Actor Profile

QTFY (also known as QT AND QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co. Evidence of payments from China's Ministry of State Security (MSS) indicates the company conducts malicious cyber activities for Beijing. QTFY functions as a technical quartermaster, providing reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage operations. The group has industrialized the creation of Operational Relay Box (ORB) networks and sells access to its tools (QScan and QTRouter) to other threat actors.

TTPs (Tactics, Techniques, Procedures)

QTFY employs vulnerability scanning and exploitation via QScan platform, notably exploiting CVE-2019-11510 (Pulse Secure VPN) to target NASA in 2019. The group operates QTRouter, an obfuscation network that creates decentralized botnets of compromised IoT devices and leased VPS infrastructure. They route malicious traffic through IoT devices local to victims to blend with legitimate network activity, supporting the Fast Labyrinth encrypted relay network. Key techniques include initial access via VPN exploitation, command and control through compromised IoT infrastructure, and defense evasion through proxy networks that obscure attribution.

Targets & Patterns

QTFY targets critical infrastructure and sensitive networks in the United States and internationally. Primary targets include U.S. federal government agencies (NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, U.S. Senate), hospitals, telecommunications operators, power companies, financial institutions, and defense contractors. The targeting pattern reflects strategic intelligence collection priorities aligned with Chinese state interests, focusing on government, defense, energy, healthcare, and financial sectors. The DoJ clarified these entities were targeted rather than confirmed as successfully breached.

Historical Context

QTFY has been active since 2018, conducting sustained cyber espionage operations on behalf of the Chinese government. A documented 2019 campaign attempted to breach NASA by exploiting CVE-2019-11510 in Pulse Secure VPN. In August 2026, the FBI disrupted QTFY infrastructure by seizing domains associated with QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com). Lumen Black Lotus Labs research revealed the group's industrialized approach to building ORB networks, demonstrating evolution from traditional APT operations to a commercialized model where tools and access are sold to other Chinese threat actors.

Defensive Recommendations

  • Monitor for exploitation attempts against CVE-2019-11510 and other VPN vulnerabilities; implement virtual patching if immediate patching is not feasible
  • Detect anomalous traffic patterns from IoT devices, particularly outbound connections to unfamiliar destinations or proxy services; segment IoT devices from critical networks
  • Block known QTFY infrastructure including qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com, and fastlink[.]ws; monitor for similar domain registration patterns
  • Implement network behavior analysis to identify traffic routing through multiple proxies or relay boxes characteristic of Fast Labyrinth encrypted relay network
  • Harden IoT device security by changing default credentials, disabling unnecessary services, and applying firmware updates to prevent botnet enrollment

---

# Geopolitical Context

Geopolitical Context

The U.S. Department of Justice's correction of its initial statement regarding Chinese threat actor activity reflects the sensitivity of attributing successful cyber intrusions to state-linked actors. The revised language—shifting from "victims" to "targets"—suggests that while QTFY, a group linked to Nanjing Xinjiuwei Network Technology Co. and allegedly operating on behalf of China's Ministry of State Security, conducted reconnaissance and exploitation attempts against high-value U.S. federal networks (NASA, Federal Reserve, Department of Energy, DoJ, HHS, NIH, and U.S. Senate), the extent of actual compromise remains unclear or limited. This distinction is significant in the context of U.S.-China strategic competition, as it modulates the narrative around Beijing's cyber espionage capabilities and the resilience of American critical infrastructure defenses. The FBI's disruption of QTFY infrastructure and the public disclosure of tools like QScan and QTRouter signal continued U.S. efforts to impose costs on PRC-linked cyber operations while managing escalation risks.

State Actor Alignment

QTFY is attributed to Nanjing Xinjiuwei Network Technology Co., a private Chinese firm that appears to conduct cyber operations on behalf of the Ministry of State Security (MSS), according to DoJ affidavit evidence citing payments from MSS to the company. The group has been active since at least 2018 and is characterized as a "technical quartermaster" providing reconnaissance, proxy management, and operational routing capabilities to support broader Chinese state-sponsored cyber espionage campaigns. The FBI has seized domains associated with QTFY's QScan and QTRouter infrastructure, consistent with U.S. policy to disrupt PRC-linked cyber threat actors through law enforcement and judicial mechanisms. The targeting of U.S. federal agencies, defense contractors, financial institutions, and critical infrastructure aligns with long-standing U.S. government assessments of PRC strategic intelligence priorities.

Business Impacty pro region

The corrected DoJ statement has implications for transatlantic and allied cyber defense coordination. QTFY's operations extended beyond U.S. targets to include hospitals, telecommunications operators, power companies, and financial institutions globally, suggesting a broad aperture for PRC-linked espionage that affects European and other allied critical infrastructure. The industrialization of Operational Relay Box (ORB) networks—leveraging compromised IoT devices and commercial VPS infrastructure to obscure attribution—poses a shared challenge for Western intelligence and cybersecurity communities. The FBI's domain seizures and public attribution may encourage parallel enforcement actions or sanctions designations by European and Five Eyes partners. The revelation that QTFY sells access to its tools (QScan, QTRouter) to other actors introduces a proliferation risk, potentially enabling lower-tier threat actors to conduct sophisticated intrusions with state-grade infrastructure. This commodification of cyber espionage capabilities complicates deterrence and response strategies across NATO and Indo-Pacific security architectures.

Forecast

If the U.S. continues to publicly attribute and disrupt PRC-linked cyber infrastructure, Beijing may accelerate operational security improvements and shift to more decentralized or commercially obfuscated tooling, complicating future detection and attribution efforts. Should allied governments coordinate sanctions or indictments against Nanjing Xinjiuwei or MSS-linked entities, China is likely to respond with counter-accusations and potential retaliatory cyber activity targeting Western government or private sector networks. If QTFY or similar actors successfully pivot infrastructure following FBI domain seizures, renewed targeting of U.S. federal agencies and critical infrastructure is probable within the next six to twelve months. The commodification of QTFY's tools may lead to increased exploitation of IoT vulnerabilities by a wider range of actors, necessitating enhanced IoT security standards and coordinated vulnerability disclosure practices among Western governments and industry. If the DoJ's corrected language reflects genuine defensive success in limiting intrusions, it may indicate that U.S. federal network defenses have improved since earlier high-profile compromises, though sustained vigilance and threat hunting will remain essential.