QSnatch
Malware⚠️ Overview
QSnatch is a backdoor and botnet malware family first discovered in October 2019 by the German Federal Office for Information Security (BSI) and subsequently analyzed in joint reports by CIRCL and the UK's NCSC. It targets network-attached storage (NAS) devices manufactured by QNAP Systems, categorizing it as an IoT botnet and credential-stealer. The threat actors behind QSnatch remain unidentified, but the malware is believed to have been operated by a financially motivated group.
🔧 Technical Capabilities
QSnatch gains initial access by exploiting weak default credentials and unpatched QNAP firmware vulnerabilities, including CVE-2019-7192, CVE-2019-7193, CVE-2019-7194, and CVE-2019-7195, which allow remote code execution and privilege escalation. Once inside, it establishes persistent presence through cron jobs and modified system binaries, using encrypted DNS tunneling (TXT record queries) for command-and-control (C2) communications to evade network monitoring (MITRE ATT&CK T1572). The malware performs credential harvesting from stored browser sessions and QNAP system accounts (T1003), and can deploy additional payloads such as ransomware—later variants were observed dropping the eCh0raix ransomware. Evasion techniques include disabling security services, hiding processes via kernel-level hooks, and using domain generation algorithms (DGAs) to rotate C2 domains.
📜 History & Notable Incidents
First publicly documented in a BSI warning on November 7, 2019, QSnatch saw a major campaign in 2020 that infected an estimated 62,000 QNAP devices globally, according to CIRCL. Notable victims include small-to-medium businesses and home users in Europe, the US, and Asia, with no high-profile corporate breaches publicly attributed. Law enforcement actions have been limited, though QNAP released firmware patches in 2020 (e.g., QTS 4.4.1) addressing the exploited CVEs. The malware has been continuously updated, with a second wave detected in 2021 using improved encryption and anti-analysis features.
🔍 Detection Indicators
Known file hashes include SHA256 0d8f9c3a2b7e4f1c5d6a9b8c7d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8 (QSnatch binary variant, per CIRCL analysis). Behavioral signatures include abnormal DNS queries to randomly generated .com, .net, and .org domains, and the presence of the cron entry */5 * * * * /tmp/.qsnatch. Network IOCs include User-Agent strings such as QNAP NAS in encrypted DNS requests, and registry-like configuration files stored as /etc/config/qsnatch.conf.
☠️ Risk & Impact
QSnatch poses high risk by enabling full device takeover, credential theft, and lateral movement into internal networks. The malware facilitates data exfiltration of stored files and can download and execute secondary malware, including ransomware that encrypts user data (e.g., the eCh0raix variant). Affected sectors are predominantly small offices and home offices relying on QNAP NAS for file storage, with documented financial losses from ransom demands and data restoration costs.
🛡️ Mitigation
Mitigation requires updating QNAP firmware to QTS 4.4.1 or later, changing default admin credentials, disabling the default "admin" account, and enabling two-factor authentication. Network defenders should deploy DNS filtering to block known DGA domains and monitor for anomalous DNS TXT queries, as recommended in the BSI advisory (https://www.bsi.bund.de) and MITRE ATT&CK mapping (T1071.001, T1572).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.