The US government said Wednesday it has disrupted a hacking platform and botnet operated by a Chinese state-sponsored group known as QTFY, which allegedly ran attacks against military systems, critical infrastructure, and government networks in the United States for years.
According to the Justice Department, QTFY has been operating out of a company called Nanjing Xinjiuwei Network Technology since its establishment in 2018. The group offered hacking services to the Chinese government and other clients, using them to target a wide range of US sectors.
Two Tools, One Takedown
Authorities focused the disruption on two linked services: QScan, a scanning and exploitation platform used to find vulnerable IoT devices, and QTRouter, an obfuscation botnet that absorbed those compromised devices to help attackers hide their activity and evade detection.
US authorities identified and seized the domains hard-coded into both QScan and QTRouter, which the malware relied on for communication and authentication. The Justice Department said the court-authorized seizures rendered both tools inoperable.
Wide-Ranging Targeting
A technical advisory issued by the FBI the same day detailed QTFY’s activity, describing a group that developed malicious tools, traded malware and exploits, and maintained botnets in support of its operations. Targeted sectors included the defense industrial base, local government, telecommunications, and higher education.
The FBI said several high-value intrusion attempts failed, including efforts against the Department of Energy, election systems, the Department of Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company.
Other operations appear to have succeeded, at least partially, against targets including NASA, the Justice Department, the Federal Reserve, the Department of Energy, state governments, a major retailer, a telecom company, defense contractors, universities, and financial institutions.
Exploitation and Broader Connections
The FBI said QTFY hackers exploited vulnerabilities in products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure.
The bureau noted that QTFY actors are active in exploit development circles, freelance PRC hacker networks, and PRC contracting and subcontracting marketplaces for offensive cyber work, and that the group has also taken part in offensive exercises against Chinese critical infrastructure.
Investigators further found that the company behind QTFY has maintained business relationships with entities connected to the Salt Typhoon espionage group, the i-Soon intrusion firm, and other known threat actors, underscoring the interconnected nature of China’s state-linked hacking ecosystem.
- Group: QTFY, linked to Nanjing Xinjiuwei Network Technology
- Tools disrupted: QScan (scanning/exploitation), QTRouter (obfuscation botnet)
- Action taken: Seizure of hard-coded domains used for command and authentication
- Exploited vendors: BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, Pulse Secure
