China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits

China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits

First seen 1 Sep 2026, 18:32 UTC www.safebreach.comsploitus.comCsoonlineF5Cpomagazine+2 80.8

Article Content

Browse articles
ThreatCluster

The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical infrastructure, including government and defense sectors. The group utilizes a database of over 200 exploits, targeting known vulnerabilities such as Log4Shell (CVE-2021-44228) and several Ivanti and BeyondTrust flaws. Recent operations have led to significant data exfiltration from over 300 organizations globally. The FBI and NSA emphasize the urgency of the threat, advising immediate patching of affected systems. The advisory also warns against blocking unvetted indicators due to potential collateral disruption. QTFY's tactics include using compromised IoT devices as proxy nodes, complicating detection efforts.

Key Points: • QTFY exploits critical vulnerabilities in infrastructure using advanced tools. • Targets include government agencies and critical sectors worldwide. • Immediate patching of affected systems is crucial to mitigate risks.

Ask AI about this cluster

Timeline

2019-03-26
CVE-2019-10068 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-05-08
CVE-2019-11510 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-06-04
CVE-2018-13379 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-12-27
CVE-2019-19781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-01
CVE-2020-5902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-10
CVE-2021-44228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-20
CVE-2023-27350 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-04
CVE-2023-22515 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-28
CVE-2024-24919 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE