Find notable cyber news and cases, enriched with sources, timelines, and signals.

QTFY long-running campaign against U.S. critical infrastructure

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The QTFY campaign has been mapped as a long-running operation against U.S. critical infrastructure and sensitive networks, with activity dating to 2018 and attacks reported as recently as June 2026. The group built QScan and QTRouter to scan, infect, and obscure intrusions, making attribution harder. The operation has touched high-value U.S. targets including NASA, the Federal Reserve, DoE, DoJ, HHS, NIH, and the U.S. Senate. The scale and persistence of the activity increase risk for critical systems, academia, and other sensitive networks.

Related Happenings

DoJ disrupts QTFY QScan and QTRouter infrastructure

Law Enforcement
H score26 First: 26.08.2026 19:42 Last: 26.08.2026 19:42 Sources 1

How related: The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.

About this happening: The U.S. Department of Justice disrupted QScan and QTRouter, cutting off a cybercrime infrastructure used by QTFY to target U.S. critical infrastructure an...

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
H score33 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...

US government warning on Iran-affiliated critical infrastructure disruption risk

Public Sector Action
H score24 First: 18.05.2026 18:41 Last: 18.05.2026 18:41 Sources 1

About this happening: The US government warned that Iran-affiliated threat actors were disrupting US critical infrastructure through attacks on Internet-exposed OT devices across mult...

UAT-7290 long-running telecom espionage campaign

Campaign
H score41 First: 08.01.2026 18:00 Last: 08.01.2026 18:00 Sources 1

About this happening: UAT-7290 is running a long-running cyber-espionage campaign against telecommunications providers in South Asia, with recent expansion into Southeastern Europe. The ope...

Timeline

  1. 26.08.2026 19:42 2 articles · 2h ago

    DOJ disrupts QScan and QTRouter used by QTFY to target U.S. critical infrastructure

    Initial Disclosure

    The U.S. Department of Justice announced the disruption of QScan and QTRouter, hacking platforms operated by the China-linked QTFY group to target U.S. critical infrastructure and other sensitive networks. The FBI said QTFY has been active since May 2018, used QScan to exploit vulnerable IoT devices and add them to the QTRouter network, and relied on QTRouter as an obfuscation layer built from compromised devices, commercial proxy services, and leased VPSs. Named victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, and the seized domains were hard-coded into both products so the court-authorized action caused them to cease operations.

    Show sources