QTFY US government and critical infrastructure targeting campaign
Campaign
Summary
Hide ▲
Show ▼
The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy compromise across sensitive sectors. The group has operated since 2018 and has focused on the defense industrial base, communications, government, and higher education sectors. In 2024, it exfiltrated data from over 300 organizations after exploiting a Check Point Quantum Gateway vulnerability. Its toolkit includes QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices.
Related Happenings
FBI urgent mitigation advisory for QTFY
Advisory/Mitigation
H score39
First: 27.08.2026 15:00
Last: 27.08.2026 15:00
Sources 1
How related:
US government and critical infrastructure entities have been advised to take urgent action to mitigate the threat from QTFY.
About this happening:
The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...
FBI urgent mitigation advisory for QTFY
Advisory/MitigationHow related: US government and critical infrastructure entities have been advised to take urgent action to mitigate the threat from QTFY.
About this happening: The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...
QTFY's freelance PRC hacker-network and cyber-contracting ecosystem
Threat Actor Meta
H score33
First: 27.08.2026 15:00
Last: 27.08.2026 15:00
Sources 1
How related:
The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.
About this happening:
QTFY's participation in freelance PRC hacker networks and malicious cyber contracting marketplaces reveals a broader support ecosystem behind its operations. The networked...
QTFY's freelance PRC hacker-network and cyber-contracting ecosystem
Threat Actor MetaHow related: The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.
About this happening: QTFY's participation in freelance PRC hacker networks and malicious cyber contracting marketplaces reveals a broader support ecosystem behind its operations. The networked...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementAbout this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
Campaign
H score17
First: 19.08.2026 20:50
Last: 19.08.2026 20:50
Sources 1
About this happening:
The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
CampaignAbout this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
German draft legislation expanding intelligence hack-back powers
Public Sector Action
H score32
First: 14.08.2026 12:38
Last: 14.08.2026 12:38
Sources 1
About this happening:
Germany approved draft legislation that expands foreign and domestic intelligence agencies’ cyber powers, giving them new authority to dismantle hostile servers and disr...
German draft legislation expanding intelligence hack-back powers
Public Sector ActionAbout this happening: Germany approved draft legislation that expands foreign and domestic intelligence agencies’ cyber powers, giving them new authority to dismantle hostile servers and disr...
Timeline
-
26.08.2026 03:00 2 articles · 1d ago
FBI warns QTFY is targeting US government and critical infrastructure
Initial DisclosureThe FBI, in coordination with the National Security Agency and Cyber National Mission Force on August 26, warned that QTFY, also tracked as QT and QTCYBER, is targeting US government and critical infrastructure systems with custom-built malicious platforms. The group has focused on defense industrial base, communications, government, and higher education targets since being established in 2018, and in 2024 it exfiltrated data from over 300 organizations by exploiting a Check Point Quantum Gateway vulnerability. The FBI also attributed QTFY to Nanjing Xinjiuwei Network Technology Co., and described QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices running custom OpenWrt software.
Show sources
- Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns — www.infosecurity-magazine.com — 27.08.2026 15:00
- Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns — www.infosecurity-magazine.com — 27.08.2026 15:00