The US National Security Agency, Federal Bureau of Investigation and Cyber National Mission Force have issued a joint warning about a China-linked hacking group accused of building an industrial-scale cyberattack infrastructure capable of scanning, exploiting and concealing intrusions against government agencies, defence contractors and critical infrastructure operators.
The group, tracked as QTFY and also known by the abbreviations QT and QTCYBER, allegedly developed an interconnected collection of hacking platforms, botnets and proxy services that allowed operators to discover vulnerable systems, compromise internet-connected devices and route malicious traffic through systems located close to intended victims.
Thejoint cybersecurity advisorywas released alongside a court-authorised US operation that seized domains supporting two of the group’s most important platforms, QScan and QTRouter. Because those domains were embedded in the malware and required for core communication and authentication functions, the Justice Department said the seizures rendered both platforms inoperable.
However, the disruption does not mean every compromised device has been cleaned or that the wider threat has disappeared. The advisory identifies additional botnet-management systems, historical infrastructure and compromised devices that may continue to present risks. Security teams are therefore being urged to hunt for evidence of earlier QTFY activity rather than treating the domain seizures as a complete resolution.
QTFY linked to Chinese hacking contractor
US authorities attribute QTFY’s infrastructure to Nanjing Xinjiuwei Network Technology Company, a China-based business that allegedly provides stolen information and offensive cyber services to customers that include China’s Ministry of State Security and People’s Liberation Army.
According to theUS Department of Justice, the company created and operated QScan and QTRouter as complementary platforms. QScan supplied large-scale reconnaissance and exploitation, while QTRouter helped customers conceal the
The case highlights what US agencies and independent researchers describe as an increasingly commercialised model for Chinese state-linked cyber operations. Instead of every espionage unit building its own scanning systems, botnets and proxy infrastructure, specialist contractors can develop and maintain those capabilities as shared services.
This creates a division of labour similar to legitimate technology markets. One organisation discovers vulnerable systems, another manages compromised devices, an infrastructure provider supplies anonymised access and the final operator conducts the intelligence operation.
That structure can complicate attribution because the organisation maintaining the infrastructure may not be the same group that selects a target, steals information or controls the final operation.
It may also give Chinese government customers access to a broader and more disposable collection of infrastructure than they could efficiently build on their own.
Lumen Technologies’ Black Lotus Labs, which supported the investigation, describes the operator as an infrastructure “quartermaster” serving other China-nexus actors. Its researchers said the model replaces fragmented, campaign-specific infrastructure with shared, multi-tenant networks that can support operations at speed and on a global scale.Lumensaid it null-routed traffic associated with known infrastructure points and provided threat intelligence to US agencies.
US agencies and critical sectors affected
The Justice Department identified NASA, the Federal Reserve, the Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and US Senate among the victims of QTFY intrusion activity.
Targets identified in the advisory also span the defence industrial base, telecommunications, energy, healthcare, financial services, universities, semiconductor companies, biotechnology organisations, state and local governments, retailers, election infrastructure and water utilities.
The distinction between targeting and confirmed compromise is important. The advisory records successful intrusions and data theft in some cases, while other entries describe unsuccessful scanning or attempted access. Inclusion on the target list does not necessarily mean an organisation was breached.
The group’s documented activity stretches back to at least 2018 and demonstrates a persistent effort to gain access to strategically important systems.
In August 2020, an address associated with the operation received an abuse complaint over an attack against a healthcare organisation’s Pulse Secure SSL VPN during the COVID-19 pandemic. In 2021, the group allegedly installed remote-access trojans on systems in Taiwan’s energy sector and used several widely exploited vulnerabilities, including ProxyLogon in Microsoft Exchange,CVE-2020-5902in F5 BIG-IP and Log4Shell.
Later operations targeted Atlassian Confluence, Ivanti appliances, Check Point gateways, CrushFTP and BeyondTrust Remote Support systems.
The advisory states that a May 2024 operation used QScan to scan US power and telecommunications companies while exploitingCVE-2024-24919, a Check Point Quantum Gateway information-disclosure vulnerability. Authorities say data was exfiltrated from more than 300 organisations in the United States and other countries, including defence contractors, universities and financial institutions.
In September 2024, the actors allegedly used zero-day vulnerabilities affecting Ivanti Cloud Services Appliance products against three Department of Energy laboratories, the National Institutes of Health, the Health Resources and Services Administration and a US security-device manufacturer.
The group remained active into 2026. The advisory links QScan to attempted exploitation ofCVE-2026-1731in BeyondTrust Remote Support against a US state government in February. A water district was also targeted during that period.
QTFY subsequently scanned the US Senate and a hospital system in March 2026 and examined a US election system in June, although the advisory characterises those particular attempts as unsuccessful.
QScan automated discovery and exploitation
At the centre of the operation was QScan, a distributed scanning and exploitation platform designed to process large numbers of internet reconnaissance tasks.
Its functions included scraping webpages, enumerating subdomains, collecting TLS certificates, identifying exposed services and looking for vulnerable content-management-system plugins. The platform could also fingerprint systems and test them against a library of exploits.
Authorities discovered more than 200 Python proof-of-concept exploits in QScan’s database. While individual proof-of-concept programs may be publicly available and used legitimately by defenders, combining hundreds of them with automated global scanning creates a system capable of rapidly identifying and attacking organisations that have not applied security updates.
The scale was substantial. On one day in 2024, QScan processed more than two million scanning and penetration-testing tasks, according to the advisory.
The platform distributed work through RabbitMQ message queues to worker systems, many of which were leased servers outside China. Results were returned through separate infrastructure using Redis. This distributed architecture enabled the group to separate task management, scanning nodes and collected results while adding capacity as needed.
QTFY also accumulated a database derived from almost a decade of internet scanning. That historical information could be used to profile specific organisations or rapidly locate potentially vulnerable systems after disclosure of a new security flaw.
This is particularly dangerous during the narrow period between publication of a vulnerability and widespread deployment of patches. A platform with an existing inventory of appliances, software versions and exposed services may allow its operators to locate likely targets without beginning a new internet-wide search.
The advisory says QTFY used both zero-day vulnerabilities—flaws unknown to a vendor or unpatched when exploitation began—and N-day vulnerabilities for which fixes were already available. The group’s history illustrates why organisations cannot concentrate solely on sophisticated zero-days: older, known vulnerabilities remain valuable when internet-facing systems are left unpatched.
QTRouter concealed the origin of attacks
After discovering or compromising a target, operators could use QTRouter to conceal their connection.
QTRouter combined compromised routers and other Internet of Things devices with commercial proxy services, cloud-hosted systems and leased virtual private servers. Some participating routers ran customised OpenWrt software and authenticated with central administration systems.
The platform used the open-n multiple nodes together. This allowed operators to pass traffic through several intermediaries before reaching a victim
As a result, an intrusion initiated by a China-based operator could appear to originate from a residential router, security camera or other device in another country. In some cases, the final proxy could be geographically close to the victim, making the connection look more like ordinary local traffic.
The FBI said the wider infrastructure routed traffic through devices in more than 130 countries.
This tradecraft weakens security controls based primarily on geographic origin or reputation. Blocking all connections from China will not stop an operator whose traffic exits through an apparently ordinary broadband connection in the United States, United Kingdom or another trusted location.
The actors further obscured their activity by mixing malicious connections with legitimate commercial proxy traffic. A defender investigating one suspicious address might therefore find both benign users and hostile operations passing through the same node.
Compromised IoT devices are particularly useful for this purpose because they often receive less security monitoring than conventional servers. Owners may not realise that their routers or cameras are relaying foreign intelligence operations, and some devices no longer receive firmware updates.
Three botnet-management platforms identified
The agencies found at least three systems capable of managing the compromised devices feeding QTRouter.
The first, translated as “Proxy Platform Management,” managed infected endpoints and deployed proxy software to them. Its architecture contained client, agent and server components, allowing operators to control devices indirectly.
A second system, “Proxy Pool Management System,” aggregated compromised devices and hosted tools for attacking additional IoT systems. It included an exploit database and a collection of device fingerprints that could help operators quickly identify new targets whenever another vulnerability became available. Stored device categories reportedly included MikroTik RouterOS equipment, PPTP devices and systems configured as SOCKS5 proxies.
The third platform, QTBotnet, used a hierarchy consisting of a primary controller, secondary control servers and compromised devices. It could execute commands, import and manage nodes and launch distributed denial-of-service attacks.
That architecture shows that the network was not limited to passive traffic forwarding. At least part of the ecosystem also provided direct remote control and disruptive attack capabilities.
Persistence through web shells, malware and stolen credentials
Once inside a network, QTFY operators reportedly installed remote-access trojans and web shells or stole legitimate credentials to preserve access.
Web shells are malicious scripts placed on web servers that provide a hidden remote interface. They can remain accessible after the original vulnerability has been patched if an organisation updates software without examining whether exploitation occurred before the fix was installed.
Stolen credentials create a similar problem. Changing or repairing the vulnerable appliance may not remove access if the attackers have already obtained passwords, session tokens, API keys or administrative accounts.
The use of QTRouter makes this persistence harder to identify. An adversary can reconnect through an IP address near the victim or rotate between proxy nodes, frustrating investigations that expect a stable command-and-control address.
The advisory also says QTFY participates in Chinese exploit-development circles, freelance hacking networks and offensive security competitions. Investigators observed the group heavily researching the integration of artificial intelligence into its processes during the previous two years, although the agencies did not claim that AI was responsible for the group’s most important compromises.
Domain seizure disrupts core platforms
The Justice Department’s intervention targeted domains essential to QScan and QTRouter.
According to court documents unsealed in the Southern District of California, the seized domains were hard-coded into the platforms and handled functions including communications and authentication. Removing the operators’ control of those domains prevented components from reaching the services they needed to work.
This approach is materially different from simply blocking a malicious IP address. If the same domain is embedded throughout a distributed platform, transferring control of it can interrupt connections from many components simultaneously.
Still, the action should be understood as a disruption rather than a permanent elimination of the underlying capability. The operators may attempt to rebuild infrastructure, update their software or move to new domains. Compromised devices that were part of the network may also remain vulnerable to other actors.
The operation follows several US actions against China-linked botnets. In 2023, the FBI disrupted a botnet used by Volt Typhoon to conceal activity against critical infrastructure. In 2024, it disabled a network of hundreds of thousands of compromised IoT devices associated with Flax Typhoon. In 2025, authorities removed PlugX surveillance malware from more than 4,000 US computers infected by Mustang Panda.
Together, the cases show how compromised small-office and home-office equipment has become an important layer of state-sponsored cyber operations.
Organisations urged to patch, segment and investigate
The NSA, FBI and Cyber National Mission Force recommend applying current software and firmware updates across internet-facing systems, including routers, firewalls, VPNs, file-transfer applications, remote-access platforms and content-management software.
Organisations should also identify end-of-support equipment and replace devices that no longer receive security updates. Automatic updates should be enabled where appropriate, but defenders should still verify that updates were successfully installed.
Critical servers and operational technology should be segmented from edge devices. A compromised VPN appliance, router or web server should not provide unrestricted access to sensitive management networks, identity infrastructure or industrial systems.
Security teams should review public webpages and internet-facing applications for accidentally exposed API keys, access tokens, passwords, configuration data and other operational information. QScan’s webpage-scraping capability means that seemingly minor disclosures could be collected at scale and used to support later attacks.
The advisory provides extensive indicators of compromise, including domains, IP addresses, certificates, file hashes and other infrastructure associated with QScan, QTRouter and the botnet-management platforms. The agencies caution that some indicators are historical or may be connected to shared infrastructure. Organisations should investigate and contextualise matches before automatically blocking them.
Where compromise is suspected, responders should isolate affected systems, preserve relevant logs and forensic evidence and determine which accounts, devices and applications were accessed. Passwords, keys and tokens exposed through a compromised system should be rotated.
Defenders should also search for web shells, unexpected administrative accounts, unauthorised remote-access software, unusual proxy configurations and connections from residential or IoT-associated addresses that do not fit normal business activity.
A warning about the infrastructure behind cyber espionage
The QTFY case is significant not just because of the organisations targeted, but because it exposes part of the supply chain supporting modern state-sponsored intrusion campaigns.
QScan enabled reconnaissance and exploitation at industrial scale. The botnet platforms supplied compromised devices. QTRouter transformed those devices into a geographically distributed concealment layer. Chinese government-linked customers could then use the combined infrastructure without necessarily maintaining every component themselves.
Disabling central domains raises the cost of those operations and may remove access to infrastructure accumulated over several years. But the underlying market for vulnerable IoT devices, leased servers, proxy networks and offensive cyber services remains intact.
For defenders, the immediate priority is therefore not simply to block a list of QTFY addresses. It is to reduce the opportunities that made the platform effective: exposed and unpatched edge devices, weak segmentation, excessive trust in local-looking IP addresses, forgotten web shells and credentials that remain valid after a security incident.
TheNSA warningprovides a rare view of an end-to-end system built to discover targets, exploit vulnerabilities and hide the resulting operations. Although US authorities have disrupted two central components, organisations previously scanned or attacked by QTFY must still determine whether the group gained access before the infrastructure was taken offline.