US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
US disrupts Chinese hacking platform QTFY used against military and critical infrastructure.
Summary
The US government has disrupted a hacking platform and botnet operated by the Chinese state-sponsored group QTFY. This group, linked to Nanjing Xinjiuwei Network Technology, offered hacking services for attacks against military and critical infrastructure in the US since 2018. The operation targeted QTFY's QScan and QTRouter tools, seizing domains to render them inoperable.
Full text
The US government announced on Wednesday that it has disrupted a hacking platform and botnet used by Chinese threat actors in attacks aimed at military and critical infrastructure systems. According to the Justice Department, the disruption efforts targeted a state-sponsored group called QTFY, which has been operating from a company called Nanjing Xinjiuwei Network Technology. QTFY has offered its hacking services to the Chinese government and others, enabling attacks against many critical systems in the United States since its establishment in 2018. Disruption of QTFY hacking platform The US government has targeted two hacking services offered by QTFY: the scanning and exploitation platform QScan, and the obfuscation network QTRouter. QScan is designed to scan the internet for vulnerable IoT devices and ensnare them in the QTRouter botnet, enabling threat actors to abuse the compromised devices to conceal their malicious activities and evade detection. US authorities identified and seized domains used by QScan and QTRouter.Advertisement. Scroll to continue reading. “Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” explained the Justice Department. QTFY attacks and exploitation A technical cybersecurity advisory published on Wednesday by the FBI reveals that QTFY has been developing malicious tools, trading malware and exploits, and maintaining botnets to carry out its attacks. Targeted sectors include the defense industrial base, local government, telecoms, and higher education. The agency said some of the group’s attempts to hack sensitive networks were unsuccessful, including attacks aimed at the Department of Energy, election systems, the Department of Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company. Other attacks appear to have been successful at least to some extent, including against NASA, the Justice Department, the Federal Reserve, the Department of Energy, state governments, a major retailer, a telecoms company, defense contractors, universities, and financial institutions. The hackers have been observed exploiting vulnerabilities in products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure. “QTFY actors are active in the exploit development community, freelance PRC [People’s Republic of China] hacker networks, and PRC malicious cyber contracting and subcontracting marketplaces,” the FBI noted. “QTFY participates in the offensive end of network attack and defense events against Chinese critical infrastructure.” The FBI also pointed out that the company behind QTFY has had business relationships with various entities connected to the Salt Typhoon cyberespionage group, the i-Soon cyber intrusion firm, and several others. Related: Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown Related: GlassWorm Botnet Disrupted Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs CISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateFirst Malware Built Specifically for Car Head Units Fuels BotnetCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited91 Vulnerabilities Patched in Spring Application Framework Latest News Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicesRecent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksThe MFA Identity Trap: When Authentication Creates a False Sense of SecurityChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data Breach Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveNaveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.More People On The MoveExpert Insights The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email