Actor Profile

QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People's Liberation Army (PLA) as customers. QTFY operates sophisticated hacking platforms QScan and QTRouter to conduct cyber espionage operations against critical infrastructure and sensitive networks globally, with primary focus on U.S. targets including NASA, Federal Reserve, Department of Energy, DoJ, HHS, NIH, and U.S. Senate. Their motivation centers on intelligence collection from government agencies, critical infrastructure, and research communities, particularly targeting academia due to the collaborative nature of advanced science.

TTPs (Tactics, Techniques, Procedures)

QTFY employs a multi-stage attack cycle: (1) Reconnaissance using QScan to scan and automatically infect IoT devices worldwide and identify vulnerabilities in victim networks (T1595.002: Vulnerability Scanning); (2) Initial Access via exploitation of zero-day vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380 in Ivanti CSA) and N-day vulnerabilities across multiple platforms including Fortinet SSL-VPN (CVE-2018-13379), Citrix ADC (CVE-2019-19781), Microsoft Exchange (CVE-2021-26855), F5 BIG-IP (CVE-2020-5902), Apache Log4j (CVE-2021-44228), Atlassian Confluence (CVE-2023-22515), Check Point Quantum Gateway (CVE-2024-24919), CrushFTP (CVE-2025-31161), and BeyondTrust Remote Support (CVE-2026-1731) (T1190: Exploit Public-Facing Application); (3) Persistence establishment using remote access trojans, web shells, and legitimate credentials (T1505.003: Web Shell, T1078: Valid Accounts); (4) Command and Control via QTRouter obfuscation network utilizing Clash proxy connections, compromised IoT devices, commercial proxy services, and leased VPSs to blend malicious traffic with legitimate traffic and evade detection (T1090: Proxy, T1090.003: Multi-hop Proxy). The infrastructure includes DDoS capabilities and operates as a decentralized operational relay box (ORB) mesh with rotating IPs.

Targets & Patterns

QTFY targets critical infrastructure and sensitive networks throughout the western world with particular emphasis on U.S. government agencies and research institutions. Confirmed victims include NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and U.S. Senate. The actor demonstrates strong preference for targeting academia and research communities, exploiting the collaborative and open nature of advanced scientific research. Geographic targeting spans the United States and western nations. The targeting pattern suggests intelligence collection objectives aligned with Chinese state interests in government operations, critical infrastructure capabilities, cutting-edge research, and sensitive technological developments. The actor's focus on research communities indicates interest in intellectual property theft and monitoring scientific collaboration networks.

Historical Context

QTFY has maintained continuous operations since May 2018, tracked by Lumen Black Lotus Labs for over 18 months prior to the August 2026 disruption. The FBI began collaborating with Lumen approximately one year before the takedown. The group's infrastructure evolved into a sophisticated distributed architecture comprising QScan (scanning and infection platform), QTRouter (traffic obfuscation network), Fast Labyrinth (operational layer incorporating commercial proxy infrastructure like Fastlink), and QTProxy (management layer). The platforms utilized hard-coded command-and-control domains including qt-proxy[.]org, mq-task.qt-team[.]com (later mq-task.qt-proxy[.]org), mq-result.qt-team[.]com (later mq-result.qt-proxy[.]org), www.qtproxy[.]xyz, and securelink.qtproxy[.]xyz. The court-authorized domain seizures in August 2026 caused both QScan and QTRouter operations to cease due to hard-coded domain dependencies.

Defensive Recommendations

  • Prioritize patching of vulnerabilities exploited by QTFY: CVE-2024-8190, CVE-2024-8963, CVE-2024-9380 (Ivanti CSA), CVE-2018-13379 (Fortinet), CVE-2019-19781 (Citrix), CVE-2021-26855 (Exchange), CVE-2020-5902 (F5), CVE-2021-44228 (Log4j), CVE-2023-22515 (Confluence), CVE-2024-24919 (Check Point), CVE-2025-31161 (CrushFTP), CVE-2026-1731 (BeyondTrust)
  • Monitor for web shell deployment and suspicious authentication patterns on internet-facing appliances (T1505.003, T1078); hunt for persistence mechanisms including RATs and unauthorized credential usage in VPN, email gateway, and collaboration platforms
  • Implement network traffic analysis to detect multi-hop proxy chains and anomalous geolocation patterns (T1090.003); flag connections originating from IoT devices or residential IPs accessing sensitive internal resources
  • Block known QTFY infrastructure domains and IPs: qt-proxy[.]org, mq-task.qt-proxy[.]org, mq-result.qt-proxy[.]org, www.qtproxy[.]xyz, securelink.qtproxy[.]xyz, fastlink.ws; monitor for DNS queries to these indicators
  • Segment IoT devices from corporate networks and implement strict egress filtering; monitor IoT devices for signs of compromise including unexpected outbound connections, scanning activity, or installation of custom firmware like OpenWrt with Clash proxy software

---

# Geopolitical Context

Geopolitical Context

The disruption of QScan and QTRouter platforms represents a significant U.S. law enforcement action against Chinese cyber espionage infrastructure. The operation targeted tools attributed to QTFY, a threat actor employed by Nanjing Xinjiuwei Network Technology Company, which reportedly serves both China's Ministry of State Security (MSS) and People's Liberation Army (PLA). The victim set—including NASA, Federal Reserve, Department of Energy, Department of Justice, and U.S. Senate—indicates systematic targeting of U.S. government institutions and critical infrastructure. The global scope of targeting, particularly against Western academic and research institutions, reflects broader strategic intelligence collection priorities consistent with China's national technology development goals. The FBI's public attribution and technical disclosure signal a continued U.S. policy of imposing costs on state-sponsored cyber operations through disruption and exposure, following the pattern established in previous operations against Chinese APT infrastructure.

State Actor Alignment

QTFY is attributed to Nanjing Xinjiuwei Network Technology Company, which the U.S. Department of Justice assesses operates on behalf of Chinese state sponsors. According to the disclosure, Nanjing's client base includes China's Ministry of State Security (MSS) and the People's Liberation Army (PLA), indicating direct linkage to Chinese state intelligence and military apparatus. The infrastructure facilitated obfuscation for multiple Chinese cyber actors, suggesting it functioned as shared operational infrastructure for state-directed campaigns. The U.S. response—court-authorized domain seizures and public attribution—reflects escalating willingness to name Chinese state entities and disrupt their cyber capabilities. No sanctions against Nanjing Xinjiuwei or associated individuals were announced in the provided reporting, though the action aligns with the U.S. strategy of disrupting adversary infrastructure and publicly attributing malicious cyber activity to impose reputational and operational costs.

Business Impacty pro region

The targeting extended throughout the Western world, with particular emphasis on academic and research communities in the United States and allied nations. The compromise of U.S. federal agencies—including those managing critical infrastructure, financial systems, and national security functions—underscores the breadth of Chinese intelligence collection against U.S. government networks. The global botnet infrastructure, comprising compromised IoT devices worldwide and commercial proxy services, demonstrates the transnational nature of the threat and the challenge for defenders in attributing malicious traffic. For European and allied governments, the disclosure highlights shared vulnerability to Chinese state-sponsored operations leveraging zero-day and N-day exploits against widely deployed enterprise technologies (Fortinet, Citrix, Microsoft Exchange, F5, Check Point, Atlassian, etc.). The emphasis on targeting research institutions may prompt increased security scrutiny of international academic collaboration, particularly in advanced science and technology fields where China seeks strategic advantage.

Forecast

If the domain seizures successfully disrupted hardcoded command infrastructure as reported, QTFY and affiliated actors will likely require time to rebuild operational relay networks, temporarily degrading their obfuscation capabilities. However, given the actor's operational history since 2018 and state backing, reconstitution of similar infrastructure under new domains and architectures is probable within months. Chinese state-sponsored groups may accelerate adoption of more resilient command-and-control mechanisms, including decentralized or blockchain-based systems, to reduce vulnerability to future takedowns. If the U.S. continues public attribution and disruption operations, Beijing may recalibrate operational security practices or shift to alternative digital quartermaster providers, though strategic intelligence collection against Western critical infrastructure and research institutions is unlikely to diminish. Allied governments may leverage the technical indicators disclosed to hunt for related activity in their networks, potentially uncovering additional compromises. The disclosed exploitation of multiple zero-day vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) in Ivanti CSA appliances suggests QTFY retains access to previously unknown vulnerabilities, and defenders should anticipate continued use of such capabilities against high-value targets.