Data Recovery Case File · NAS & RAID · Ransomware
Deadbolt ransomware on two QNAP NAS units: an honest account of a ransomware recovery
A family's entire digital archive — Mac backups and decades of photographs — sat on two internet-connected QNAPs when the Deadbolt campaign swept through exposed QNAP devices. Ransomware cases are where data recovery marketing gets least honest, so this case file is written to be the opposite: here is exactly where recovered data comes from in a case like this, and where it cannot.
| Devices | QNAP TS-219P+ (2 × WD Red 4TB WD40EFRX, mirrored) and QNAP TS-419P II (4 × WD Red 2TB WD20EFRX, RAID array) |
| Reported symptoms | Both units struck by Deadbolt ransomware; files renamed with the .deadbolt extension; ransom note demanding cryptocurrency; vendor support unavailable for end-of-life units |
| Fault class | Malicious encryption of stored data; drives physically healthy |
| Equipment used | Atola TaskForce 2 (parallel write-blocked imaging, all six members) · ACE Lab Data Extractor RAID reconstruction and filesystem analysis |
The enquiry
“I have two QNAPs — my original one backing up our iMac and storing our family photos, and a second I was rebuilding. Both were hit by Deadbolt ransomware. I'm not an IT expert and there was little protection on the NAS drives, which were connected to my network. I couldn't get help from QNAP as the units are no longer supported.”
First, the honest boundary
Deadbolt encrypts files with strong cryptography and renames them with a .deadbolt extension. A file that the malware fully encrypted cannot be decrypted by us, by any data recovery company, or by anyone else without the attacker's key. Any firm telling you otherwise is describing something other than decryption. What a laboratory can do — and what makes cases like this far from hopeless — is recover the data the encryption never actually consumed. In a ransomware-struck NAS there are consistently three places to look, and the split between them is what an assessment establishes.
Where recoverable data lives after a ransomware attack
All six drives were imaged write-blocked on the TaskForce 2 before any analysis — ransomware cases are evidence-handling cases, and nothing runs from original media. The arrays were then reassembled virtually in Data Extractor, and the reconstructed volumes examined for the three recovery classes.
Unencrypted survivors. Ransomware works through a filesystem over hours or days, and it is frequently interrupted — by a shutdown, a crash, or simply being noticed. Everything the malware had not yet reached remains ordinary, readable data. Powering the units down when the attack was discovered, as this customer did, is what preserves this class.
Deleted originals. Depending on how a variant processes each file, encryption can leave the original file's blocks deallocated on disk rather than overwritten in place. Where that pattern holds, deleted-file recovery and signature-level carving against the volume's free space bring back pre-attack copies of files whose "official" versions are encrypted — recovery yield here depends heavily on how full the volume was and how much was written afterwards, which is why nothing gets written to a struck NAS.
Snapshots and prior structures. NAS filesystems keep more history than users realise — snapshot data where the feature was active, and superseded metadata from before the attack — all of which is searched from the images.
Outcome
The assessment across both arrays produced the pattern these cases usually do: a substantial body of untouched files from the interrupted attack, a further tranche of pre-encryption originals recovered from deallocated space, and a residue of fully-encrypted files that we reported plainly as unrecoverable rather than dressing up. The family's photo archive — the material that actually mattered — fell overwhelmingly into the first two classes. We also gave the advice that outlasts the job: these units should never return to the open internet, and the recovered archive now needs the offline backup it never had.
If ransomware hits your NAS
Power it down immediately — every running hour encrypts more and overwrites more. Disconnect it from the network and do not reboot "to check": each boot writes. Don't pay the ransom before an assessment; a significant share of the data usually never needed the attacker's key. And treat any recovery firm promising to "decrypt" modern ransomware with the scepticism that claim deserves.
Get a straight answer about what's recoverable — call Bristol Data Recovery on 0117 332 1137.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.