Press play to start listening
The US Department of Justice and FBI on August 26 announced court-authorized seizures of domains used by QTFY, a China-linked hacking group accused of targeting US critical infrastructure and sensitive networks since at least 2018. The FBI said QTFY operated within a wider network of hackers-for-hire and government clients in China.
“Our investigation links the group to Nanjing Xinjiuwei Network Technology, a company that sells stolen data and hacking services to Chinese military and intelligence agencies,” FBI Cyber Division Assistant Director Brett Leatherman said.
According to the US Department of Justice, QTFY’s customers included China’s Ministry of State Security and People’s Liberation Army. QTFY operated QScan, a vulnerability-scanning and exploitation platform, and QTRouter, an obfuscation network. Separate botnet systems controlled compromised IoT devices and added them as QTRouter proxy nodes.
How QScan and QTRouter Worked
QScan was a distributed reconnaissance and exploitation platform that searched internet-connected systems for weaknesses. It could also automatically compromise vulnerable IoT devices, including routers and security cameras.
Federal reporting links QTFY activity to the exploitation of several widely used enterprise products, including Pulse Secure VPN flaw CVE-2019-11510, Fortinet FortiOS flaw CVE-2018-13379, and Citrix ADC vulnerability CVE-2019-19781. QScan contained more than 200 proof-of-concept exploits and processed over two million scanning and penetration-testing tasks in one day in 2024.
Compromised devices were then added to QTRouter, an obfuscation network that also used commercial proxy services and leased virtual private servers. Attack traffic could therefore appear to originate from devices outside China, including systems located near a victim’s network.
QTFY also used remote access trojans (RATs), web shells, and credentials obtained from compromised systems to retain access. The domains seized by US authorities were hard-coded into QScan and QTRouter for essential communication and authentication functions. Seizing those domains therefore rendered both platforms inoperable.
Government Targets and Recent Activity
The Justice Department identified NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the US Senate as victims of QTFY computer intrusion activity.
Federal reporting (PDF) also documented targeting of hospitals, telecommunications providers, power companies, financial institutions and defence contractors, although not every attempt resulted in access. A 2019 attempt to breach NASA through a Pulse Secure VPN flaw failed because NASA had already patched the vulnerability.
In May 2024, QTFY used QScan and an exploit for Check Point vulnerability CVE-2024-24919 while targeting US power and telecommunications companies. The federal advisory says the actors exfiltrated data from more than 300 organisations in the United States and other countries, including defence contractors, financial institutions and universities.
In September 2024, QTFY actors used Ivanti Cloud Services Appliance zero-days against three Department of Energy laboratories, the National Institutes of Health, the Health Resources and Services Administration and a security-device manufacturer.
In March 2026, the group scanned a US Senate network and a hospital system, while a June scan targeted an unidentified US election system. Those attempts failed.
In its own analysis, Lumen Technologies’ Black Lotus Labs, which tracked the infrastructure for the past year and shared threat intelligence with US government agencies, described the operation as an “infrastructure quartermaster” integrating reconnaissance, proxy orchestration and routing to help downstream threat actors hide their activity.
John Riggi, the American Hospital Association’s national adviser for cybersecurity and risk, said compromised routers and security cameras can help attackers conceal their movements and gain access to targeted networks.
The disruption follows earlier FBI operations against China-linked infrastructure, including actions involving PlugX malware in 2025, a Flax Typhoon IoT botnet in 2024, and the Volt Typhoon botnet used to conceal attacks in 2023.
Expert Analysis
Josh Picolet, VP of Detection & Analysis at Team Cymru, shared the following comments with Hackread.com about the QTFY operation:
“QTFY is a useful case study in how state-linked contracting networks actually operate. QScan scanned the internet for vulnerable IoT/SOHO devices and enrolled them into QTRouter, the layer that hid the actual operations behind a mesh of compromised hardware. That is the operating model of an ORB network, an operational relay box mesh assembled from hijacked edge devices.”
Picolet also explained why targeting the infrastructure behind QTFY’s operations was significant, noting that the seized domains were essential to the malware’s communication and authentication:
“The domains were hard-coded into the malware for communication and authentication, so seizing that infrastructure made the tooling inoperable across every operation depending on it, not just one intrusion. Detection built around a single campaign’s indicators would never have surfaced a platform built to be shared across operators.”
(Photo by David Pupăză on Unsplash)