QSnatch Description

Cybersecurity experts have spotted a brand-new malware targeting NAS (Network Attached Storage) devices. Its name is QSnatch, and it goes after QNAP NAS devices specifically. Malware researchers managed to spot the activity of this new threat in the middle of October 2019, as communication between the malware and a particular C&C (Command & Control) server was detected. At first, the experts believed that this newly uncovered malware targets systems operating with Windows, but upon a detailedinspection, it became clear that the QSnatch threat aims at infiltrating NAS devices instead.


It is yet to be determined what infection vectors have been used by the QSnatch authors in the propagation of this threat. The QSnatch threat plants its bad code in the firmware of the host and then runs it as a legitimate process. Then, the QSnatch malware makes sure to establish a connection with the attackers' C&C server. Using various domain generation algorithms, the QSnatch threat is capable of fetching additional harmful payloads. Once this is completed, the QSnatch malware will be able to cause a fair bit of damage to the compromised host. The QSnatch threat is capable of:

  • Prevent any applications from applying updates as this might tamper with its unsafe activity.
  • Prevent the QNAP MalwareRemover application from launching if the users have installed this program on their PCs.
  • Load new features from the attackers' C&C server.
  • Alter the active time-based job schedulers (cronjobs) and init files (initialization scripts that are executed to start necessary processes as part of the boot process).
  • Gather all login credentials present on the infected host and transfer them to the C&C server of its operators.

QSnatch can be Removed from an Infected Device

The QSnatch malware is set to contact the C&C server of the attackers at certain time intervals.

However, you can wipe off the QSnatch malware from your system. However, this may require you to reset the compromised device to factory settings, which means that all the data you are storing on it also will be lost permanently. Then, you have to apply an update that has been released as this will provide further protection for your NAS device.

Do You Suspect Your PC May Be Infected with QSnatch & Other Threats? Scan Your PC with SpyHunter

SpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like QSnatch as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Note: SpyHunter's scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. Free Remover allows you to run a one-off scan and receive, subject to a 48-hour waiting period, one remediation and removal. Free Remover subject to promotional details and Special Promotion Terms. To understand our policies, please also review our EULA, Privacy Policy and Threat Assessment Criteria. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.
If you still can't install SpyHunter? View other possible causes of installation issues.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.