Summoning Team
Summoning Team is a security research team that demonstrated multiple critical zero-day vulnerabilities affecting QNAP NAS software during the Pwn2Own Ireland 2025 competition. In the referenced reporting, Summoning Team is listed alongside other participating research teams (DEVCORE, Team DDOS, and CyCraft) as having demonstrated issues impacting QNAP QTS and QuTS hero operating systems and QNAP applications including Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync. The demonstrated flaws (including stack-based buffer overflows, use-after-free, path traversal, and command injection in CGI handlers such as quick.cgi) could enable unauthenticated remote code execution, privilege escalation to root, and full device takeover, including access to/alteration of stored and backup data. The content characterizes these activities as white-hat research conducted in the context of coordinated disclosure via Pwn2Own; no nation-state attribution, criminal motivation, or operational intrusion activity is described.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Security research team that discovered and demonstrated zero-day vulnerabilities in QNAP NAS devices during Pwn2Own Ireland 2025.
Participated in Pwn2Own 2025, demonstrating zero-day vulnerabilities in QNAP products as part of a white-hat hacking competition.
Participated in Pwn2Own Ireland 2025, demonstrating zero-day vulnerabilities in QNAP NAS devices.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.