The U.S. Department of Justice (DoJ) announced the disruption of two hacking platforms, QScan and QTRouter, operated by the Chinese state-sponsored group QTFY, which is linked to Nanjing Xinjiuwei Network Technology Company. The infrastructure was used to target critical infrastructure and sensitive networks in the United States, including NASA, the Federal Reserve, the Department of Energy, and the U.S. Senate.
QTFY has been active since May 2018, according to Lumen Black Lotus Labs, and has been attributed to China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA). The group used QScan to scan and infect IoT devices, adding them to the QTRouter network, which served as an obfuscation network to hide the true origins of cyber intrusions. The FBI noted that QTFY exploited both zero-day and N-day vulnerabilities, including CVE-2024-8190, CVE-2024-8963, CVE-2024-9380 in Ivanti CSA appliances, and CVE-2018-13379 in Fortinet SSL-VPN, among others.
The disruption involved seizing domains hard-coded into the tools, causing them to cease operations. The FBI described QTFY as an enabling company with ties to larger private cyber-enabling firms in China, and noted that QTFY actors participated in freelance brokering networks to acquire and sell cyber exploit items. Attacks as recent as June 2026 targeted a U.S. election system.
Lumen highlighted the industrialization of China-nexus cyber operations, emphasizing that traditional static blocks are no longer sufficient to stop such threats.
CVEs: CVE-2024-8190, CVE-2024-8963, CVE-2024-9380, CVE-2018-13379, CVE-2019-19781, CVE-2021-26855, CVE-2020-5902, CVE-2019-10068, CVE-2021-44228, CVE-2023-22515, CVE-2024-24919, CVE-2025-31161
Attack groups: QTFY
Malware: QScan, QTRouter, QTBotnet
Companies: Nanjing Xinjiuwei Network Technology Company, Lumen Black Lotus Labs, FBI, DoJ
Products: Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Kentico CMS, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, CrushFTP, BeyondTrust Remote Support
Original source: thehackernews.com