Deadbolt Ransomware is Back
ID: 1a794b9b-eda1-57e4-8a22-5aebdd637bb9
STIX ID: report--1a794b9b-eda1-57e4-8a22-5aebdd637bb9
Feed Name: Censys Blog
Date Published: 2022-03-22
Date Updated: 2026-04-27
Author: Mark Ellzey; Senior Security Researcher
Censys observed and tracked the Deadbolt ransomware campaign that targets QNAP QTS NAS devices (and reported ASUSTOR incidents), which encrypts backup directories and defaces the web administration interface; at peak in January 2022 thousands of devices were infected (4,988 observed), ransoms and wallet addresses were tracked, QNAP issued a firmware update, and infections resurged in March 2022 prompting continued monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
