Zero Day Room
Live
Vulnerabilities

FBI: Chinese Group QTFY Targets US

The FBI warns that Chinese hacking group QTFY, active since 2018, is using custom-built platforms to target US critical infrastructure.

The FBI warns that Chinese hacking group QTFY, active since 2018, is using custom-built platforms to target US critical...

The FBI warns that a sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems. The group uses a custom-built ecosystem of malicious platforms to conduct its operations, according to an advisory published on August 26 by the FBI, the National Security Agency, and the Cyber National Mission Force.

QTFY, also known as QT and QTCYBER, has been attributed to Nanjing Xinjiuwei Network Technology Co., a company linked to the People's Republic of China (PRC). The group has focused on sectors including the defense industrial base, communications, government, and higher education since its establishment in 2018. In 2024, QTFY successfully exfiltrated data from over 300 organizations in the US and globally by exploiting a Check Point Quantum Gateway vulnerability. Victims have included US defense contractors, financial institutions, universities, the US Department of Justice, the US Federal Reserve, and NASA. The group has also attempted to compromise hospitals and election systems.

Custom Attack Ecosystem

QTFY operates using its own distributed ecosystem, which the FBI says makes it difficult for defenders to identify and track its activity. This ecosystem includes several interconnected custom platforms.

One platform, named "QScan," is designed to rapidly identify vulnerabilities in victim networks and exploit vulnerable IoT devices. The FBI revealed that QTFY used QScan to conduct over two million scanning and penetration testing tasks in a single day in 2024. Another product, "QTRouter," is a network traffic obfuscation tool running on devices like routers with custom OpenWrt software. QTFY also uses botnet products to control compromised IoT devices and incorporate them as proxy nodes for the QTRouter network. "These products work in conjunction with each other," the FBI noted.

Nick Tausek, lead security automation architect at Swimlane, commented on the sensitivity of the targets. "Military and defense-linked networks are about as sensitive as targets get," he said. "Even limited access can give an adversary intelligence that's useful far beyond the organization initially breached."

Attack Methodology

The advisory highlighted QTFY's focus on exploiting zero-day and N-day vulnerabilities to gain initial access. The QScan platform conducts reconnaissance, including webpage scraping, TLS certificate collection, subdomain enumeration, and penetration testing. It maintains a large database to quickly identify targets of interest when a new vulnerability is discovered.

The group participates in freelance PRC hacker networks and malicious cyber contracting marketplaces. This reportedly enables them to keep up with new exploits and attack techniques, including the integration of AI. Once inside a network, QTFY attempts to maintain persistence by deploying remote access trojans (RATs), web shells, and obtaining legitimate credentials.

The QTRouter obfuscation network allows the group to access victim networks from nearby compromised IoT devices, blending in with legitimate traffic. The FBI stated that unique user agent strings from IP addresses in China indicated QTRouter was used by both QTFY personnel and PRC government personnel. QTFY has also developed at least three major platforms to manage botnets of compromised IoT devices for this network.

Gabrielle Hempel, a security operations strategist at Exabeam, said the scale of QTFY's model poses unique challenges. "They have built an ecosystem designed to make malicious activity look geographically and operationally ordinary," she said. Hempel noted that QScan gives the group a head start when a new vulnerability emerges, as it may already have a catalogue of exposed systems ready to exploit.

Recommended Defensive Measures

The authoring agencies recommended several measures for government and critical infrastructure organizations to protect against QTFY:

  • Apply the latest software and firmware updates to your organization's devices.
  • Regularly audit your organization's web pages and applications for published secrets, such as API keys and tokens.
  • Proactively threat hunt for indicators of compromise included in the advisory.
  • Isolate critical systems from edge devices.
  • Regularly test your organization's security program against the threat behaviors mapped to the MITRE ATT&CK for Enterprise framework detailed in the advisory.

In a separate announcement on August 26, the US Justice Department and FBI revealed they had successfully disrupted the QScan and QTRouter platforms. Court documents indicate QTFY offered these hacking services to paying customers. This law enforcement action is the latest in a series of court-authorized technical operations against indiscriminate hacking activities linked to the PRC.

Related coverage

More from Vulnerabilities