Back www.safebreach.com Qtfy Jcsa 20260826 01 Safebreach Coverage
Learn how SafeBreach maps JCSA-20260826-01 to simulations that test your exposure to China-linked QTFY’s industrialized vulnerability scanning and IoT obfuscation network.
Joint Cybersecurity Advisory JCSA-20260826-01, released August 26, 2026 by the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Cyber National Mission Force (CNMF), warns of ongoing activity by the China-linked hacking group QTFY (also tracked as QT and QTCYBER), attributed to Nanjing Xinjiuwei Network Technology Co. (XJW).
Active since 2018, QTFY has industrialized offensive operations across three purpose-built products: QScan, a distributed scanning and exploitation platform that processed over two million tasks in a single day against all queue types; QTRouter, an obfuscation network running on compromised routers and IoT devices; and three botnet platforms that enroll compromised devices as proxy nodes.
Targets span the defense industrial base, communications, energy, water systems, government, and higher education—a May 2024 campaign exfiltrated data from over 300 organizations worldwide.
This post outlines QTFY’s TTPs mapped to MITRE ATT&CK, the fourteen CVEs the advisory attributes to the group, the advisory’s caution against blocking unvetted indicators, and the nine SafeBreach simulations now mapped to the advisory—one existing behavioral attack plus eight new IOC-based attacks covering QTFY’s command-and-control infrastructure.
On August 26, 2026, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Cyber National Mission Force (CNMF) released a joint Cybersecurity Advisory titled “China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems” (Product ID JCSA-20260826-01). The advisory provides critical intelligence on the China-linked hacking group QTFY, including the malicious distributed platforms it built to compromise US and foreign organizations, its tactics, techniques, and procedures (TTPs), its infrastructure, and indicators of compromise (IOCs) derived from incident response and investigative techniques.
QTFY’s products have enabled hackers to obfuscate their location and target critical infrastructure systems including the defense industrial base (DIB), communications, government, energy, information technology, water and wastewater systems, and higher education. The authoring agencies describe their warning as urgent, and the activity as ongoing.
For more information, read the full advisory here .
Understanding the QTFY Threat
QTFY—which also uses the acronyms QT and QTCYBER for itself and its tooling—is attributed to Nanjing Xinjiuwei Network Technology Co. (XJW / 南京鑫玖维网络科技有限公司), a company established in 2018. XJW is an enabling company for cyber operations linked to the People’s Republic of China (PRC). It holds business relationships with PRC Ministry of State Security (MSS) units and with larger private China-based cyber-enabling companies specializing in critical infrastructure security.
What makes QTFY distinctive is less its exploits than its business model. QTFY actors include former People’s Liberation Army (PLA) members who leverage their contacts to win contracts and sub-contracts related to targeting critical infrastructure. They participate in China-based freelance brokering networks, buying and selling cyber exploit items—including access to victim networks. The advisory names an ecosystem of counterparties around XJW, including MSS Unit 0718 (which held a business relationship with the Salt Typhoon-associated Sichuan Zhixin Ruijie Network Technology) and MSS Unit 9086, alongside commercial entities such as Bozhi Security Technology, Changyang Technology (Cy-Tech), Nanjing Lexbell Information Technology, and Fujian Ares Network Technology.
XJW sits inside what the advisory calls the PRC enabler ecosystem: a layer of nominally private companies performing contract and subcontract work for the MSS. If the shape is familiar, that is the point. The advisory notes that MSS Unit 9086 held two contracts in 2019 with i-Soon, the China-based intrusion company whose leaked internal documents read less like a hacking manual than a corporate sales deck for espionage. QTFY establishes that i-Soon was not an outlier but a specimen.
What makes the ecosystem legible is that it has procurement cycles and competitive bidders. Bozhi Security Technology submitted three bids to the National University of Defense Technology in June 2025 for power-system vulnerability detection and information-assurance work. Nanjing Lexbell won a contract to build a networked data-mining tool to parse unstructured data in support of command-and-control system design. Fujian Ares Network Technology was finalist or winning bidder on at least six NUDT projects for radio-frequency hardware and software between May 2023 and October 2025. This is not a shadowy crew operating outside the state. It is a small industry with named suppliers, tender documents, and a customer.
QTFY has also invested in staying current. The advisory notes the actors are active on the offensive end of Chinese network attack and defense events (护网/HW/HVV), and that their use of Ivanti Cloud Services Appliance zero-days in September 2024 occurred directly after one of these events. The sequencing is worth sitting with: these domestic exercises appear to function as a technique pipeline, with capability developed against Chinese critical infrastructure moving into contractor hands and then outward at commercial scale. The advisory also records that QTFY has been heavily researching and integrating AI into its processes over the past two years. It offers no further detail, but against everything else in the document, that is not a throwaway line.
For nearly a decade, QTFY products and infrastructure have been observed targeting sensitive networks in the US and worldwide. The advisory’s timeline of observed activity runs from vulnerability scanning of the US Department of Energy in May 2018 through scanning of a US election system in June 2026—and includes a May 2024 campaign in which QScan was used against US power and telecommunications companies, exfiltrating data from over 300 organizations in the United States and around the world, with victims including US defense contractors, financial institutions, and universities.
Recent PRC-linked activity we have covered includes Salt Typhoon and allied actors (CISA Advisory AA25-239A) —an advisory this one explicitly cross-references through the Unit 0718 relationship.
The QTFY Attack Chain
SafeBreach Labs breaks the operation into four stages:
Reconnaissance. QTFY runs millions of automated internet scanning tasks through QScan to identify vulnerable software, while acquiring zero-day and N-day exploits through freelance hacker networks and Chinese security competitions.
Initial access. The actors exploit perimeter vulnerabilities in VPNs, edge devices, and web applications—Ivanti, Check Point, Citrix, and Log4Shell among them—to penetrate critical infrastructure systems.
Defense evasion and traffic obfuscation. Attack traffic is proxied through QTRouter and compromised IoT botnet nodes, blending malicious commands with legitimate user traffic.
Persistence and data exfiltration. QTFY deploys remote access trojans and web shells, harvests legitimate credentials, and maintains long-term access to exfiltrate sensitive data across target organizations.
The attack complexity is high, and the objective is unambiguous: persistent network access and data exfiltration from US critical infrastructure, government agencies, and sensitive global networks in service of state- espionage.
QTFY’s Three Malicious Products
The advisory breaks QTFY’s tooling into three interlocking products. Understanding how they fit together is the key to understanding the threat.
QScan is a distributed system that processes a high volume of internet scanning tasks, including malicious penetration testing. Architecturally it is a task-queue pipeline: a “mq-task” server hosting RabbitMQ message queues (queuing port 5672, management port 15672) distributes scanning tasks to a pool of worker nodes primarily housed on leased servers located outside of China; a “mq-result” server running Redis (port 16379) receives completed tasks. As of December 2025 the domain qt-proxy[.]org had subdomains mq-task.qt-proxy[.]org and mq-result.qt-proxy[.]org ; prior to December 2025 the domains were mq-task.qt-team[.]com and mq-result.qt-team[.]com .
QScan’s task queues include webpage scraping, TLS certificate collection, subdomain enumeration, and penetration testing. The web-scraping queue includes a dedicated task for detecting the presence of specific content management system plugins that may have weakened a website’s security. For penetration testing, the system carries a database of over 200 proof-of-concept exploits written in Python and was designed for large-scale employment. On a single day in 2024, QScan processed over two million scanning and penetration testing tasks .
QTRouter is a network traffic obfuscation network running on devices that include routers with custom OpenWrt software. As of June 2026, QTRouter devices authenticate to administration servers named “Proxy Node Management System” (代理节点管理系统) at and securelink.qtproxy[.]xyz . QTRouter nodes include commercial proxy service IP addresses (including a proxy service called Fastlink), Alibaba Cloud IPs, and compromised IoT devices. QTRouter uses Clash to establish proxy connections; its functionality includes viewing available nodes and chaining nodes together to obscure the actor behind the activity. By mixing malicious traffic with legitimate traffic on commercial proxy services and using compromised IoT devices to borrow the locations of legitimate users, QTRouter makes the activity difficult to identify and track. As of December 2025, a jump server for the obfuscation network uses the domain jump.qt-proxy[.]org (previously jump.qt-team[.]com ). Unique user agent strings originating from IP addresses in China indicate QTRouter was used by QTFY personnel and PRC government personnel in Jiangsu, Qingdao, Jilin, and Sichuan.
Botnet platforms. QTFY developed and maintained at least three platforms that manage botnets of compromised IoT devices and enroll them as obfuscation network nodes:
“Proxy Platform Management” (代理平台管理) —manages a botnet of compromised devices and configures proxy software on them. Three components were identified hosted on open web directories: a “client”, an “agent”, and a “server”; the actor interacts with the server, and the agent handles client-server communication.
“Proxy Pool Management System” (代理池管理系统) —hosted at IP address 206.119.167[.]207 . An aggregator of compromised IoT devices and hosted tools to compromise IoT devices, holding a database of exploits and a database of server fingerprints to quickly identify systems to target when a new exploit is discovered or new proxy nodes are needed. It contains categorized lists of compromised IoT devices with access details, including SOCKS5 botnet proxies, MikroTik RouterOS devices, and PPTP devices.
QTBotnet —a main controller server, secondary-level control servers, and compromised devices. The control server can launch DDoS attacks, view nodes, import nodes, run commands on compromised IoT devices, and manage the level 2 servers.
Key Tactics, Techniques, and Procedures (TTPs)
The advisory maps QTFY activity to the MITRE ATT&CK Matrix for Enterprise, version 19. Note that the advisory cites a deliberately narrow set of technique IDs—the breadth of QTFY’s threat is in the scale and industrialization of these few techniques rather than in a long technique list.
Active Scanning: Vulnerability Scanning ( T1595.002 )—QTFY actors run software to check whether target systems match the configuration of a system that is expected to be vulnerable. They use the QScan platform to conduct reconnaissance against victim networks, and maintain a large database from nearly a decade of internet scanning that they can leverage when targeting a specific victim, or to quickly identify targets of interest when a new vulnerability is identified.
Exploit Public-Facing Application ( T1190 )—QTFY actors exploit both zero-day and N-day vulnerabilities to gain initial access to victim networks. Per the advisory, actors may run remote commands affecting the target system in a minor way to confirm a vulnerability exists, then run other commands to exploit a weakness in an application accessible via the public web.
The advisory’s targeting timeline attributes exploitation of the following vulnerabilities to QTFY:
CVE-2019-11510 —Pulse Secure VPN, used against the US Department of Justice, US Federal Reserve, and NASA (August 2019)
CVE-2018-13379 —Fortinet FortiOS SSL VPN (October 2019)
CVE-2019-19781 —Citrix Application Delivery Controller (ADC) and Gateway, used against numerous US targets (January 2020)
CVE-2021-26855 —”ProxyLogon”, Microsoft Exchange (March 2021)
CVE-2020-5902 —F5 BIG-IP, used against a US state government and a large US retailer (July–August 2021)
CVE-2019-10068 —Kentico CMS, at a US telecommunications company (August 2021)
CVE-2021-44228 —”Log4Shell” JNDI (December 2021)
CVE-2023-22515 —Atlassian Confluence (October 2023)
CVE-2024-24919 —Check Point Quantum Gateway, leveraged via QScan against US power and telecommunications companies (May 2024)
CVE-2024-8190 , CVE-2024-8963 , and CVE-2024-9380 —Ivanti Cloud Services Appliance (CSA) zero-days, used at three US Department of Energy labs, the US National Institute of Health, the US Health Resources and Services Administration, and a US security device manufacturer (September 2024)
CVE-2025-31161 —CrushFTP, at a US biotechnology company (April 2025)
CVE-2026-1731 —BeyondTrust Remote Support (RS), exploited via QScan against a US state government, with a US water district also targeted (February 2026)
Alongside successful exploitation, the timeline records repeated unsuccessful vulnerability scanning against the US Department of Energy, a US election system (2019 and again in June 2026), the US Department of Health and Human Services, a US children’s hospital, Ivanti management devices at a US semiconductor company, a US power company, and the US Senate and a US hospital system.
Server Software Component: Web Shell ( T1505.003 )—QTFY actors may write or download a small script onto the target system which can be run to expose backdoor access to the system via the internet. More broadly, the advisory notes the actors use various remote access trojans (RATs), web shells, and legitimate credentials obtained from compromised systems to maintain persistence. They also use the QTRouter obfuscation network to access victim networks from nearby compromised IoT, blending in with legitimate users. In 2021, QTFY installed RATs on Taiwan energy sector systems.
Acquire Infrastructure: Virtual Private Server ( T1583.003 )—actors may purchase VPSs available via cloud computing providers, which are easily and rapidly configurable. QScan’s worker nodes were primarily housed on leased servers located outside of China.
Develop Capabilities ( T1587 )—rather than purchasing, freely downloading, or stealing capabilities, QTFY develops its own in house. QScan, QTRouter, and the three botnet platforms are all branded, purpose-built QTFY products.
Indicators of Compromise (IOCs)
The advisory provides extensive IOCs across Tables 1 through 8, including:
IPs and domains affiliated with QTRouter , including the qtproxy[.]xyz administration servers and the qt-proxy[.]org / qt-team[.]com jump server domains
IPs and domains affiliated with Proxy Platform Management , the Proxy Pool Management System, and QTBotnet infrastructure
SHA-256 file hashes for QTFY tooling components
Downloadable IOC files are published by the FBI at QTFY_IOC_Files.csv and QTFY_IOC_Infrastructure.csv .
An important caveat from the authoring agencies: several of the listed indicators are linked to historical QTFY activity as early as 2017, and many are affiliated with current QTFY infrastructure. The agencies explicitly recommend that organizations investigate or vet these IP addresses prior to taking action such as blocking. QTRouter deliberately mixes malicious traffic with legitimate traffic on commercial proxy services—so blocking without vetting carries real risk of collateral impact on legitimate users.
What This Advisory Changes for Defenders
QTFY is less a hacking crew than a scanning-and-exploitation business, and three shifts in defensive posture follow from that model rather than from any single indicator in the advisory.
Exposure, Not Importance, Puts You in Scope
The most instructive entries in the advisory’s timeline are the failures. QTFY scanned US election systems in 2019 and again in June 2026. A US children’s hospital in June 2021. The US Senate and a US hospital system in March 2026. None of those scans succeeded—but the persistence is the signal, not the outcome.
A group running QScan continuously against everything reachable on the internet is not deciding in advance to attack the Senate. It is letting exploitation results nominate targets, then having someone take a closer look when something in a sensitive category lights up. The practical consequence is uncomfortable: any internet-facing exposure puts an organization in scope, regardless of how interesting that organization believes it is to a nation-state. Threat models that begin with “we are not a target” do not survive with an industrial scanner.
The corollary is that N-day speed, not a zero-day arsenal, is the competitive advantage. QTFY does use zero-days when it has them—the September 2024 Ivanti Cloud Services Appliance campaign hit three Department of Energy labs, the National Institute of Health, the Health Resources and Services Administration, and a security device manufacturer on vulnerabilities that were not yet public. But the repeatable model is pivoting existing scanning infrastructure onto a newly disclosed CVE within days. The window between disclosure and patch is the product.
Malicious Traffic That Reads as a Customer
QTRouter deserves more attention than obfuscation layers usually get. What makes it effective is not the code—it runs on compromised routers flashed with custom OpenWrt firmware and chains connections using Clash, a legitimate open-source tool. What makes it effective is the sourcing: commercial residential-proxy services, one named Fastlink, alongside Alibaba Cloud infrastructure and compromised consumer IoT devices, all mixed together.
For a defender reading logs, traffic arriving from a legitimate residential IP address—possibly in their own country, blended into genuine user sessions on a commercial proxy service—does not present as an intrusion. It presents as a customer. Geographic implausibility, reputation scoring, and origin-based heuristics all degrade against this design, because the traffic’s origin is genuinely ordinary.
IOC Blocklists Are a Floor, Not a Ceiling
The advisory’s caution against acting on unvetted IP addresses is usually read as a false-positive warning. It is also a strategic statement the limits of indicator matching. Because QTRouter deliberately mixes malicious traffic with legitimate residential and commercial proxy traffic, blocklists alone will miss a meaningful of this activity going forward, and blocking without vetting risks collateral damage to real users. Behavioral detection has to sit on top of indicator matching, not beside it.
There is also a validation gap worth naming plainly. Exposure-validation programs test endpoint and application behavior well, and QTFY’s initial-access activity sits squarely in that space: every initial-access event in the advisory is exploitation of a public-facing application, and the fourteen CVEs across twelve exploitation events give security teams a specific, testable list. The right question is not whether a category is generally covered by an off-the-shelf rule, but whether these particular exploits would actually be stopped at the perimeter.
QTRouter’s proxy-chaining is a different kind of problem. It is a pattern in network traffic rather than endpoint behavior, which places it outside what attack simulation conventionally exercises. Validating it means a deliberate conversation with whoever owns egress and anomaly detection whether traffic from residential-IP ranges reaching sensitive applications would be flagged or waved through. The IOC-based simulations described below are built for precisely that question.
This Is Live Infrastructure, Not a Retrospective
The advisory bundles eight years of tooling, corporate registration, and MSS unit relationships into a single document, which usually indicates that the investigative picture only recently became complete enough for confident attribution. What it does not indicate is a takedown. Several QTRouter IPs carry an “Active” last-seen status with no end date, and jump.qt-team[.]com is registered through 2032. The authoring agencies are describing infrastructure they are still watching. Whoever is running this does not expect to stop.
SafeBreach Coverage and Playbook Attack Updates
Existing Behavioral Coverage
SafeBreach Labs confirmed existing simulations in the playbook for six of the fourteen CVEs the advisory attributes to QTFY:
Pulse Secure (CVE-2019-11510)
Fortinet FortiOS (CVE-2018-13379)
Citrix ADC (CVE-2019-19781)
Microsoft Exchange ProxyLogon (CVE-2021-26855)
F5 BIG-IP (CVE-2020-5902).
The Log4Shell simulation is mapped to this advisory, and the others can be found by searching the Attack Playbook by CVE number.
QTFY used Log4Shell against victim networks in December 2021, and it remains one of the N-day exploits the group carries in QScan’s proof-of-concept database. Running this simulation validates whether your controls detect and block remote exploitation of the vulnerability. It requires bi-directional communication, since the success criteria is the return connection from the exploited web server back to the attacker simulator.
SafeBreach Labs also confirmed there was no pre-existing IOC coverage for QTFY infrastructure, so all of the network-level content below is new.
New IOC-Based Coverage
SafeBreach Labs added eight new IOC-based simulations that test whether your controls detect and block communication with QTFY’s four infrastructure platforms:
#11800 —ICMP Ping Request to QTFY Cybersecurity Advisory (QTRouter) C2 Servers
#11801 —Communication with QTFY Cybersecurity Advisory (QTRouter) using HTTP
#11802 —ICMP Ping Request to QTFY Cybersecurity Advisory (Proxy Platform Management) C2 Servers
#11803 —Communication with QTFY Cybersecurity Advisory (Proxy Platform Management) using HTTP
#11804 —ICMP Ping Request to QTFY Cybersecurity Advisory (Proxy Pool Management System) C2 Servers
#11805 —ICMP Ping Request to QTFY Cybersecurity Advisory (QScan) C2 Servers
#11806 —Communication with QTFY Cybersecurity Advisory (QScan) using HTTP
#11807 —Communication with QTFY Cybersecurity Advisory (QTFY Infrastructure) using HTTP
Four of these simulations (#11800, #11802, #11804, and #11805) are Advanced Actions. They send a real ICMP echo request to the IP addresses listed in the advisory, and a from the server is what proves the target simulator can reach that infrastructure. The four HTTP simulations are risk free, they place the QTFY domain in the request headers while the traffic itself is directed to a SafeBreach controlled server, so no communication with real QTFY infrastructure takes place.
The new simulations include four ICMP reachability tests, against QTRouter, QScan, Proxy Platform Management, and Proxy Pool Management System infrastructure, and four HTTP communication tests, against QTRouter, QScan, Proxy Platform Management, and additional QTFY domains. Where both protocols run against the same platform, you can distinguish between controls that block outbound traffic to QTFY infrastructure outright and controls that permit the connection but fail to inspect it.
What You Should Do Now
SafeBreach customers can validate their controls against these TTPs in two ways.
Method 1 — Attack Playbook: From the Attack Playbook, select and filter attacks related to Cybersecurity Advisory QTFY. The filter returns the nine attacks mapped to this advisory. The additional CVE simulations listed above can be found by searching the Playbook by CVE number.
Method 2 — Known Threat Series Report: Open the Known Threats Series report, select the Cybersecurity Advisory QTFY report, and run the simulations.
Additional Advisory Steps
Run the SafeBreach Platform Simulations
Log into the SafeBreach platform and navigate to the updated playbooks mapped to JCSA-20260826-01.
Execute the nine simulations mapped to this advisory: #6861 for remote exploitation of Log4Shell (CVE-2021-44228), and #11800 through #11807 for ICMP and HTTP communication with QTFY command and control infrastructure.
Run #6861 for behavioral coverage and #11800 through #11807 for IOC-based coverage of QTFY’s C2 and proxy infrastructure.
Review results to validate detection, surface gaps, and guide remediation.
Mitigation Strategies
Drawn from the advisory’s Mitigations section:
Apply the latest software and firmware updates to your organization’s devices. Enable automatic updates where possible. Audit your environment for end-of-support (EOS) devices and use lifecycle management procedures to plan their replacement.
Keep web server software and plugins up to date, and monitor for web shells. QScan specifically hunts for CMS plugins that weaken a site’s security posture, and web shells are QTFY’s named persistence technique.
Patch the vulnerabilities QTFY is known to exploit —prioritizing edge and remote-access products: BeyondTrust Remote Support ( CVE-2026-1731 ), CrushFTP ( CVE-2025-31161 ), Ivanti CSA ( CVE-2024-8190 , CVE-2024-8963 , CVE-2024-9380 ), and Check Point Quantum Gateway ( CVE-2024-24919 ).
Protect operational information from unintentional disclosure via internet-facing applications. Regularly audit your web pages and applications for published secrets—API keys, tokens, sensitive configuration details—and configure applications to expose only non-sensitive information to web crawlers and scanners. QTFY’s entire model begins with scraping and scanning at scale.
Isolate critical systems from edge devices. Implement zero trust network segmentation principles to limit the scope of a potential breach.
Hunt for the provided indicators of compromise in your network environment or network monitoring solution—after vetting them, per the advisory’s own caution. Consider machine learning techniques to build an understanding of your network activity baselines.
Proactive Threat Monitoring
Watch for scanning that precedes exploitation by minutes, not months. QTFY’s model is to fingerprint at scale and then exploit the moment a new vulnerability lands. Correlate low-signal probe traffic against your newly-disclosed-CVE exposure list rather than dismissing it as background noise.
Baseline and alert on commercial proxy and VPN egress. QTRouter deliberately blends into Fastlink and other commercial proxy services and Alibaba Cloud IPs. Anomalous authentication from a commercial proxy range is a stronger signal than the IP’s reputation alone.
Monitor your own IoT and SOHO estate as attacker infrastructure, not just as attack surface. QTFY enrolls compromised IoT devices, MikroTik RouterOS devices, and PPTP devices as obfuscation nodes. Look for outbound proxy behavior, SOCKS5 listeners, and unexpected OpenWrt or Clash artifacts on network devices.
Hunt for web shells on internet-facing web servers, with particular attention to CMS installations and recently patched edge appliances.
Flag authentication from geographically implausible but locally-sourced IPs. The point of QTRouter is to make traffic appear to originate from a legitimate nearby user—so proximity alone should not confer trust.
Stay Ahead with SafeBreach
For a complete view of your security gaps against QTFY attacks, sign into SafeBreach and run the latest simulations mapped to JCSA-20260826-01. In addition to testing your defenses against remote exploitation of Log4Shell and outbound communication with QTFY infrastructure, you can go a step further with SafeBreach Propagate.
Propagate enables you to assess how attackers could pivot across your environment post-compromise—mapping high-risk attack paths, visualizing lateral movement, and prioritizing remediation efforts based on exposure to your most critical assets. Given that QTFY’s stated persistence model relies on legitimate credentials harvested from compromised systems and on pivoting in from compromised devices nearby, understanding where an initial foothold could lead matters as much as closing the foothold itself. Find out more SafeBreach Propagate .
Frequently Asked Questions
JCSA-20260826-01 is a joint Cybersecurity Advisory released on August 26, 2026 by the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Cyber National Mission Force (CNMF). Note that CISA is not an authoring agency on this advisory. It warns of ongoing activity by the China-linked hacking group QTFY, which built malicious distributed platforms to compromise US and foreign organizations across the defense industrial base, communications, government, energy, information technology, water and wastewater systems, and higher education.
QTFY operates three purpose-built products. QScan is a distributed vulnerability scanning and exploitation platform that processed over two million scanning and penetration testing tasks in a single day in 2024, drawing on a database of more than 200 proof-of-concept Python exploits. QTRouter is a traffic obfuscation network running on compromised OpenWrt routers, commercial proxy IP addresses, and IoT devices. Three further botnet platforms enroll compromised IoT devices as proxy nodes and can launch DDoS attacks.
The activity is attributed to QTFY, also tracked as QT and QTCYBER, and linked to Nanjing Xinjiuwei Network Technology Co. (XJW), a PRC cyber-enabling company established in 2018. XJW holds business relationships with PRC Ministry of State Security units, and QTFY actors include former People’s Liberation Army members who leverage their contacts to win contracts targeting critical infrastructure. The group also buys and sells exploits and victim network access through China-based freelance brokering networks.
The advisory attributes fourteen CVEs to QTFY between 2018 and 2026, concentrated in internet-facing edge and remote-access products. They include Pulse Secure ( CVE-2019-11510 ), Citrix ADC ( CVE-2019-19781 ), Microsoft Exchange ProxyLogon ( CVE-2021-26855 ), Log4Shell ( CVE-2021-44228 ), Atlassian Confluence ( CVE-2023-22515 ), Check Point Quantum Gateway ( CVE-2024-24919 ), three Ivanti Cloud Services Appliance zero-days, CrushFTP ( CVE-2025-31161 ), and most recently BeyondTrust Remote Support ( CVE-2026-1731 ) in February 2026.
Not without vetting them first. The authoring agencies explicitly recommend that organizations investigate or vet the listed IP addresses prior to taking action such as blocking. Several indicators trace to QTFY activity as early as 2017, and QTRouter deliberately mixes malicious traffic with legitimate traffic on commercial proxy services and Alibaba Cloud IP addresses. Blocking without vetting carries a real risk of collateral impact on legitimate users.
SafeBreach customers can validate their defenses three ways: the SafeBreach Scenarios page filtered by JCSA-20260826-01, the Attack Playbook filtered by the same code, or the Known Threats Series report. Nine attacks are mapped to the advisory: simulation #6861 for remote exploitation of Log4Shell (CVE-2021-44228), and eight new IOC-based simulations, #11800 through #11807, that test whether controls detect and block ICMP communication with QScan, QTRouter, Proxy Platform Management, and Proxy Pool Management System infrastructure, and HTTP communication with QScan, QTRouter, Proxy Platform Management, and additional QTFY domains.
You Might Also Be Interested In
Countering Chinese State- Espionage Campaigns: SafeBreach Coverage for CISA Advisory AA25-239A
SafeBreach Exposure Validation Platform
China State- Cyber Threat Actors: A Comprehensive Guide
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
