Team DDOS is a white-hat security research team known for vulnerability discovery and live exploitation demonstrations at Pwn2Own Ireland 2025. The team publicly demonstrated exploit chains against QNAP products, including SD-WAN routers, NAS devices, and HBS 3 Hybrid Backup Sync, and achieved root-level compromise by chaining multiple vulnerabilities. Reported demonstrations included flaws that enabled privilege escalation, unauthorized access to sensitive data, command execution, and system disruption, as well as path traversal issues affecting backup data. Team DDOS received a $100,000 award for an exploit chain involving multiple QNAP flaws. The available information characterizes Team DDOS as a legitimate offensive security research team participating in coordinated vulnerability disclosure rather than a malicious intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Security research team that demonstrated a chained exploit against QNAP devices at Pwn2Own Ireland 2025 to gain root access.
Security researchers credited with reporting multiple QuRouter vulnerabilities at Pwn2Own 2025.
Security research team that discovered and demonstrated zero-day vulnerabilities in QNAP NAS devices during Pwn2Own Ireland 2025.
Participated in Pwn2Own 2025, demonstrating zero-day vulnerabilities in QNAP products as part of a white-hat hacking competition.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.