← Back to blog

FBI Disrupts Chinese State-Backed Hacking Group Targeting U.S. Infra

The FBI has taken down QScan and QTRouter, hacking tools used by China-linked actors to infiltrate critical U.S. systems. The operation targeted the QTFY group, linked to a Nanjing-based tech firm.

TL;DR

  • U.S. authorities disrupted two hacking platforms, QScan and QTRouter, used by China-linked threat actors.
  • The group behind the attacks, QTFY, is tied to Nanjing Xinjiuwei Network Technology Company.
  • Targets included critical infrastructure and sensitive networks across the United States.
  • This takedown highlights ongoing state-sponsored cyber threats against Western organizations.
  • Organizations should reassess their network defenses and monitor for similar attack patterns.

In a coordinated effort, the U.S. Department of Justice announced the disruption of two hacking platforms, QScan and QTRouter, operated by a Chinese state-sponsored group known as QTFY. These tools were actively used to infiltrate critical infrastructure and sensitive networks within the United States. The operation marks a significant step in countering advanced persistent threats originating from state-backed actors.

The group, identified as QTFY, is reportedly employed by Nanjing Xinjiuwei Network Technology Company, a firm based in China. This attribution underscores the growing concern over nation-state cyber operations aimed at stealing data and compromising national security assets. Security researchers and federal agencies continue to track related malware and tactics to protect vulnerable systems.

Operation Details

  • QScan and QTRouter were used for reconnaissance and routing malicious traffic.
  • The platforms enabled stealthy access to high-value targets in the U.S.
  • FBI-led disruption severed command-and-control communications.

Implications for Defense Teams

  • Organizations should review logs for signs of QTFY-related tool usage.
  • Defensive strategies must evolve to counter state-sponsored APT groups.
  • Proactive threat hunting can help detect similar infrastructures before exploitation.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.