Contained High impact Espionage Checked 3d ago

FBI seizes China-linked QTFY hacking platforms

The US Justice Department and FBI seized domains behind QScan and QTRouter, two hacking platforms run by a China state-linked group called QTFY. Officials say the group scanned for vulnerable systems and used hijacked routers and cameras to hide its tracks while targeting NASA, the Justice Department, the Federal Reserve, the Senate, power and telecom companies, hospitals, and defense contractors. On August 28 the DOJ corrected its initial announcement, clarifying that most of those named organizations were targets rather than confirmed victims; the confirmed breaches were three Energy Department labs, the NIH, an HHS agency and a security device maker, and a separate attempt against NASA reportedly failed.

Started
May 1, 2024
Latest activity
Sep 1, 2026
Attributed to
QTFY (China state-linked)Confirmed
Where
United States
Sectors
Government, Energy, Healthcare, Telecom, Defence, Finance +1
Scale
More than 300 organizations in the US and abroad. The DOJ's August 28 correction clarified that NASA, the Federal Reserve, the Senate

Current status

As of September 8, no credible source has reported new QTFY activity, new victims, or the return of QScan and QTRouter since the September 1 update.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

FBI San Diego officials additionally named the Nanjing-based company behind the platforms as Nanjing Xinjiuwei Network Technology Co., which they say provided hacking services to Chinese intelligence and military organizations.

Impact

Confirmed data theft and intrusions at three Energy Department national laboratories, the NIH, an HHS agency and a US security device manufacturer in September 2024. NASA, the Federal Reserve, the Senate, the Justice Department and other federal agencies were targeted over a multi-year campaign but the DOJ's own affidavit says only some were actually compromised; the attempted NASA breach reportedly failed because the software involved was already patched. Attempted intrusions into Senate, hospital and election systems in 2026 reportedly failed.

What to do

Organizations in critical infrastructure and defense should watch for advisories from CISA, the FBI and NSA about QTFY indicators of compromise.

Timeline

  1. Sep 1, 2026

    Recapping the case, FBI San Diego and DOJ officials, including US Attorney General Todd Blanche, reiterated that the seized QScan and QTRouter platforms were run through Nanjing Xinjiuwei Network Technology Co. to provide hacking services to Chinese intelligence and military organizations; no new victims or platform restoration were reported.

    Containedtimesofsandiego.com
  2. Aug 28, 2026

    The Justice Department issued a corrected press release acknowledging its August 26 statement wrongly described all named agencies as hacking victims; the underlying court affidavit shows the agencies were targeted but only some, including three DOE national laboratories, the NIH, an HHS agency and a security device manufacturer, were confirmed breached. A footnote in the affidavit says the attempted NASA intrusion failed because the targeted software had already been patched.

    Containedyahoo.com
  3. Aug 27, 2026

    The FBI and NSA published a joint cybersecurity advisory with indicators of compromise for QTFY, based on analysis of the group's malicious cyber activity.

    Containedhstoday.us
  4. Aug 27, 2026

    Chinese Foreign Ministry spokesperson Lin Jian rejected the US accusation at a press briefing, calling it a disinformation campaign and pointing to China's own earlier allegation of a US NSA cyberattack on its National Time Service Center.

    Containedoutlookindia.com
  5. Aug 26, 2026

    The Justice Department and FBI seized three domains that powered the QScan and QTRouter platforms, publicly attributing the operation to QTFY and a Nanjing-based company.

    Containedmedia.defense.gov
  6. Jun 1, 2026

    QTFY scanned a US election system in June but reportedly failed to gain access.

    Activefoxnews.com
  7. Mar 1, 2026

    A National Mission Force advisory said QTFY scanned Senate and hospital-system networks in March but failed to gain access.

    Activefoxnews.com
  8. May 1, 2024

    QTFY exploited a recently disclosed Check Point vulnerability while scanning US power and telecommunications companies and began stealing data from organizations in the US and abroad.

    Activefoxnews.com

Sources

Related reports