QTFY long-running campaign against U.S. critical infrastructure
Campaign
Summary
Hide ▲
Show ▼
The QTFY campaign has been mapped as a long-running operation against U.S. critical infrastructure and sensitive networks, with activity dating to 2018 and attacks reported as recently as June 2026. The group built QScan and QTRouter to scan, infect, and obscure intrusions, making attribution harder. The operation has touched high-value U.S. targets including NASA, the Federal Reserve, DoE, DoJ, HHS, NIH, and the U.S. Senate. The scale and persistence of the activity increase risk for critical systems, academia, and other sensitive networks.
Related Happenings
DoJ disrupts QTFY QScan and QTRouter infrastructure
Law Enforcement
H score26
First: 26.08.2026 19:42
Last: 26.08.2026 19:42
Sources 1
How related:
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
About this happening:
The U.S. Department of Justice disrupted QScan and QTRouter, cutting off a cybercrime infrastructure used by QTFY to target U.S. critical infrastructure an...
DoJ disrupts QTFY QScan and QTRouter infrastructure
Law EnforcementHow related: The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
About this happening: The U.S. Department of Justice disrupted QScan and QTRouter, cutting off a cybercrime infrastructure used by QTFY to target U.S. critical infrastructure an...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementAbout this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
US government warning on Iran-affiliated critical infrastructure disruption risk
Public Sector Action
H score24
First: 18.05.2026 18:41
Last: 18.05.2026 18:41
Sources 1
About this happening:
The US government warned that Iran-affiliated threat actors were disrupting US critical infrastructure through attacks on Internet-exposed OT devices across mult...
US government warning on Iran-affiliated critical infrastructure disruption risk
Public Sector ActionAbout this happening: The US government warned that Iran-affiliated threat actors were disrupting US critical infrastructure through attacks on Internet-exposed OT devices across mult...
UAT-7290 long-running telecom espionage campaign
Campaign
H score41
First: 08.01.2026 18:00
Last: 08.01.2026 18:00
Sources 1
About this happening:
UAT-7290 is running a long-running cyber-espionage campaign against telecommunications providers in South Asia, with recent expansion into Southeastern Europe. The ope...
UAT-7290 long-running telecom espionage campaign
CampaignAbout this happening: UAT-7290 is running a long-running cyber-espionage campaign against telecommunications providers in South Asia, with recent expansion into Southeastern Europe. The ope...
Timeline
-
26.08.2026 19:42 2 articles · 2h ago
DOJ disrupts QScan and QTRouter used by QTFY to target U.S. critical infrastructure
Initial DisclosureThe U.S. Department of Justice announced the disruption of QScan and QTRouter, hacking platforms operated by the China-linked QTFY group to target U.S. critical infrastructure and other sensitive networks. The FBI said QTFY has been active since May 2018, used QScan to exploit vulnerable IoT devices and add them to the QTRouter network, and relied on QTRouter as an obfuscation layer built from compromised devices, commercial proxy services, and leased VPSs. Named victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, and the seized domains were hard-coded into both products so the court-authorized action caused them to cease operations.
Show sources
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations — thehackernews.com — 26.08.2026 19:42
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations — thehackernews.com — 26.08.2026 19:42