Nation-State

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.

China - US cybersecurity

The US government announced on Wednesday that it has disrupted a hacking platform and botnet used by Chinese threat actors in attacks aimed at military and critical infrastructure systems.

According to the Justice Department, the disruption efforts targeted a state-sponsored group called QTFY, which has been operating from a company called Nanjing Xinjiuwei Network Technology.

QTFY has offered its hacking services to the Chinese government and others, enabling attacks against many critical systems in the United States since its establishment in 2018. 

Disruption of QTFY hacking platform

The US government has targeted two hacking services offered by QTFY: the scanning and exploitation platform QScan, and the obfuscation network QTRouter. 

QScan is designed to scan the internet for vulnerable IoT devices and ensnare them in the QTRouter botnet, enabling threat actors to abuse the compromised devices to conceal their malicious activities and evade detection.

US authorities identified and seized domains used by QScan and QTRouter.

Advertisement. Scroll to continue reading.

“Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable,” explained the Justice Department.

QTFY attacks and exploitation

A technical cybersecurity advisory published on Wednesday by the FBI reveals that QTFY has been developing malicious tools, trading malware and exploits, and maintaining botnets to carry out its attacks.

Targeted sectors include the defense industrial base, local government, telecoms, and higher education. 

The agency said some of the group’s attempts to hack sensitive networks were unsuccessful, including attacks aimed at the Department of Energy, election systems, the Department of Health and Human Services, the US Senate, a children’s hospital, a semiconductor company, and a power company.

Other attacks appear to have been successful at least to some extent, including against NASA, the Justice Department, the Federal Reserve, the Department of Energy, state governments, a major retailer, a telecoms company, defense contractors, universities, and financial institutions. 

The hackers have been observed exploiting vulnerabilities in products from BeyondTrust, CrushFTP, Ivanti, Check Point, Atlassian, Kentico, F5, Microsoft, Citrix, Fortinet, and Pulse Secure. 

“QTFY actors are active in the exploit development community, freelance PRC [People’s Republic of China] hacker networks, and PRC malicious cyber contracting and subcontracting marketplaces,” the FBI noted. “QTFY participates in the offensive end of network attack and defense events against Chinese critical infrastructure.”

The FBI also pointed out that the company behind QTFY has had business relationships with various entities connected to the Salt Typhoon cyberespionage group, the i-Soon cyber intrusion firm, and several others.

Related: Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown

Related: GlassWorm Botnet Disrupted

Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested

Related Content

Artificial Intelligence

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

Artificial Intelligence

AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.

Supply Chain Security

The agency said imports of advanced robots pose cybersecurity and other national security risks.

ICS/OT

State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.

Cybercrime

The company disconnected its systems on July 13 and is starting to gradually restore operations.

Government

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.

Cyberwarfare

Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.

Network Security

Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version