Summary
- A Chinese state-sponsored group known as QTFY compromised multiple US federal agencies — including the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, and the NIH — over an eight-year period.
- QTFY operated through a Chinese front company, Nanjing Xinjiuwei Network Technology Company, and built a comprehensive hacking suite including QScan, a reconnaissance tool with more than 200 proof-of-concept exploits, and QTRouter for traffic concealment.
- The group exploited vulnerabilities in products from at least eleven vendors, including Ivanti, Fortinet, Citrix, BeyondTrust, and Microsoft; three DOE national laboratories were among the targets hit via Ivanti zero-days in September 2024.
- Authorities seized three domains, cutting off access to QTFY’s primary platforms, and released a joint advisory with known indicators of compromise.
- The operation attempted — unsuccessfully — to access a US election system in June and the Senate in March, indicating broad targeting ambitions beyond traditional espionage objectives.
What Was Disrupted
US federal authorities on Wednesday announced the seizure of three domains linked to a long-running Chinese state-sponsored espionage campaign. The action dismantled access to QScan and QTRouter, the two central platforms underpinning a hacking operation attributed to a group designated QTFY. The FBI has been investigating QTFY since at least 2019, though the group’s activity dates to 2018, making this an eight-year-plus operation before disruption.
The Scope of Compromise
The agencies confirmed as compromised read like a map of sensitive US government operations: the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, and the National Institutes of Health. Beyond government, QTFY targeted financial institutions, defence contractors, utility companies, telecommunications providers, and hospitals. The group includes former members of China’s military, according to court records. Attempted intrusions against the Senate and a US election system were ultimately unsuccessful.
The Hacking Suite in Detail
QTFY’s infrastructure was purpose-built for scale and persistence. QScan, the reconnaissance and vulnerability scanning tool, contained more than 200 proof-of-concept exploits. An FBI special agent’s affidavit noted that on a single day in 2024, QScan processed over two million scanning and exploit tasks. QTRouter complemented QScan by providing traffic concealment and rerouting capabilities, while the group also infected IoT devices to build and maintain a botnet. Ryan English, an information security engineer at Lumen Technologies’ Black Lotus Labs — which assisted the disruption — described the operation as having “continuous reconnaissance capabilities and flexibilities designed for specific targets or objectives.”
Vendor Exposure Across the Enterprise Stack
The list of exploited products is significant for any enterprise security team. Authorities identified vulnerabilities targeted in products from Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP, and BeyondTrust. In September 2024, QTFY exploited multiple Ivanti zero-day vulnerabilities to access the networks of three Department of Energy national laboratories, NIH, an HHS agency, and a US-based security device manufacturer. The three seized domains were all used in those specific attacks.
Front Companies as an Emerging Pattern
QTFY operated out of Nanjing Xinjiuwei Network Technology Company, a private Chinese firm described in court documents as a government-funded front. English noted that such arrangements are becoming more common: “Discovery of these private companies building networks for China is becoming more frequent. We’re starting to see that when they’re getting exposed, some of these have been in business a few years before they’re found.” This follows a broader pattern of disruption activity, including a separate early 2025 operation that removed PlugX malware from thousands of US computers.
Regulatory and Law Enforcement Response
The FBI, NSA, and Cyber National Mission Force released a joint cybersecurity advisory alongside Wednesday’s announcement, including known indicators of compromise. The Justice Department also detailed QTFY’s known affiliations with other Chinese state-sponsored hacking groups. Assistant Attorney General John A. Eisenberg stated that the court-authorised seizures “deny People’s Republic of China-linked hackers access to tools they use to mount online attacks against our nation’s critical infrastructure.”
Why it matters
For CISOs, this case reinforces several uncomfortable realities. First, the vendor exposure list covers products that are standard fixtures in enterprise and government environments — if your organisation runs Ivanti, Fortinet, Citrix, BeyondTrust, or Confluence, you have a direct interest in reviewing the joint advisory’s indicators of compromise immediately. Second, the two-million-task-per-day scanning volume means that internet-facing systems in any sector — not just government — are being continuously probed at machine scale. Third, the front-company model used by QTFY is becoming more prevalent, which complicates attribution and may affect how threat intelligence is classified and acted upon. Finally, the eight-year dwell span before public disruption is a reminder that detection timelines, not just prevention, must be central to your security programme.
What to do now
- Review the joint FBI, NSA, and Cyber National Mission Force advisory and apply all listed indicators of compromise to your threat detection tooling.
- Audit your environment for the eleven vendor products identified as exploited — Pulse Secure, Fortinet, Citrix, Microsoft, F5, Kentico CMS, Atlassian Confluence, Ivanti, Check Point, CrushFTP, and BeyondTrust — and confirm patches are current, particularly for Ivanti given the September 2024 zero-day exploitation.
- Review network logs for anomalous scanning activity and traffic rerouting behaviour consistent with QScan and QTRouter indicators.
- Assess IoT device inventory for signs of botnet compromise, given QTFY’s use of IoT infrastructure for traffic concealment.
- Brief your threat intelligence function on the front-company attribution model; ensure your intel sources are tracking Chinese state-linked contractors, not only known APT designations.
