Skip to main content
Threat IntelligenceEmerging Threats

FBI Warns of Chinese Hacker Group QTFY's Infrastructure Attacks

Network operations center with rows of equipment and a single engineer.

The FBI revealed that QTFY’s QScan platform performed “over two million scanning and penetration testing tasks in a single day in 2024,” a scale that federal agencies say helped a sophisticated Chinese-linked group identify and exploit targets across U.S. government and critical infrastructure networks.

QScan and QTRouter: QTFY’s custom-built ecosystem

The FBI’s advisory describes an integrated toolset developed and used by a group known as QTFY (also QT and QTCYBER) and attributed to Nanjing Xinjiuwei Network Technology Co. At the center of the group’s operations are three families of capabilities: QScan, QTRouter and multiple botnet-management platforms.

QScan is a rapid reconnaissance and exploitation platform that conducts webpage scraping, TLS certificate collection, subdomain enumeration and automated penetration testing, and maintains a large database of exposed systems to match against new vulnerabilities. QTRouter is described as “a network traffic obfuscation network” deployed on devices including routers running custom OpenWrt software. Botnet products give QTFY control over compromised IoT devices and allow those devices to serve as QTRouter proxy nodes. “These products work in conjunction with each other,” the FBI noted.

Targets: defense industrial base, communications, government, higher education — and named agencies

The advisory says QTFY has focused on critical infrastructure sectors “including defense industrial base (DIB), communications, government and higher education” since its establishment in 2018. In 2024 the group successfully exfiltrated data from more than 300 organizations worldwide after leveraging an exploit for a Check Point Quantum Gateway vulnerability; victims included U.S. defense contractors, financial institutions and universities.

Other entities the advisory lists as targets or attempted targets include the U.S. Department of Justice, the U.S. Federal Reserve and NASA, and the FBI said attempts were made to compromise hospitals and election systems in the country.

Tactics: zero-day/N-day exploits, large-scale scanning, persistence and obfuscation

The advisory attributes QTFY’s operational success to a workflow that combines rapid vulnerability discovery, pre-populated target catalogs and layered persistence techniques. The group “focus[es] on exploiting zero-day and N-day vulnerabilities to gain initial access,” the FBI said, and its QScan platform gives it a head start when a new vulnerability appears because it “may already have a catalogue of exposed systems ready to match against the latest exploit.”

Once inside networks, QTFY uses remote access trojans (RATs), web shells and stolen credentials to maintain persistence. The QTRouter obfuscation network then enables access to victim networks from nearby compromised IoT devices, “blending in with legitimate users.” The FBI also identified unique user agent strings from IP addresses in China that indicated QTRouter usage by both QTFY personnel and PRC government personnel. The group also participates in freelance PRC hacker networks and cyber contracting marketplaces, and the advisory says QTFY integrates AI into aspects of its processes.

U.S. law enforcement disruption: DOJ and FBI operations on August 26

In a separate announcement on August 26, the U.S. Department of Justice and the FBI said they had disrupted the QScan and QTRouter platforms, “denying malicious cyber actors access to the tools.” Court documents cited in that announcement state QTFY offers QScan and QTRouter as services to paying customers. The Justice Department characterized the operation as the latest in a series of court-authorized technical actions against indiscriminate hacking activities by the PRC.

Mitigation steps the authoring agencies recommend

The FBI, in coordination with the National Security Agency and Cyber National Mission Force, recommended a set of concrete defensive measures for government and critical infrastructure organizations: apply the latest software and firmware updates; regularly audit webpages and applications for published secrets such as API keys and tokens; proactively threat hunt for the indicators of compromise included in the advisory; isolate critical systems from edge devices; and test security programs against the threat behaviors mapped to the MITRE ATT&CK for Enterprise framework that the advisory details.

What this means for defense contractors, universities, and hospitals

  • Defense contractors: The advisory underscores the sensitivity of DIB networks — as Nick Tausek, lead security automation architect at Swimlane, put it, “Military and defense-linked networks are about as sensitive as targets get,” meaning even limited access can expose operational plans and technical capabilities.
  • Universities and research institutions: Because QTFY has successfully exfiltrated data from universities, these organizations should prioritize patching, credential hygiene and auditing publicly exposed assets that could be rapidly catalogued by tools like QScan.
  • Hospitals and election officials: Both were targeted or attempted targets; the advisory’s call to isolate critical systems from edge devices and to proactively threat-hunt follows directly from QTFY’s use of compromised IoT devices and QTRouter to blend malicious access with legitimate traffic.

Gabrielle Hempel, security operations strategist at Exabeam, summarized the operational challenge: “They have built an ecosystem designed to make malicious activity look geographically and operationally ordinary.” The disruption by the FBI and DOJ denied QTFY access to two of its key platforms, but the advisory and court documents together make clear the group had developed an industrialized service model — selling QScan and QTRouter capabilities to customers — and maintained large-scale tooling and botnet infrastructure. Organizations named in the advisory now have specific mitigations to apply; whether those steps will close the windows QTFY has exploited will be judged in the weeks and months ahead.

https://www.infosecurity-magazine.com/news/chinese-qtfy-us-infrastructure-fbi/