Find notable cyber news and cases, enriched with sources, timelines, and signals.

QTFY US government and critical infrastructure targeting campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy compromise across sensitive sectors. The group has operated since 2018 and has focused on the defense industrial base, communications, government, and higher education sectors. In 2024, it exfiltrated data from over 300 organizations after exploiting a Check Point Quantum Gateway vulnerability. Its toolkit includes QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices.

Related Happenings

FBI urgent mitigation advisory for QTFY

Advisory/Mitigation
H score39 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: US government and critical infrastructure entities have been advised to take urgent action to mitigate the threat from QTFY.

About this happening: The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...

QTFY's freelance PRC hacker-network and cyber-contracting ecosystem

Threat Actor Meta
H score33 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.

About this happening: QTFY's participation in freelance PRC hacker networks and malicious cyber contracting marketplaces reveals a broader support ecosystem behind its operations. The networked...

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
H score33 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

German draft legislation expanding intelligence hack-back powers

Public Sector Action
H score32 First: 14.08.2026 12:38 Last: 14.08.2026 12:38 Sources 1

About this happening: Germany approved draft legislation that expands foreign and domestic intelligence agencies’ cyber powers, giving them new authority to dismantle hostile servers and disr...

Timeline

  1. 26.08.2026 03:00 2 articles · 1d ago

    FBI warns QTFY is targeting US government and critical infrastructure

    Initial Disclosure

    The FBI, in coordination with the National Security Agency and Cyber National Mission Force on August 26, warned that QTFY, also tracked as QT and QTCYBER, is targeting US government and critical infrastructure systems with custom-built malicious platforms. The group has focused on defense industrial base, communications, government, and higher education targets since being established in 2018, and in 2024 it exfiltrated data from over 300 organizations by exploiting a Check Point Quantum Gateway vulnerability. The FBI also attributed QTFY to Nanjing Xinjiuwei Network Technology Co., and described QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices running custom OpenWrt software.

    Show sources