F5
China-Linked QTFY Group Targets Critical Infrastructure with Malicious Tools
Article Content
The Joint Cybersecurity Advisory JCSA-20260826-01, issued on August 26, 2026, by the FBI, NSA, and CNMF, warns of ongoing operations by the China-linked hacking group QTFY. Active since 2018, QTFY exploits vulnerabilities in critical infrastructure, government, and defense sectors globally. Their attack methods include using QScan for high-volume vulnerability scanning and QTRouter for obfuscating malicious traffic through compromised devices. Key vulnerabilities exploited by QTFY include Log4Shell (CVE-2021-44228), Ivanti zero-days (CVE-2024-8190, CVE-2024-8963), and BeyondTrust Remote Support (CVE-2026-1731). The advisory emphasizes the urgent need for organizations to patch affected systems and carefully vet indicators of compromise to avoid collateral damage. The group is associated with Nanjing Xinjiuwei Network Technology Co. and has targeted over 300 organizations worldwide in previous campaigns. Current operations are ongoing, with an emphasis on the urgency of the threat.
Key Points: • QTFY exploits critical vulnerabilities in infrastructure and government sectors. • Key CVEs include Log4Shell and multiple Ivanti zero-days. • Organizations must urgently patch systems and vet indicators to prevent exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.