Back to feed

FBI takedown of QTFY exposes China's industrialized state hacking infrastructure

2 min
FBI takedown of QTFY exposes China's industrialized state hacking infrastructure

This digest was compiled by AI from multiple sources — links to the originals are below.

The FBI and Justice Department seized domains linked to QScan and QTRouter, hacking platforms operated by China-based Nanjing Xinjiuwei Network Technology Company. The platforms supported Chinese state-sponsored group QTFY in targeting US agencies including NASA, the Federal Reserve, and the Department of Energy. The action underscores how China's use of private cyber contractors gives state hackers scale and stealth.

Key Facts

  • The FBI and Justice Department seized domains hard-coded into QScan and QTRouter, two hacking platforms used by Chinese state-sponsored group QTFY.
  • QTFY is employed by Nanjing Xinjiuwei Network Technology Company and offers hacking services to the PRC's Ministry of State Security and the People's Liberation Army.
  • Targets of QTFY include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, and the US Senate.
  • QScan automatically infects thousands of IoT devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices.
  • The FBI previously removed PlugX malware from over 4,000 US computers infected by PRC-sponsored group Mustang Panda.

The Takedown

The US Justice Department and FBI announced court-authorized seizures of domains hard-coded into QScan and QTRouter. The platforms were created and operated by QTFY, a PRC state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company. QTFY offers computer hacking services to paying customers, including the PRC's Ministry of State Security and the People's Liberation Army. QScan scans and automatically infects thousands of IoT devices worldwide, which are then added to the QTRouter network.

Targets and Impact

QTFY targeted NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. FBI cyber assistant director Brett Leatherman said QTFY has exploited software vulnerabilities for nearly a decade to launch cyberattacks against US government agencies, power companies, telcos, and major hospital systems. Leatherman described QTFY as operating within a complex network of hackers-for-hire and government clients in the People's Republic of China.

FBI's Broader Campaign

The FBI previously removed PlugX surveillance malware from over 4,000 US computers infected by PRC-sponsored group Mustang Panda. In 2024, the FBI disabled a botnet of hundreds of thousands of infected IoT devices that PRC-sponsored group Flax Typhoon provided to Chinese government customers. In 2023, the FBI disrupted a botnet used by PRC-sponsored group Volt Typhoon to conceal exploitation of US and foreign critical infrastructure. SentinelOne consultant Dakota Cary said QTFY's shared service combined reconnaissance, exploitation, routing, and obfuscation infrastructure for multiple offensive teams.

1 source

Time · lag behind first