A Military-Designated Vendor Whose Drivers Are Already Being Turned Against Defenders
Qihoo 360 (360 Security Technology, Inc.) presents a convergence of three distinct risk vectors for enterprise defenders. The U.S. Department of Defense (now Department of War) designates it as a Chinese military company with ties to the Ministry of State Security [1][2]. Its consumer antivirus product ships a WHQL-signed kernel driver capable of killing any process on a Windows system, including Protected Process Light (PPL) EDR agents [3]. And a separate Qihoo 360 driver, 360netmon_wfp.sys, is already being abused in the wild by the Gentlemen ransomware gang's GentleKiller framework to disable over 400 security processes across 48 products [4][5].
This is not a theoretical supply chain risk. It is an active one, playing out across three distinct vectors: state affiliation, weaponizable driver design, and real-world exploitation by criminal actors.
Background: Qihoo 360 and the MSS Connection
Qihoo 360, founded in 2005 [8], grew into one of China's largest cybersecurity firms through a model built on free consumer tools (antivirus, browser, mobile security, VPN) subsidized by advertising and data collection. The company also operates an enterprise security division and one of China's most prolific vulnerability research programs [6].
The U.S. government's concerns about Qihoo 360 have escalated steadily. In May 2020, the Commerce Department's Bureau of Industry and Security (BIS) placed 360 on the Entity List, barring American companies and individuals from doing business with it without a license, citing activities contrary to U.S. national security and foreign policy interests [6][8]. The DoD subsequently added Qihoo 360 to the Section 1260H list of Chinese military companies on a prior version of the list [8]. The June 2026 update reaffirms and expands the designation.
The most concerning institutional relationship is with the Ministry of State Security (MSS). The 2026 1260H filing indicates that Qihoo 360 is affiliated with the Ministry of Industry and Information Technology (MIIT) and the Ministry of State Security [1]. The MSS runs China's foreign intelligence operations and also operates the China National Vulnerability Database (CNNVD). Qihoo 360's significant vulnerability research apparatus feeds into this ecosystem. China's 2017 National Intelligence Law (Article 7) compels Chinese organizations and citizens to "support, assist, and cooperate" with national intelligence work, with no court order requirement and no transparency reporting.
The 2026 Designation: Harder Edges
The Department of Defense/War (the Department) released its updated 1260H list on June 8, 2026, with the Federal Register notice published on June 10 [1]. The list now covers 188 entities total, and the Department has indicated it reserves the right to take additional actions on these entities under authorities other than Section 1260H [2].
Qihoo 360 is classified as a military-civil fusion contributor to the Chinese defense industrial base, based on its affiliations with MIIT and MSS [1]. "Military-civil fusion" is China's strategic program for eliminating barriers between civilian technology companies and defense/intelligence applications. The U.S. government's assessment is that Qihoo 360 is an active participant in this pipeline, not a passive bystander.
Under Section 805 of the FY2024 NDAA, the Department of Defense/War faces contracting prohibitions regarding 1260H-listed entities, creating hard contracting restrictions rather than merely advisory guidance [1].
DsArk64.sys: A Signed Kernel Weapon Shipping With Free Antivirus
The LOLDrivers project documented a critical finding about Qihoo 360's anti-rootkit driver, DsArk64.sys (and its 32-bit variant DsArk.sys) [3]. This driver ships with 360 Total Security, is freely downloadable from 360.cn, and installs as a boot-start driver at \SystemRoot\System32\drivers\DsArk64.sys [3].
The driver's capabilities are extreme even by antivirus kernel-driver standards:
- Arbitrary kernel read/write: The driver exposes IOCTL handlers allowing arbitrary kernel memory read and write operations. The kernel write primitive broadcasts across all CPUs via DPC, making it atomic and usable for cross-CPU kernel patching [3].
- Process termination: It can kill any process, including PPL-protected EDR and AV processes, with a single 4-byte IOCTL [3].
- Bypassable signing check: The driver implements a custom Authenticode check that validates the on-disk PE file of the calling process. This is bypassable via process hollowing into any Qihoo-signed executable, as demonstrated in public PoC code [3].
- Static encryption: The encryption on read/write IOCTLs uses a static key embedded in the driver, making it completely reversible [3].
- Weak validation: MmIsAddressValid is the sole address validation mechanism, with no range checks or page protection checks on kernel read/write targets [3].
The driver is WHQL-signed by Microsoft (Microsoft Windows Hardware Compatibility Publisher), giving it the highest tier of trust on Windows systems [3]. It is not on the HVCI blocklist [3].
Both x86 (DsArk.sys) and x64 (DsArk64.sys) variants exist [3].
GentleKiller: Qihoo Drivers Weaponized by Ransomware Operators
ESET published research on June 17, 2026, detailing the Gentlemen ransomware-as-a-service (RaaS) gang's EDR-killing framework, dubbed GentleKiller [4][5]. Gentlemen emerged in late 2025 and became one of the most active ransomware gangs in Q1 2026 [5]. The group's victimology is distinct: rather than the typical US-centric targeting of most top-tier gangs, Gentlemen reportedly focuses on victims across Southeast Asia, South America, and Western Europe [5].
GentleKiller is an in-house framework with at least eight distinct variants, each impersonating a different legitimate security product and abusing a unique vulnerable or malicious kernel-level driver via the Bring Your Own Vulnerable Driver (BYOVD) technique [4]. One of those eight drivers is Qihoo 360's 360netmon_wfp.sys [4].
The other seven abused drivers come from Kaspersky (eb.sys), FACEIT Anti-Cheat (nseckrnl.sys), Valorant (GameDriverX64.sys), Javelin/Safetica (stpm_old.sys/stpm_new.sys), Zemana WatchDog (dmx.sys), IObit (IMFForceDelete), and the PoisonX rootkit [4].
GentleKiller targets more than 400 processes mapped to 48 security products, including Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks, ESET, Bitdefender, Kaspersky, and McAfee/Trellix [4]. The framework operates on a loop, scanning and terminating targeted processes every two seconds [4]. According to ESET, the gang can rapidly operationalize newly published BYOVD proof-of-concept exploits [4][5].
Beyond GentleKiller, Gentlemen's affiliate toolkit integrates three externally sourced EDR killers: HexKiller, ThrottleBlood, and HavocKiller [5]. These tools are standardized through a shared defense-evasion layer that impersonates security vendors using fake version information and copied legitimate certificates and icons [5].
Beyond Drivers: Backdoors, Whitelisting Failures, and AI Ambitions
The driver problem is not the only trust concern with Qihoo 360's product ecosystem.
Researchers at Norwegian security firm Mnemonic discovered that children's smartwatches manufactured by Qihoo 360 and sold in European and US markets (rebranded by Norwegian firm Xplora, with over 350,000 units sold globally) contained covert surveillance capabilities [10]. The backdoor included functions named "remote snapshot," "send location," and "wiretap," activated by sending SMS commands to the watch [10]. The device communicated directly with Qihoo 360's domain, 360.cn, and 19 of the apps on the device were authored by Qihoo 360 [10]. Qihoo 360 sells a nearly identical watch in China branded as the "360 Kids Guard" [10].
Check Point's mobile threat research documented a separate incident where cybercriminals bribed employees of a Chinese gaming company to include malware among legitimate apps submitted to Qihoo 360 for whitelisting, letting the malware bypass Qihoo's antivirus detection [9]. Attackers then distributed the whitelisted malware through the Taobao.com marketplace by disguising Trojans as product photos sent via the Aliwanwang messaging app [9].
On the AI front, Qihoo 360 CEO Zhou Hongyi revealed an AI vulnerability-finding tool called Tulongfeng at the 14th Beijing Cybersecurity Conference, an event Qihoo 360 itself organizes [7]. Zhou reportedly described Anthropic's Mythos model as a "cyber nuclear weapon" due to US restrictions on foreign nationals' access, arguing it gives the US an asymmetric vulnerability-discovery advantage [7]. According to reporting, the tool has found thousands of software vulnerabilities, with over 100 confirmed by Chinese authorities [7][8].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| Filename | DsArk64.sys |
WHQL-signed Qihoo 360 kernel driver: arbitrary kernel R/W, process kill including PPL bypass | [3] |
| Filename | DsArk.sys |
32-bit variant of Qihoo 360 anti-rootkit driver | [3] |
| Filename | 360netmon_wfp.sys |
Qihoo 360 driver abused by GentleKiller BYOVD framework | [4] |
| Malware | GentleKiller | In-house EDR-killer framework operated by Gentlemen RaaS, 8 variants | [4][5] |
| Malware | Gentlemen | RaaS gang active since late 2025, targeting SE Asia, S. America, W. Europe | [4][5] |
| Malware | HexKiller | External EDR killer integrated into Gentlemen's affiliate suite | [5] |
| Malware | ThrottleBlood | External EDR killer integrated into Gentlemen's affiliate suite | [5] |
| Malware | HavocKiller | External EDR killer integrated into Gentlemen's affiliate suite | [5] |
| Domain | 360.cn |
Qihoo 360 primary domain. Traffic to this domain on enterprise endpoints indicates Qihoo 360 product installation, warranting investigation given 1260H designation. Also documented as receiving covert telemetry from children's smartwatches [10]. This is a policy-based indicator, not a traditional malicious IOC. | [10] |
MITRE ATT&CK Mapping
| Technique ID | Name | Relevance |
|---|---|---|
| T1543.003 | Create or Modify System Process: Windows Service | DsArk64.sys installs as a boot-start kernel driver/service [3] |
| T1036 | Masquerading | GentleKiller variants impersonate legitimate security products using fake version info, copied certificates, and icons [5] |
| T1036.005 | Match Legitimate Name or Location | GentleKiller uses copied legitimate certificates, icons, and version information for visual impersonation of security products [5] |
| T1068 | Exploitation for Privilege Escalation | GentleKiller uses BYOVD technique to load legitimately signed drivers for EDR termination [4][5] |
Detection and Hunting
Driver presence: Hunt for DsArk64.sys, DsArk.sys, and 360netmon_wfp.sys across your fleet. These should not be present on enterprise-managed endpoints unless Qihoo 360 products are explicitly sanctioned (which, given the 1260H designation, they should not be in any environment handling sensitive data).
index=sysmon EventCode=6 ImageLoaded IN ("*\\DsArk64.sys", "*\\DsArk.sys", "*\\360netmon_wfp.sys")
BYOVD behavioral indicators: GentleKiller operates on a 2-second loop killing targeted processes [4]. Look for rapid, repeated process termination events affecting security tools, correlated with recent driver load events from non-standard kernel modules.
index=sysmon EventCode=6 NOT ImageLoaded IN ("*\\drivers\\*Microsoft*", "*\\drivers\\*Windows*")
| join host
[search index=sysmon EventCode=5
| bin _time span=10s
| stats count by _time host TerminatedImage
| where count > 3]
Boot-start driver auditing: DsArk64.sys installs as a boot-start driver [3]. Audit the HKLM\SYSTEM\CurrentControlSet\Services registry hive for unexpected entries with Start value of 0 (boot) that point to unsigned or WHQL-signed drivers from non-standard vendors.
Sigma Rule: Qihoo 360 BYOVD Driver Load
title: Qihoo 360 Vulnerable Driver Load
id: a3f5c2d1-8b7e-4f12-9c3a-1d5e7f8a2b4c
status: experimental
description: Detects loading of Qihoo 360 kernel drivers known to be abusable for BYOVD attacks
author: RedSheepSec
date: 2026/09/04
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\DsArk64.sys'
- '\DsArk.sys'
- '\360netmon_wfp.sys'
condition: selection
falsepositives:
- Legitimate Qihoo 360 Total Security installations (should not be present on enterprise networks)
level: high
tags:
- attack.privilege_escalation
- attack.t1543.003
- attack.t1068
Network indicators: Any enterprise endpoint communicating with 360.cn warrants investigation. This domain is Qihoo 360's primary backend and was documented as receiving telemetry from children's smartwatches [10].
Analysis
The convergence of these three vectors creates a compounding risk that is worse than any single one in isolation.
First, the state affiliation vector. The 1260H designation is the U.S. government's formal assessment that Qihoo 360 actively participates in China's military-civil fusion program, with specific ties to the MSS [1]. This is not an advisory or a recommendation. It is a finding backed by statutory authority that now carries hard contracting prohibitions.
Second, the driver quality vector. DsArk64.sys is a textbook case of a kernel driver that should never have passed WHQL certification with these capabilities exposed. Arbitrary kernel read/write with a static encryption key, process termination including PPL-protected processes, and a signing check bypassable through process hollowing: these are not subtle weaknesses [3]. They are fundamental design choices that create a freely available, Microsoft-signed kernel attack primitive.
Third, the active exploitation vector. Gentlemen's GentleKiller framework demonstrates that threat actors are already treating Qihoo drivers as part of their BYOVD toolkit [4][5]. The gang's ability to rapidly operationalize new BYOVD PoCs suggests a mature development pipeline [4][5].
Qihoo 360's consumer products continue to ship. The April 2026 release of version 11.0.0.1314 confirms active development [11]. No current major independent AV lab results (AV-TEST, AV-Comparatives) exist for the product [11]. The product is free, which means the install base likely skews toward users and organizations that are cost-sensitive and potentially less security-mature.
Red Sheep Assessment
Confidence: High (based on primary source documentation, independent technical research, and ESET incident-level analysis)
The sources collectively point to a conclusion none of them state individually: Qihoo 360's kernel drivers almost certainly represent a persistent, pre-positioned BYOVD supply for any attacker (state-sponsored or criminal) for the foreseeable future. The WHQL signing, the free distribution model, the boot-start installation, and the static cryptographic material mean these drivers will remain available on millions of systems long after any given organization decides to remove the product. The drivers are already signed, already trusted by Windows, and already cached in driver stores.
The GentleKiller case also reveals something important about the economics of BYOVD. Gentlemen's framework uses drivers from eight different vendors, meaning Qihoo 360 is not uniquely negligent in shipping exploitable kernel code. But Qihoo 360 is unique in being the only vendor on that list simultaneously designated as a Chinese military company affiliated with the MSS. The combination of exploitable kernel drivers from a state-affiliated vendor creates an ambiguity that defenders cannot afford: is a given incident criminal BYOVD abuse, or is it something else?
The Tulongfeng AI vulnerability-finding tool announcement [7][8] adds another dimension. Zhou Hongyi's framing of Anthropic's Mythos model as a "cyber nuclear weapon" and positioning Tulongfeng as a deterrent [7] signals that Qihoo 360 views automated vulnerability discovery as a strategic capability, not just a product feature. We assess that a company with MSS ties, a massive installed base providing telemetry, and an AI-powered vulnerability discovery pipeline is a qualitatively different kind of actor than a typical AV vendor.
An alternative interpretation: Qihoo 360's consumer products are simply legacy bloatware with poor driver engineering, and the MSS affiliation is a bureaucratic reality of operating as a large Chinese tech company rather than evidence of active intelligence cooperation. This interpretation is possible but increasingly difficult to sustain given the pattern: MSS affiliation, covert smartwatch surveillance capabilities [10], whitelisting failures exploited for financial crime [9], and kernel drivers designed with bypassable security controls [3].
Defender's Checklist
- ▢[ ] Sweep for Qihoo 360 products and drivers: Run an enterprise-wide query for
DsArk64.sys,DsArk.sys,360netmon_wfp.sys, and any installed instance of 360 Total Security, 360 Security (mobile), or 360 browser products. Useindex=sysmon EventCode=6 ImageLoaded="\\DsArk"or equivalent EDR queries.
- ▢[ ] Block Qihoo 360 drivers via WDAC/HVCI policy: Create a Windows Defender Application Control policy explicitly denying these driver hashes. Note that DsArk64.sys is not currently on the HVCI blocklist [3], so this requires manual policy creation. Use hash-based rules rather than filename-based rules for stronger enforcement.
- ▢[ ] Hunt for BYOVD process termination patterns: Query for rapid, repeated security process termination events (more than 3 in 10 seconds) that could indicate GentleKiller's 2-second scan-and-kill loop [4]. Correlate with driver load events from non-standard kernel modules.
- ▢[ ] Block network traffic to 360.cn: Add
360.cnand its subdomains to DNS sinkholes and proxy block lists. Any enterprise endpoint reaching this domain warrants immediate investigation [10].
- ▢[ ] Review BYOD and shadow IT policies: Qihoo 360's free products are most likely to appear on personal devices connecting to enterprise networks. Ensure NAC or endpoint compliance checks flag these products before granting network access.
References
- DoD Section 1260H List, June 2026
- Federal Register: Notice of Availability of Designation of Chinese Military Companies
- LOLDrivers: DsArk64.sys / DsArk.sys Qihoo 360 Kernel Driver
- CybersecurityNews: GentleKiller Ransomware Abuses Vulnerable Drivers
- ESET: Killing Me Gently: Inside Gentlemen's EDR Killer Framework
- Forbes: Qihoo 360: The Cyber Giant Behind China's Mythos Rival
- The Register: Chinese Cybersecurity Company Claims Better-Than-Mythos Bug Finder
- Wikipedia: Qihoo 360
- Check Point: Qihoo 360: Just the Tip of the Whitelisted Malware Iceberg
- Mnemonic: Exposing Backdoor Consumer Products
- Antivirus-Review: 360 Total Security Review 2026