China-Linked QTFY Group Targets Critical Infrastructure with Malicious Tools

China-Linked QTFY Group Targets Critical Infrastructure with Malicious Tools

First seen 1 Sep 2026, 18:32 UTC www.safebreach.comsploitus.comF5securityonline.info 81.0

Article Content

Browse articles
ThreatCluster

The Joint Cybersecurity Advisory JCSA-20260826-01, issued on August 26, 2026, by the FBI, NSA, and CNMF, warns of ongoing operations by the China-linked hacking group QTFY. Active since 2018, QTFY exploits vulnerabilities in critical infrastructure, government, and defense sectors globally. Their attack methods include using QScan for high-volume vulnerability scanning and QTRouter for obfuscating malicious traffic through compromised devices. Key vulnerabilities exploited by QTFY include Log4Shell (CVE-2021-44228), Ivanti zero-days (CVE-2024-8190, CVE-2024-8963), and BeyondTrust Remote Support (CVE-2026-1731). The advisory emphasizes the urgent need for organizations to patch affected systems and carefully vet indicators of compromise to avoid collateral damage. The group is associated with Nanjing Xinjiuwei Network Technology Co. and has targeted over 300 organizations worldwide in previous campaigns. Current operations are ongoing, with an emphasis on the urgency of the threat.

Key Points: • QTFY exploits critical vulnerabilities in infrastructure and government sectors. • Key CVEs include Log4Shell and multiple Ivanti zero-days. • Organizations must urgently patch systems and vet indicators to prevent exploitation.

Timeline

2019-03-26
CVE-2019-10068 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-05-08
CVE-2019-11510 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-06-04
CVE-2018-13379 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-12-27
CVE-2019-19781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-01
CVE-2020-5902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-10
CVE-2021-44228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-20
CVE-2023-27350 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-04
CVE-2023-22515 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-28
CVE-2024-24919 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE