QTFY and the Nanjing Xinjiuwei front company
Federal filings and an unsealed affidavit name a state-sponsored Chinese hacking collective operating under the label “QTFY.” The FBI and Justice Department say QTFY ran out of a private, government-funded front company, Nanjing Xinjiuwei Network Technology Company, and that the group has been active for more than eight years and under investigation since at least 2019. Court records further allege the group includes former members of China’s military and has provided a range of offensive services to intrude sensitive networks.
QScan, QTRouter and the three seized domains
Officials seized three domains Wednesday that, they said, cut off access to QTFY’s primary platforms: QScan, a reconnaissance and vulnerability-scanning tool, and QTRouter, a platform used to control infected devices and reroute traffic. The affidavit describes QScan as containing more than 200 proof-of-concept exploits and designed “for large-scale deployment.” An FBI special agent told the court that, on a single day in 2024, QScan processed over two million scanning and exploit tasks. Ryan English of Lumen Technologies’ Black Lotus Labs characterized QTFY’s operation as “comprehensive with features that provided continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTargets: federal agencies, critical infrastructure, and election systems
According to the Justice Department and FBI, QTFY targeted and in many cases intruded networks belonging to multiple U.S. federal entities, including the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health. Officials say the group unsuccessfully attempted to intrude the Senate in March and made an unsuccessful attempt to gain access to a U.S. election system in June. Beyond government targets, court records list attacks against financial institutions, defense contractors, utility companies, telecom providers and hospitals.
Exploited products and the September 2024 Ivanti zero-day intrusions
Officials tied QTFY intrusions to exploitation of vulnerabilities across a broad set of vendor products, naming Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP and BeyondTrust. Court documents highlight that QTFY exploited multiple Ivanti zero-day vulnerabilities in September 2024 to intrude three Department of Energy national laboratories, the National Institutes of Health, an HHS agency and a U.S.-based security device manufacturer — and that the seized domains were used in those attacks.
Law enforcement disruption, advisories, and prior operations
The FBI and Justice Department led the disruption, with assistance from the National Security Agency and the Cyber National Mission Force; those agencies released a joint cybersecurity advisory Wednesday that includes QTFY’s known indicators of compromise. Lumen Technologies’ Black Lotus Labs aided the disruption work, according to officials. The takedown follows earlier technical operations described by officials; the announcement cites an operation in early 2025 that allowed authorities to remove PlugX malware from thousands of U.S.-based computers. Attorney General Todd Blanche framed the action as part of a prosecutorial posture: “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” he said. “We are here to ensure security for the American people and will use every tool we have to keep that promise.”
What this means for technologists, policymakers, and affected agencies
- Technologists and security teams: defenders have an actionable set of indicators of compromise from the joint FBI–NSA–Cyber National Mission Force advisory and a known list of exploited vendors; the QScan and QTRouter seizures remove two key platforms officials say supported large-scale scanning and exploitation.
- Policymakers and regulators: the disruption underscores a prosecution-focused response by the Justice Department and highlights recurring use of private companies funded by foreign governments to run offensive cyber platforms.
- Affected federal agencies and critical infrastructure operators: multiple named agencies and private-sector targets were identified in the court record; agencies cited in filings — including DOE national laboratories, NIH and an HHS agency — were reported victims of intrusions tied to Ivanti zero-day exploitation in September 2024.
The disruption removed live access to QTFY’s two principal platforms and seized domains used in recent intrusions, but court records describe an infrastructure capable of continuous reconnaissance and rapid redeployment: more than 200 exploits in QScan and a single-day processing peak of over two million tasks in 2024. Officials also detailed affiliations and collaborations between QTFY and other state-sponsored groups, leaving open whether the collective’s capabilities can be permanently dismantled or quickly rebuilt. For now, federal authorities have interrupted a long-running espionage operation that traversed the public and private sectors, and they have published indicators designed to help defenders close the same gaps QTFY exploited.




