Quessts is an underground online persona associated with the development, promotion, and sale of offensive and abuse-enabling tooling across multiple platforms. Activity attributed to this alias spans Android application crypting intended to evade Google Play Protect, Windows antivirus bypass tooling, social-media abuse utilities, marketplace sales, and related monetization infrastructure. The persona maintained consistent branding across forums, code-hosting platforms, and messaging channels, indicating a structured and sustained operational presence rather than isolated experimentation. Observed activity includes advertising an Android-focused crypting service designed to modify or protect APKs from detection, as well as maintaining or promoting Windows AV-bypass tooling described as facilitating payload download and antivirus exclusion. Quessts was also linked to Snapify, a Snapchat-focused abuse tool intended to manipulate engagement metrics, and to broader exploit-tool distribution and technical discussions in underground communities. Additional marketplace behavior included sales of verified accounts and other digital goods, suggesting a blended model of tool development, abuse enablement, and direct monetization. The alias appeared across multiple cybercrime-oriented forums and Telegram communities, where it was used for promotion, support, distribution, and customer contact. Reported activity also included exploit-related discussions, instructional content, Linux setup guidance, and references to DDoS tooling. The overall pattern is consistent with a financially motivated underground operator involved in malware-adjacent evasion services, social-media abuse tooling, account sales, and related cybercrime facilitation. High-confidence reporting directly supports the alias Quessts; no corroborated sub-group structure or additional formal aliases are established beyond the same name variant.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.