Summoning Team is a security research team known for demonstrating previously unknown vulnerabilities in vendor products at the Pwn2Own hacking competition. Publicly attributed activity places the team among white-hat researchers who disclosed multiple QNAP zero-day vulnerabilities during Pwn2Own Ireland 2025, affecting QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync. The demonstrated flaws included memory-corruption and input-validation issues that could enable unauthenticated remote code execution, privilege escalation, denial of service, and full device compromise. Summoning Team is referenced alongside other competition participants such as DEVCORE, Team DDOS, and CyCraft researchers. Available information supports characterization as a vulnerability research team engaged in coordinated disclosure rather than a malicious intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Security research team that discovered and demonstrated zero-day vulnerabilities in QNAP NAS devices during Pwn2Own Ireland 2025.
Participated in Pwn2Own 2025, demonstrating zero-day vulnerabilities in QNAP products as part of a white-hat hacking competition.
Participated in Pwn2Own Ireland 2025, demonstrating zero-day vulnerabilities in QNAP NAS devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.