.