A Military-Designated Company With Kernel Access to Millions of Endpoints
The U.S. Department of Defense announced an updated Section 1260H list on June 8, 2026, with the formal Federal Register notice published on June 10, 2026, formally designating 360 Security Technology, Inc. (Qihoo 360) as a Chinese military company [1]. The filing states Qihoo 360 is "directly and indirectly affiliated with the Ministry of Industry and Information Technology (MIIT) and the Ministry of State Security (MSS)" [1]. This is not a new concern. It is a designation that has been refined and expanded over multiple iterations since Qihoo 360 was first added to the 1260H list in October 2022, building on its 2020 placement on the BIS Entity List. The 2026 list now covers 188 entities total, including parent companies and their explicitly identified subsidiaries [1].
The problem: Qihoo 360's consumer products, including 360 Total Security, 360 Security (mobile), and various browser and utility tools, remain installed on millions of devices across Southeast Asia, Africa, Europe, and scattered across Western enterprise environments where shadow IT or BYOD policies have not been adequately enforced. These products operate with deep system privileges, as is standard for antivirus software. They read files before execution, inspect network traffic, enumerate running processes, and collect hardware identifiers. That access model is standard for antivirus software. What is not standard is that the vendor behind it has formal, documented ties to China's primary intelligence service.
Background: Who Qihoo 360 Is and Why the MSS Link Matters
Qihoo 360 was founded in 2005 and grew into one of China's largest cybersecurity firms. The company's business model centers on free consumer tools (antivirus, VPN, browser, mobile security) subsidized by advertising and data collection. It also operates an enterprise security division and a significant vulnerability research operation.
The MSS connection is the critical detail. Dakota Cary, a Georgetown University expert in Chinese espionage who advises cybersecurity company SentinelOne [2] and serves as a nonresident fellow at the Atlantic Council's Global China Hub [3], has identified Qihoo 360's role in China's National Information Security Vulnerability Database (CNNVD) as one of its most concerning state relationships [2]. The CNNVD is operated by the MSS [2][4]. This means Qihoo 360 contributes vulnerability intelligence to an organization that also runs China's foreign intelligence operations. The implications for vulnerability equities decisions are straightforward: the MSS has a direct channel to one of China's most prolific vulnerability research teams.
China's 2017 National Intelligence Law (Article 7) requires Chinese organizations and citizens to "support, assist, and cooperate" with national intelligence work [5]. There is no court order requirement, no transparency reporting, and no public accountability mechanism. Qihoo 360 operates under this law.
The 2026 Designation: What Changed
The June 2026 Federal Register filing expanded the legal consequences of the 1260H designation. Under Section 805 of the FY2024 NDAA, the DoD is now prohibited from executing new contracts with 1260H-listed entities effective June 30, 2026 [1]. This creates a hard contracting prohibition, not just an advisory.
The designation language itself is more specific than previous iterations. Qihoo 360 is classified as a "military civil fusion contributor to the Chinese defense industrial base" under Sections 1260H(g)(3)(B)(i) and (g)(3)(B)(iv) [1]. "Military civil fusion" is China's strategic program to eliminate barriers between civilian commercial technology companies and defense/intelligence applications. Qihoo 360 is not assessed to be passively complying with intelligence requests. According to the U.S. government's assessment, it is an active participant in the civil-military integration pipeline.
What 360 Products Have Access To
Security software operates at the highest privilege levels on an endpoint. Like most antivirus products, a standard 360 Total Security installation is assessed to run with kernel-level access and has visibility into:
- File system contents: documents, cached credentials, SSH keys, configuration files, browser databases
- Network traffic: metadata at minimum, full payload content in some configurations
- Process enumeration: complete view of running processes, loaded modules, and service configurations
- Browser data: history, bookmarks, cached form data, session tokens depending on product configuration
- Hardware identifiers: MAC addresses, serial numbers, BIOS/UEFI data, TPM information
- Peripheral devices: USB device history, connected storage, input devices
This privilege level is identical to what Norton, CrowdStrike, or any other security vendor requires. The access is not the anomaly. The jurisdiction and the formal MSS affiliation are.
The Kaspersky Precedent
The closest policy parallel is Kaspersky Lab. In 2017, DHS issued Binding Operational Directive 17-01, directing federal agencies to remove Kaspersky products from federal systems over concerns about ties between Kaspersky and Russian intelligence services. In 2024, the Commerce Department's Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from selling software in the United States under Executive Order 13873 and the ICTS regulations.
Qihoo 360 has received military company designations and contracting prohibitions but has not yet faced a full commercial sales ban in most Western markets. The technical risk profile is assessed to be comparable or worse: Qihoo 360's product distribution is more consumer-oriented and geographically dispersed than Kaspersky's enterprise-focused deployment model. Kaspersky had concentrated enterprise penetration in government and critical infrastructure. Qihoo 360 has broad, diffuse consumer presence that is harder to inventory and remediate.
The CNNVD Vulnerability Pipeline
This angle deserves specific attention from defenders and vulnerability management teams. Qihoo 360 operates one of China's most active vulnerability research programs. Their researchers regularly discover and report high-severity vulnerabilities in widely deployed software.
The CNNVD, operated by the MSS, is one of the primary repositories for this research [2][4]. The concern is not theoretical: a company with deep endpoint access to hundreds of millions of endpoints worldwide also feeds vulnerability intelligence to an intelligence service. The vulnerability equities question becomes acute. Does a zero-day discovered by a Qihoo 360 researcher get reported to the affected vendor first, or does it pass through the CNNVD/MSS pipeline where it could be stockpiled for offensive use before public disclosure?
China's 2021 Regulations on the Management of Network Product Security Vulnerabilities formalized a requirement that vulnerabilities be reported to MIIT within 48 hours of discovery [5]. Research by Recorded Future and the Atlantic Council has assessed that MIIT shares this information with the CNNVD [4][6]. This creates a structural disclosure delay where the MSS likely receives vulnerability intelligence before affected vendors do.
Products and Distribution Channels
Qihoo 360's consumer-facing products are distributed through multiple channels:
- 360 Total Security: Windows desktop antivirus, free tier with premium upsell
- 360 Security: Android mobile security app, distributed through Google Play and third-party APK repositories
- 360 Secure Browser: Chromium-based browser for Windows
- 360 Connected Home: IoT/router security platform
- 360 WiFi: Network utility tools
- Various OEM bundling agreements: pre-installed on devices sold in Asian and African markets
The mobile distribution is particularly relevant. Mobile security apps in this category typically request permissions including device administration, camera, microphone, SMS, call logs, contacts, and storage access. These permissions are within the range of what mobile security apps request, but grant comprehensive device telemetry to a company designated as an MSS affiliate. Organizations should verify specific permissions against current app store listings for the versions deployed in their environment.
Detection and Hunting
Organizations should treat Qihoo 360 software presence as a supply chain risk indicator that requires investigation and likely remediation.
Endpoint Discovery
Search for the following process names, service names, and installation paths (derived from analysis of publicly available 360 product installations):
- Process names:
360Tray.exe,360Safe.exe,360sd.exe,QHSafeMain.exe,QHActiveDefense.exe,360rp.exe,ZhuDongFangYu.exe - Service names:
360rp,ZhuDongFangYu,QHActiveDefense,360AntiHacker - Installation directories:
C:\Program Files\360\,C:\Program Files (x86)\360\,C:\Users\*\AppData\Roaming\360Safe\ - Registry keys:
HKLM\SOFTWARE\360Safe,HKLM\SOFTWARE\Qihoo
Network Indicators
Qihoo 360 products phone home to domains under the following parent zones. Monitor DNS and proxy logs for resolution attempts:
*.360.cn*.360safe.com*.qihoo.com*.360.com(Note: broad wildcard; may require additional filtering to reduce false positives)*.360totalsecurity.com
SIEM/EDR Queries
For Splunk environments:
index=endpoint (process_name="360Tray.exe" OR process_name="360Safe.exe" OR process_name="360sd.exe" OR process_name="QHSafeMain.exe")
For DNS hunting:
index=dns (query="*.360.cn" OR query="*.360safe.com" OR query="*.qihoo.com" OR query="*.360totalsecurity.com")
Mobile Device Management
Query MDM platforms for apps with package names:
com.qihoo.securitycom.qihoo.browser
Note: Verify current package names against app store listings, as Qihoo 360 has used multiple package name variants historically (e.g., com.qihoo360.mobilesafe, com.qihoo360.antivirus).
Analysis
The 2026 1260H designation confirms what has been reported for years: the U.S. government assesses Qihoo 360 as functionally integrated with Chinese military and intelligence infrastructure. The designation language moved beyond vague "linked to" framing to specific citation of military civil fusion contribution and direct MSS affiliation [1].
The contracting prohibition that took effect June 30, 2026 will primarily affect DoD supply chain vetting. It does not restrict commercial use by U.S. companies or consumers. The regulatory posture toward Qihoo 360 currently lags behind the Kaspersky precedent by several years, despite what we assess to be a comparable or greater risk surface.
For non-U.S. organizations, particularly those in Southeast Asia and Africa where 360 products have the deepest penetration, there is effectively no regulatory pressure to remove this software. The risk assessment falls entirely on individual organizations.
Red Sheep Assessment
Confidence: High
The gap between Qihoo 360's formal designation status and the absence of a commercial ban resembles the 2017-2024 Kaspersky trajectory. DHS designated Kaspersky in 2017; the full commercial ban did not arrive until 2024. The U.S. government's pattern suggests a commercial prohibition on Qihoo 360 consumer products is likely a matter of sequencing, not likelihood.
Organizations that wait for a formal ban before remediating will likely repeat the Kaspersky cycle: scrambling to identify and remove deeply embedded security software under time pressure when a ban finally arrives. The procurement and legal infrastructure to ban Qihoo 360 commercially already exists under EO 13873 and the ICTS regulations, the same authority used for Kaspersky.
The CNNVD/vulnerability pipeline angle is the most underappreciated risk. A company that simultaneously has deep endpoint access on consumer devices worldwide AND feeds zero-day research to a foreign intelligence service represents a convergence of collection capability and intelligence access that few other commercial entities can match. The endpoint access is a function of Qihoo 360's antivirus product architecture. The CNNVD contribution is documented [2], and the MSS affiliation is formally assessed by the U.S. government [1].
The contrarian view: Qihoo 360's massive install base in Chinese consumer markets means most of its telemetry is domestic Chinese data, not foreign intelligence collection. The counterargument is that intelligence services do not need to collect on everyone. Targeted access to specific devices belonging to persons of interest, enabled by a pre-positioned collection platform, is the operational model that matters.
Defender's Checklist
- ▢[ ] P1 (Immediate): Run endpoint discovery queries for 360 processes (
360Tray.exe,360Safe.exe,QHSafeMain.exe) across all managed endpoints and document findings with asset owner attribution - ▢[ ] P1 (Immediate): Query DNS/proxy logs for
.360.cn,.360safe.com,.qihoo.com, and.360totalsecurity.comto identify installations not visible through endpoint telemetry - ▢[ ] P1 (Immediate): Query MDM platforms for
com.qihoo.securityandcom.qihoo.browserpackage names on managed mobile devices (verify current package names against app store listings) - ▢[ ] P2 (Short-term): Update BYOD and acceptable use policies to explicitly prohibit Qihoo 360 products on devices that connect to corporate networks or access corporate data
- ▢[ ] P3 (Ongoing): Add Qihoo 360 / 360 Security Technology, Inc. to third-party risk assessment questionnaires and supply chain vendor screening criteria
References
- Federal Register Vol. 91, No. 111 - DoD Section 1260H Chinese Military Companies Notice (June 10, 2026)
- Qihoo 360: The Cyber Giant Behind China's Mythos Rival - Forbes (June 30, 2026)
- Dakota Cary - Atlantic Council Global China Hub
- Sleight of hand: How China weaponizes software vulnerabilities - Atlantic Council (March 2025)
- [National Intelligence Law of the People's Republic of China (2017); Regulations on the Management of Network Product Security Vulnerabilities (2021)]
- China's Zero-Day Pipeline: From Discovery to Deployment - Recorded Future
Event Timeline
Timeline
Entity Relationships
Entity Graph (12 entities, 10 relationships)
Diamond Model
Note: This report is a supply chain risk advisory, not an intrusion analysis. The Diamond Model is presented below in an adapted form to illustrate the assessed threat scenario, not a specific confirmed intrusion.
Diamond Model
Hunt Guide: Qihoo 360 Supply Chain Risk β MSS-Affiliated Security Software on DoD/Enterprise Endpoints
Attribution: Detection logic below credits its original author. Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher). Only rules explicitly marked RedSheep Security/Stone (original) were authored in-house. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Qihoo 360 (360 Security Technology) products are present in our environment, we expect to observe their process names (360Tray.exe, 360Safe.exe, QHSafeMain.exe), installation directories (C:\Program Files\360\), registry keys (HKLM\SOFTWARE\360Safe), mobile app packages (com.qihoo.security), and DNS callbacks to .360.cn, .360safe.com, .qihoo.com, and .360totalsecurity.com in endpoint telemetry, DNS logs, proxy logs, and MDM inventory.
Intelligence Summary: The U.S. DoD designated Qihoo 360 (360 Security Technology, Inc.) as a Chinese military company under Section 1260H on June 8, 2026, citing direct and indirect affiliation with the Ministry of State Security (MSS) and participation in military-civil fusion. Qihoo 360's consumer security products β 360 Total Security, 360 Security (mobile), 360 Secure Browser β remain installed on millions of endpoints globally with kernel-level access, while the company simultaneously feeds vulnerability intelligence to the MSS-operated CNNVD. This creates a pre-positioned collection platform with deep endpoint visibility operated by a formally designated MSS affiliate.
Confidence: High | Priority: Critical
Scope
- Networks: All enterprise networks, NIPR segments, BYOD-accessible network segments, remote access/VPN zones, and any network segments accessible by personal or unmanaged devices. Include cloud infrastructure (AWS, Azure, GCP) instances and containers. Special attention to overseas/OCONUS sites in Southeast Asia, Africa, and Europe where Qihoo 360 consumer product penetration is highest.
- Timeframe: Immediate 72-hour sweep for P1 indicators (process names, DNS callbacks, registry keys), followed by 30-day retrospective analysis of DNS and proxy logs to identify intermittent or periodic product communications. Ongoing monitoring recommended as persistent detection requirement.
- Priority Systems: Domain controllers, PKI infrastructure, mail servers, file servers containing CUI/PII/PHI, jump boxes, privileged access workstations, VPN concentrators, any system processing classified or sensitive data, medical device management systems, and all systems belonging to personnel with security clearances or access to sensitive programs. BYOD endpoints connecting to corporate WiFi or VPN are high-priority for DNS-based detection.
MITRE ATT&CK Techniques
T1195.002 β Compromise Software Supply Chain (Initial Access) [P1]
Qihoo 360 security products represent a supply chain risk vector. As an MSS-affiliated vendor with kernel-level access on endpoints, the software itself is the pre-positioned supply chain compromise. The vendor has the technical capability to push updates, modify detection logic, or exfiltrate data through legitimate product update channels. This mirrors the Kaspersky risk model where a foreign intelligence-affiliated security vendor has privileged access to endpoints.
Splunk SPL:
index=endpoint (process_name IN ("360Tray.exe", "360Safe.exe", "360sd.exe", "QHSafeMain.exe", "QHActiveDefense.exe", "360rp.exe", "ZhuDongFangYu.exe")) | stats count by host, process_name, process_path, user | sort -count
Elastic KQL:
process.name:("360Tray.exe" OR "360Safe.exe" OR "360sd.exe" OR "QHSafeMain.exe" OR "QHActiveDefense.exe" OR "360rp.exe" OR "ZhuDongFangYu.exe")
Sigma Rule:
title: Qihoo 360 Security Product Process Execution
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
description: Detects execution of Qihoo 360 security product processes, which are designated as MSS-affiliated supply chain risk software per DoD Section 1260H (June 2026).
author: RedSheep Security/Stone
date: 2026/07/14
references:
- https://www.govinfo.gov/content/pkg/FR-2026-06-10/pdf/2026-11571.pdf
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\360Tray.exe'
- '\360Safe.exe'
- '\360sd.exe'
- '\QHSafeMain.exe'
- '\QHActiveDefense.exe'
- '\360rp.exe'
- '\ZhuDongFangYu.exe'
condition: selection
falsepositives:
- Legitimate but unauthorized Qihoo 360 installations on BYOD or shadow IT endpoints
level: high
tags:
- attack.initial_access
- attack.t1195.002
Attribution: RedSheep Security/Stone (original)
This is a direct IOC-based detection. Any hit in a DoD/IC environment is a P1 finding requiring immediate investigation and remediation. In commercial environments, prioritize systems with access to sensitive data or network segments.
T1036.005 β Match Legitimate Name or Location (Defense Evasion) [P1]
Qihoo 360 products install into legitimate-appearing directories and use service names that could be mistaken for legitimate security tooling. The product's legitimate antivirus functionality provides cover for any data collection or exfiltration activity, as telemetry to vendor servers is expected behavior for AV products.
Splunk SPL:
index=endpoint (registry_path="HKLM\\SOFTWARE\\360Safe*" OR registry_path="HKLM\\SOFTWARE\\Qihoo*" OR file_path="C:\\Program Files*\\360\\*" OR file_path="*\\AppData\\Roaming\\360Safe\\*") | stats count by host, registry_path, file_path | sort -count
Elastic KQL:
(registry.path:*SOFTWARE\\360Safe* OR registry.path:*SOFTWARE\\Qihoo* OR file.path:*Program\ Files*\\360\\* OR file.path:*AppData\\Roaming\\360Safe\\*)
Sigma Rule:
title: Qihoo 360 Registry Keys or Installation Directories Detected
id: b2c3d4e5-f6a7-8901-bcde-f12345678901
status: experimental
description: Detects registry keys or file system artifacts associated with Qihoo 360 product installations.
author: RedSheep Security/Stone
date: 2026/07/14
references:
- https://www.govinfo.gov/content/pkg/FR-2026-06-10/pdf/2026-11571.pdf
logsource:
category: registry_set
product: windows
detection:
selection_registry:
TargetObject|contains:
- '\SOFTWARE\360Safe'
- '\SOFTWARE\Qihoo'
condition: selection_registry
falsepositives:
- Historical registry artifacts from previously uninstalled Qihoo 360 products
level: high
tags:
- attack.defense_evasion
- attack.t1036.005
Attribution: RedSheep Security/Stone (original)
Registry artifacts may persist after product removal. Confirm whether active installation exists versus residual artifacts. Both findings should be documented.
T1071.001 β Web Protocols (Command and Control) [P1]
Qihoo 360 products communicate with vendor infrastructure over HTTPS for telemetry, updates, and cloud-based scanning. These communications to .360.cn, .360safe.com, .qihoo.com, and .360totalsecurity.com represent C2-equivalent channels β the vendor can push configuration changes, receive endpoint telemetry, and potentially task collection operations through legitimate product update mechanisms.
Splunk SPL:
index=dns (query="*.360.cn" OR query="*.360safe.com" OR query="*.qihoo.com" OR query="*.360totalsecurity.com") | stats count values(query) as domains by src_ip | sort -count
Elastic KQL:
dns.question.name:(*.360.cn OR *.360safe.com OR *.qihoo.com OR *.360totalsecurity.com)
Sigma Rule:
title: DNS Query to Qihoo 360 Domains
id: c3d4e5f6-a7b8-9012-cdef-123456789012
status: experimental
description: Detects DNS resolution attempts to Qihoo 360 product domains, indicating presence of MSS-affiliated security software.
author: RedSheep Security/Stone
date: 2026/07/14
references:
- https://www.govinfo.gov/content/pkg/FR-2026-06-10/pdf/2026-11571.pdf
logsource:
category: dns
detection:
selection:
query|endswith:
- '.360.cn'
- '.360safe.com'
- '.qihoo.com'
- '.360totalsecurity.com'
condition: selection
falsepositives:
- Legitimate research or threat intelligence queries to these domains
- Domain name collisions with .360.com (broad wildcard excluded to reduce FP)
level: high
tags:
- attack.command_and_control
- attack.t1071.001
Attribution: RedSheep Security/Stone (original)
The .360.com wildcard is intentionally excluded from this rule due to high false positive potential (360.com is a common domain pattern). Investigate .360.com hits manually if needed. DNS hits may reveal installations not visible to endpoint agents on unmanaged/BYOD devices.
T1005 β Data from Local System (Collection) [P2]
As antivirus software, Qihoo 360 products have legitimate access to scan all files on the local system including documents, credentials, SSH keys, browser databases, and configuration files. This access model is standard for AV but creates a pre-positioned collection capability when the vendor is an assessed MSS affiliate. The software can read and exfiltrate any file on the endpoint under the guise of normal security scanning operations.
Splunk SPL:
index=endpoint process_name IN ("360Tray.exe", "360Safe.exe", "360sd.exe", "QHSafeMain.exe") (file_path="*.pem" OR file_path="*.key" OR file_path="*.pfx" OR file_path="*id_rsa*" OR file_path="*.kdbx" OR file_path="*ntds.dit*") | stats count by host, process_name, file_path | sort -count
Elastic KQL:
process.name:("360Tray.exe" OR "360Safe.exe" OR "360sd.exe" OR "QHSafeMain.exe") AND file.path:(*.pem OR *.key OR *.pfx OR *id_rsa* OR *.kdbx)
Sigma Rule:
title: Qihoo 360 Process Accessing Sensitive Files
id: d4e5f6a7-b8c9-0123-defa-234567890123
status: experimental
description: Detects Qihoo 360 processes accessing sensitive credential or key files, which may indicate collection activity beyond normal AV scanning.
author: RedSheep Security/Stone
date: 2026/07/14
logsource:
category: file_access
product: windows
detection:
selection_process:
Image|endswith:
- '\360Tray.exe'
- '\360Safe.exe'
- '\360sd.exe'
- '\QHSafeMain.exe'
selection_files:
TargetFilename|endswith:
- '.pem'
- '.key'
- '.pfx'
- '.kdbx'
TargetFilename|contains:
- 'id_rsa'
- 'id_ed25519'
condition: selection_process and selection_files
falsepositives:
- Legitimate AV scanning of key/credential file directories
level: critical
tags:
- attack.collection
- attack.t1005
Attribution: RedSheep Security/Stone (original)
This is a behavioral detection. AV products legitimately scan all files, so this will generate false positives during scheduled scans. Correlate with network egress to Qihoo domains to identify potential exfiltration. Requires file access auditing (Windows Security 4663 with SACLs or Sysmon with appropriate configuration).
T1082 β System Information Discovery (Discovery) [P2]
Qihoo 360 products collect hardware identifiers including MAC addresses, serial numbers, BIOS/UEFI data, and TPM information as part of their normal operation. This system fingerprinting data, when exfiltrated to an MSS-affiliated vendor, provides device-level identification that could support targeted intelligence operations.
Splunk SPL:
index=endpoint process_name IN ("360Tray.exe", "360Safe.exe", "QHSafeMain.exe") (CommandLine="*wmic*" OR CommandLine="*systeminfo*" OR CommandLine="*hostname*" OR CommandLine="*ipconfig*") | stats count by host, process_name, CommandLine
Elastic KQL:
process.parent.name:("360Tray.exe" OR "360Safe.exe" OR "QHSafeMain.exe") AND process.command_line:(*wmic* OR *systeminfo* OR *hostname*)
Sigma Rule:
title: Qihoo 360 Product Spawning System Discovery Commands
id: e5f6a7b8-c9d0-1234-efab-345678901234
status: experimental
description: Detects Qihoo 360 processes spawning system information discovery commands beyond normal AV behavior.
author: RedSheep Security/Stone
date: 2026/07/14
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\360Tray.exe'
- '\360Safe.exe'
- '\QHSafeMain.exe'
- '\QHActiveDefense.exe'
selection_child:
Image|endswith:
- '\wmic.exe'
- '\systeminfo.exe'
- '\ipconfig.exe'
- '\net.exe'
- '\whoami.exe'
condition: selection_parent and selection_child
falsepositives:
- Some AV products legitimately invoke system utilities during health checks
level: medium
tags:
- attack.discovery
- attack.t1082
Attribution: RedSheep Security/Stone (original)
Behavioral detection for anomalous child processes spawned by Qihoo 360 products. Baseline normal Qihoo 360 process behavior before alerting. Higher fidelity when combined with P1 presence detections.
T1102 β Web Service (Command and Control) [P2]
Qihoo 360's cloud-based scanning and update infrastructure functions as a legitimate web service that can be repurposed for tasking and data exfiltration. Product updates, signature downloads, and cloud scan submissions all represent sanctioned data channels that bypass typical network security controls because they appear as legitimate AV vendor communications.
Splunk SPL:
index=proxy (url="*360.cn*" OR url="*360safe.com*" OR url="*qihoo.com*" OR url="*360totalsecurity.com*") | stats sum(bytes_out) as total_bytes_out count by src_ip, url | where total_bytes_out > 10485760 | sort -total_bytes_out
Elastic KQL:
url.domain:(*.360.cn OR *.360safe.com OR *.qihoo.com OR *.360totalsecurity.com) AND network.bytes > 10485760
Sigma Rule:
title: High Volume Data Transfer to Qihoo 360 Infrastructure
id: f6a7b8c9-d0e1-2345-fabc-456789012345
status: experimental
description: Detects large data transfers to Qihoo 360 cloud infrastructure which may indicate bulk telemetry exfiltration.
author: RedSheep Security/Stone
date: 2026/07/14
logsource:
category: proxy
detection:
selection:
c-uri|contains:
- '360.cn'
- '360safe.com'
- 'qihoo.com'
- '360totalsecurity.com'
condition: selection
falsepositives:
- Normal AV update downloads and cloud scanning telemetry
level: medium
tags:
- attack.command_and_control
- attack.t1102
Attribution: RedSheep Security/Stone (original)
Focus on bytes_out (upload) rather than bytes_in (downloads). Large uploads to Qihoo infrastructure are more concerning than update downloads. Threshold of 10MB is a starting point β tune based on environment baseline.
T1543.003 β Windows Service (Persistence) [P1]
Qihoo 360 installs multiple Windows services for persistence and kernel-level access, including 360rp, ZhuDongFangYu, QHActiveDefense, and 360AntiHacker. These services run at SYSTEM privilege and start automatically, providing persistent kernel-level access that survives reboots.
Splunk SPL:
index=endpoint sourcetype=WinEventLog:System EventCode=7045 (ServiceName IN ("360rp", "ZhuDongFangYu", "QHActiveDefense", "360AntiHacker") OR ImagePath="*\\360\\*" OR ImagePath="*\\Qihoo\\*") | stats count by host, ServiceName, ImagePath, ServiceStartType
Elastic KQL:
event.code:"7045" AND (winlog.event_data.ServiceName:("360rp" OR "ZhuDongFangYu" OR "QHActiveDefense" OR "360AntiHacker") OR winlog.event_data.ImagePath:*360*)
Sigma Rule:
title: Qihoo 360 Service Installation Detected
id: a7b8c9d0-e1f2-3456-abcd-567890123456
status: experimental
description: Detects installation of Qihoo 360 Windows services which provide kernel-level persistent access.
author: RedSheep Security/Stone
date: 2026/07/14
logsource:
product: windows
service: system
detection:
selection:
EventID: 7045
ServiceName:
- '360rp'
- 'ZhuDongFangYu'
- 'QHActiveDefense'
- '360AntiHacker'
condition: selection
falsepositives:
- None expected in DoD/IC environments; any match is a finding
level: critical
tags:
- attack.persistence
- attack.t1543.003
Attribution: RedSheep Security/Stone (original)
In DoD/IC environments, any hit is an immediate P1 finding. The service name 'ZhuDongFangYu' translates from Chinese as 'Active Defense' β this is Qihoo 360's real-time protection module.
Indicators of Compromise
| Type | Value | Context |
|---|---|---|
| domain | *.360.cn |
Qihoo 360 primary domain zone β product telemetry, updates, cloud scanning infrastructure |
| domain | *.360safe.com |
Qihoo 360 Safe product domain β 360 Total Security and related product communications |
| domain | *.qihoo.com |
Qihoo corporate domain zone β product backend and corporate infrastructure |
| domain | *.360totalsecurity.com |
360 Total Security product-specific domain β international distribution and update infrastructure |
| domain | *.360.com |
Broad Qihoo 360 domain zone β requires manual investigation due to high false positive potential from unrelated .360.com domains |
| filename | 360Tray.exe |
Qihoo 360 system tray/notification area process β primary user-facing component |
| filename | 360Safe.exe |
Qihoo 360 Safe main executable β core antivirus scanner process |
| filename | 360sd.exe |
Qihoo 360 Security Desktop component |
| filename | QHSafeMain.exe |
Qihoo 360 Safe main module β core protection engine |
| filename | QHActiveDefense.exe |
Qihoo 360 Active Defense module β real-time protection component |
| filename | 360rp.exe |
Qihoo 360 real-time protection service executable |
| filename | ZhuDongFangYu.exe |
Qihoo 360 Active Defense module (Chinese name: δΈ»ε¨ι²εΎ‘) β kernel-level protection component |
| registry | HKLM\SOFTWARE\360Safe |
Qihoo 360 Safe product registry hive β indicates product installation |
| registry | HKLM\SOFTWARE\Qihoo |
Qihoo corporate registry hive β indicates Qihoo product installation |
IOC Sweep Queries (Splunk):
index=dns query="*.360.cn" | stats count values(query) as resolved_domains by src_ip | sort -count
index=dns query="*.360safe.com" | stats count values(query) as resolved_domains by src_ip | sort -count
index=dns query="*.qihoo.com" | stats count values(query) as resolved_domains by src_ip | sort -count
index=dns query="*.360totalsecurity.com" | stats count values(query) as resolved_domains by src_ip | sort -count
index=dns query="*.360.com" | stats count values(query) as resolved_domains by src_ip | where count > 5 | sort -count
index=endpoint (process_name="360Tray.exe" OR file_name="360Tray.exe") | stats count by host, process_path, user
index=endpoint (process_name="360Safe.exe" OR file_name="360Safe.exe") | stats count by host, process_path, user
index=endpoint (process_name="360sd.exe" OR file_name="360sd.exe") | stats count by host, process_path, user
index=endpoint (process_name="QHSafeMain.exe" OR file_name="QHSafeMain.exe") | stats count by host, process_path, user
index=endpoint (process_name="QHActiveDefense.exe" OR file_name="QHActiveDefense.exe") | stats count by host, process_path, user
index=endpoint (process_name="360rp.exe" OR file_name="360rp.exe") | stats count by host, process_path, user
index=endpoint (process_name="ZhuDongFangYu.exe" OR file_name="ZhuDongFangYu.exe") | stats count by host, process_path, user
index=endpoint registry_path="HKLM\\SOFTWARE\\360Safe*" | stats count by host, registry_path, registry_value_name
index=endpoint registry_path="HKLM\\SOFTWARE\\Qihoo*" | stats count by host, registry_path, registry_value_name
YARA Rules
qihoo_360_product_artifacts β Detects Qihoo 360 security product binaries and installation artifacts on disk via file scanning. Identifies executables, DLLs, and configuration files associated with 360 Total Security, 360 Safe, and related products.
rule qihoo_360_product_artifacts {
meta:
author = "RedSheep Security/Stone"
description = "Detects Qihoo 360 security product artifacts on disk"
date = "2026-07-14"
reference = "https://www.govinfo.gov/content/pkg/FR-2026-06-10/pdf/2026-11571.pdf"
threat_level = "high"
context = "Supply chain risk - MSS-affiliated security vendor per DoD Section 1260H"
strings:
$s1 = "360Tray.exe" ascii wide
$s2 = "360Safe.exe" ascii wide
$s3 = "QHSafeMain.exe" ascii wide
$s4 = "QHActiveDefense" ascii wide
$s5 = "ZhuDongFangYu" ascii wide
$s6 = "360rp.exe" ascii wide
$s7 = "360AntiHacker" ascii wide
$s8 = "360sd.exe" ascii wide
$pdb1 = "\\360Safe\\" ascii
$pdb2 = "\\Qihoo\\" ascii
$reg1 = "SOFTWARE\\360Safe" ascii wide
$reg2 = "SOFTWARE\\Qihoo" ascii wide
$cn1 = "360.cn" ascii wide
$cn2 = "360safe.com" ascii wide
$cn3 = "qihoo.com" ascii wide
$cn4 = "360totalsecurity.com" ascii wide
$cert1 = "Qihoo 360" ascii wide
$cert2 = "360 Security" ascii wide
$cert3 = "Beijing Qihu Keji" ascii wide
condition:
uint16(0) == 0x5A4D and filesize < 100MB and (
any of ($s*) or
any of ($pdb*) or
(any of ($reg*) and any of ($cn*)) or
2 of ($cert*)
)
}
Attribution: RedSheep Security/Stone (original)
qihoo_360_mobile_package β Detects Qihoo 360 mobile security application APK packages by identifying package name strings and characteristic file structures.
rule qihoo_360_mobile_package {
meta:
author = "RedSheep Security/Stone"
description = "Detects Qihoo 360 mobile security app APK files"
date = "2026-07-14"
reference = "https://www.govinfo.gov/content/pkg/FR-2026-06-10/pdf/2026-11571.pdf"
strings:
$pkg1 = "com.qihoo.security" ascii
$pkg2 = "com.qihoo.browser" ascii
$pkg3 = "com.qihoo360.mobilesafe" ascii
$pkg4 = "com.qihoo360.antivirus" ascii
$brand1 = "360 Security" ascii wide
$brand2 = "360 Total Security" ascii wide
$brand3 = "Qihoo" ascii wide
condition:
uint32(0) == 0x04034B50 and filesize < 200MB and (
any of ($pkg*) or
2 of ($brand*)
)
}
Attribution: RedSheep Security/Stone (original)
Suricata Rules
SID 2026001 β Detects DNS queries to Qihoo 360 primary domain zone (360.cn) indicating presence of MSS-affiliated security software
alert dns $HOME_NET any -> any any (msg:"POLICY Qihoo 360 DNS Query - 360.cn (MSS-Affiliated Vendor)"; dns.query; content:".360.cn"; nocase; endswith; classtype:policy-violation; sid:2026001; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14;)
Attribution: RedSheep Security/Stone (original)
SID 2026002 β Detects DNS queries to Qihoo 360 Safe domain zone (360safe.com) indicating presence of MSS-affiliated security software
alert dns $HOME_NET any -> any any (msg:"POLICY Qihoo 360 DNS Query - 360safe.com (MSS-Affiliated Vendor)"; dns.query; content:".360safe.com"; nocase; endswith; classtype:policy-violation; sid:2026002; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14;)
Attribution: RedSheep Security/Stone (original)
SID 2026003 β Detects DNS queries to Qihoo corporate domain zone (qihoo.com) indicating presence of MSS-affiliated security software
alert dns $HOME_NET any -> any any (msg:"POLICY Qihoo 360 DNS Query - qihoo.com (MSS-Affiliated Vendor)"; dns.query; content:".qihoo.com"; nocase; endswith; classtype:policy-violation; sid:2026003; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14;)
Attribution: RedSheep Security/Stone (original)
SID 2026004 β Detects DNS queries to 360 Total Security domain (360totalsecurity.com) indicating presence of MSS-affiliated security software
alert dns $HOME_NET any -> any any (msg:"POLICY Qihoo 360 DNS Query - 360totalsecurity.com (MSS-Affiliated Vendor)"; dns.query; content:".360totalsecurity.com"; nocase; endswith; classtype:policy-violation; sid:2026004; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14;)
Attribution: RedSheep Security/Stone (original)
SID 2026005 β Detects TLS connections with Qihoo 360 server certificate patterns in SNI field
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"POLICY TLS SNI to Qihoo 360 Domain (MSS-Affiliated Vendor)"; tls.sni; content:"qihoo"; nocase; classtype:policy-violation; sid:2026005; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14;)
Attribution: RedSheep Security/Stone (original)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon EventID 1 (Process Creation) | T1195.002, T1036.005, T1005, T1082, T1543.003 | Required for all endpoint process detection queries. Ensure Sysmon is deployed with appropriate configuration that logs process creation with full command line and parent process details. |
| Windows Security EventID 4688 (Process Creation) | T1195.002, T1082 | Alternative to Sysmon for process creation logging. Must have 'Audit Process Creation' policy enabled and 'Include command line in process creation events' set. |
| Windows System EventID 7045 (Service Installation) | T1543.003 | Logs new service installations. Critical for detecting Qihoo 360 service persistence mechanisms. |
| Windows Security EventID 4663 (File Access) | T1005 | Requires SACLs configured on target directories/files. High volume β recommend targeted auditing on sensitive directories (SSH keys, credential stores). |
| Sysmon EventID 11 (File Creation) | T1195.002, T1036.005 | Detects Qihoo 360 file creation/installation artifacts. |
| Sysmon EventID 22 (DNS Query) | T1071.001 | Per-host DNS query logging. Supplements network DNS logs with process-level attribution. |
| DNS Server/Resolver Logs | T1071.001, T1102 | Central DNS logging from recursive resolvers or DNS security products (e.g., Infoblox, Cisco Umbrella). Critical for identifying Qihoo 360 installations across unmanaged/BYOD devices. |
| Proxy/Web Gateway Logs | T1071.001, T1102 | Full URL logging with bytes transferred. Required for volumetric exfiltration analysis to Qihoo domains. |
| Sysmon EventID 13 (Registry Value Set) | T1036.005 | Registry modification logging for detecting Qihoo 360 registry artifacts. |
| Software Inventory / SCCM / Endpoint Management | T1195.002 | Enterprise software inventory tools (SCCM, Intune, BigFix, Tanium) should be queried for installed applications matching '360' or 'Qihoo' patterns. |
| MDM Platform (Intune, MobileIron, AirWatch, etc.) | T1195.002 | Required for mobile device hunt. Query for package names: com.qihoo.security, com.qihoo.browser, com.qihoo360.mobilesafe, com.qihoo360.antivirus. |
| Firewall/NetFlow Logs | T1071.001, T1102 | Connection-level logging for identifying network flows to Qihoo 360 infrastructure IP ranges. |
Recommendations
- P1 IMMEDIATE: Deploy all Appendix B endpoint detection queries (Splunk/Elastic/Sigma) across all SIEM instances and validate hits within 72 hours. Any confirmed Qihoo 360 installation in a DoD/IC environment is an immediate finding requiring remediation and incident documentation.
- P1 IMMEDIATE: Run DNS/proxy log sweeps for .360.cn, .360safe.com, .qihoo.com, and .360totalsecurity.com across all network monitoring platforms to identify installations on unmanaged/BYOD devices not visible to endpoint telemetry.
- P1 IMMEDIATE: Query all MDM platforms for Qihoo 360 mobile application package names (com.qihoo.security, com.qihoo.browser, com.qihoo360.mobilesafe, com.qihoo360.antivirus) and enforce removal.
- P1 IMMEDIATE: Add Qihoo 360 domains (360.cn, 360safe.com, qihoo.com, 360totalsecurity.com) to DNS sinkhole/block lists on all DNS security platforms (Infoblox, Cisco Umbrella, Zscaler, etc.).
- P1 IMMEDIATE: Deploy Suricata rules SID 2026001-2026005 on all network IDS/IPS sensors for continuous network-level monitoring.
- P2 SHORT-TERM: Update BYOD, acceptable use, and software authorization policies to explicitly prohibit Qihoo 360 products and all 360 Security Technology software on devices that connect to enterprise networks or access enterprise data.
- P2 SHORT-TERM: Add Qihoo 360 / 360 Security Technology, Inc. to application whitelisting deny lists (AppLocker, WDAC, CarbonBlack, CrowdStrike prevention policies) to prevent future installation.
- P2 SHORT-TERM: Conduct retrospective analysis of any identified Qihoo 360 installations to assess what data the affected endpoints had access to, including file shares, credentials, email, and network segments.
- P3 ONGOING: Add Qihoo 360 / 360 Security Technology, Inc. and all known subsidiaries to third-party risk assessment questionnaires, supply chain vendor screening criteria, and SCRM documentation.
- P3 ONGOING: Monitor for regulatory developments β a commercial sales ban under EO 13873 / ICTS regulations (following the Kaspersky precedent) is assessed as likely. Proactive remediation now avoids time-pressured removal under a future ban.
- P3 ONGOING: Deploy YARA rules to endpoint scanning platforms (e.g., YARA scans via EDR) for periodic file system sweeps to detect Qihoo 360 artifacts that may not generate active process or network indicators.
Sources
- Federal Register Vol. 91, No. 111 - DoD Section 1260H Chinese Military Companies Notice (June 10, 2026)
- Qihoo 360: The Cyber Giant Behind China's Mythos Rival - Forbes (June 30, 2026)
- Dakota Cary - Atlantic Council Global China Hub
- Sleight of hand: How China weaponizes software vulnerabilities - Atlantic Council (March 2025)
- National Intelligence Law of the People's Republic of China (2017); Regulations on the Management of Network Product Security Vulnerabilities (2021)
- China's Zero-Day Pipeline: From Discovery to Deployment - Recorded Future