CyCraft
CyCraft is a cybersecurity company whose technology intern participated as a white-hat hacker in the Pwn2Own Ireland 2025 competition. During this event, the intern, along with other research teams (Summoning Team, DEVCORE, Team DDOS), demonstrated several critical zero-day vulnerabilities in QNAP products, including QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync. There is no evidence or indication that CyCraft is a malicious threat actor; rather, their involvement is in the context of responsible vulnerability disclosure and security research. No nation-state affiliation or sub-groups are mentioned. The demonstrated vulnerabilities included stack-based buffer overflows, use-after-free, path traversal, and command injection, leading to unauthenticated remote code execution and privilege escalation. CyCraft's participation was as part of coordinated disclosure at a recognized security competition.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Security research team that discovered and demonstrated zero-day vulnerabilities in QNAP NAS devices during Pwn2Own Ireland 2025.
A CyCraft technology intern participated in Pwn2Own 2025, demonstrating zero-day vulnerabilities in QNAP products as part of a white-hat hacking competition.
A CyCraft technology intern participated in Pwn2Own Ireland 2025, demonstrating zero-day vulnerabilities in QNAP NAS devices.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.