Home / Case Studies / NAS & Network Storage
NAS & Network Storage · case file

The NAS Re-Encrypts Every Time It Powers On

His situation is still actively getting worse, which is what makes it urgent. A QNAP NAS "partially encrypted" with files renamed to a ".devon extension" keeps encrypting "when it is powered on" — they "reinstalled with a new image, but when the old disks are inserted, it is starting to encrypt" again. The disks hold "10 TB of backup". Ransomware that resumes on every power-up means the malicious process is still present on the disks themselves — so the first rule is the opposite of the instinct to keep trying: stop powering the array, because each attempt encrypts more of what remains.

RAID / NASEncryption / BitLocker
// case at a glance
MediaQNAP NAS disks carrying roughly 10TB of backup data, partially encrypted with files renamed to a .devon extension — the encryption resuming whenever the disks are powered, even after a NAS firmware reinstall
Reported situationPartial ransomware encryption with a .devon file extension · NAS reimaged with fresh firmware in an attempt to stop it · original disks reinserted, encryption restarting on power-up · 10TB of backup data on the array · the process ongoing rather than finished
Fault classActive ransomware persisting on the storage disks — completed encryption sealed by strong cryptography, unencrypted data intact but shrinking with every power-on, the malicious component re-triggering from the disks themselves
Equipment usedDisks removed and imaged individually under hardware write-blockers, so they are never powered in a system that runs the malware again · the QNAP array reconstructed read-only from the images in UFS Explorer · the ransomware's method and the .devon variant identified, its persistence mechanism located · unencrypted data extracted directly, deleted originals swept from free space in X-Ways Forensics · results separated honestly into recovered and sealed
// the decode

The decode

Encryption that resumes on power-up proves the threat lives on the disks, not just the NAS. Reimaging the NAS replaced its operating firmware — a sensible step — but the encryption restarting when the old disks go back in shows the malicious component, or its trigger, resides on the storage disks themselves. So the fresh firmware runs the persistent threat all over again the moment it reads the disks. The problem was never only in the part they replaced.

The critical instruction reverses the natural instinct. The impulse is to keep powering the array to assess the damage or attempt a fix — but every power-on lets the encryption advance further through the still-unencrypted data. On a partial encryption, that directly shrinks what can be recovered. The disks must not be powered in any live system again; the first protective act is to stop, and image the disks in isolation instead.

The honest split follows the pattern of all ransomware. Files the process has already encrypted are sealed with strong cryptography, and without the key those cannot be reversed — no laboratory brute-forces sound encryption, and it would be dishonest to imply the .devon files can simply be unlocked. Everything the process has not yet reached remains intact and fully recoverable. Because the encryption is ongoing, how much falls on the recoverable side depends on stopping it now rather than later.

Imaging in isolation both preserves data and defuses the threat. Removing the disks and imaging each one under write-blocking captures their exact current state without ever powering them in a system that would run the malware. All subsequent work happens on the images, and the array is reconstructed read-only from them — so the recovery cannot itself trigger further encryption, and the live threat is taken out of the loop entirely.

A second avenue can recover more than the untouched files alone. Ransomware of this kind typically deletes or replaces originals as it encrypts, and those deleted originals may persist in the array's free space — recoverable by the same techniques used for any deletion, provided nothing has overwritten them. Keeping the disks unpowered protects that avenue too, potentially returning files that had already been processed.

The deliverable is an honest ledger with the timing made explicit. The result separates what was recovered — untouched files plus any reclaimed originals — from what remains sealed in .devon-encrypted form, and makes clear that the recoverable share was maximised by ceasing power-ups. He sees exactly where the line fell before anything is paid.

// on the bench

On the bench

The disks were removed and imaged individually under hardware write-blockers, never powered in a system that would run the malware again. The QNAP array was reconstructed read-only from the images in UFS Explorer, the .devon variant and its persistence mechanism identified, and unencrypted data extracted directly. Deleted originals were swept from free space in X-Ways Forensics, and the results separated honestly into recovered files and sealed .devon archives.

// the outcome

The outcome

Disks imaged in isolation to halt the threat, the array reconstructed read-only, untouched and reclaimable data recovered, and the sealed remainder reported honestly. The assessment is free and the quote is a single fixed figure inclusive of VAT; if the data cannot be recovered, there is nothing to pay. The decode: the encryption resuming on power-up means the threat is still on your disks — so every power-on costs you more data. Stop powering them, image them in isolation, and everything the process hasn't reached is recoverable; what it finished sealing stays sealed.

A NAS that resumes encrypting whenever it powers on

Power the array down and leave it down — reimaging the NAS doesn't help if the threat lives on the disks, and every power-up encrypts more of your remaining data. Don't keep reinserting the old disks to test it. Remove them and have them imaged in isolation, where the malware can't run. Everything the encryption hasn't reached is recoverable, and deleted originals may be reclaimable from free space, so stopping now directly determines how much comes back.

Sending this in from Staines? Every case starts with a free diagnostic and one fixed written quote before any work — no fix, no fee. If the data is inside a laptop, PC, Mac or server, remove the hard drive or SSD and send us just the drive; we don’t provide an internal drive-removal service, and we don’t recover storage soldered to a motherboard (e.g. Apple Silicon Macs) — only drives that can be removed and sent to us. Post or courier tracked and insured to our Guildford Data Recovery lab — full sending instructions and the shipping form are here.
Start a free diagnostic

Our case files are written up from genuine enquiries our lab has handled for customers across Staines, Surrey and the surrounding area, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery approach our engineers apply to that fault, using the equipment listed.

// related case files

More cases like this one

Browse all case studies →

Got a device with a story like this?

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.