A Chinese hacking operation known as QTFY breached more than 300 organizations across the United States and worldwide in 2024 after exploiting a vulnerability in Check Point Quantum Gateway systems, according to an FBI advisory published August 26 in coordination with the National Security Agency and Cyber National Mission Force. The alert warns that the group has been actively attacking US government agencies and critical infrastructure through a network of specially designed malicious tools. Victims included defense contractors, financial institutions, and universities, while the group also attempted intrusions at the Department of Justice, Federal Reserve, NASA, hospitals, and election systems.

QTFY operates through a custom-built distributed system that allows the group to carry out attacks at scale while evading detection, according to the advisory. The group's scanning platform, named QScan, rapidly locates weaknesses in target networks and takes advantage of vulnerable internet-connected devices. In a single day during 2024, the FBI said QTFY used this tool to complete more than two million scanning and penetration testing operations. The group has also built QTRouter, a traffic concealment network that runs on routers equipped with modified OpenWrt software, and maintains at least three major platforms for managing botnets of hijacked devices. QTFY has operated since 2018, concentrating on the defense industrial base, communications, government, and higher education sectors for nearly ten years.

The FBI noted that these tools "work in conjunction with each other" to enable the group's operations. The advisory attributed QTFY—which also goes by the acronyms QT and QTCYBER—to Nanjing Xinjiuwei Network Technology Co., described as an enabling company for cyber operations linked to the People's Republic of China. According to the alert, QTFY's reconnaissance platform gathers intelligence on victim networks through webpage scraping, TLS certificate collection, subdomain enumeration, and penetration testing, maintaining a large database that allows rapid identification of targets when a new vulnerability emerges. The group participates in freelance hacker networks and malicious cyber contracting marketplaces tied to the PRC, which helps them stay current with new exploits and attack methods, including incorporating AI into their workflows.

The FBI explained that espionage is likely a primary driver behind the attacks, though the advisory didn't specify the group's objectives. Nick Tausek, lead security automation architect at Swimlane, said "military and defense-linked networks are about as sensitive as targets get." Once inside a system, QTFY works to maintain long-term access by deploying remote access trojans and web shells or stealing legitimate login credentials, the advisory said. The QTRouter obfuscation network lets the group connect to victim networks from nearby compromised internet-connected devices, making their traffic appear to come from legitimate users. The FBI revealed that distinctive user agent strings coming from IP addresses in China showed that both QTFY personnel and PRC government personnel used QTRouter. Gabrielle Hempel, security operations strategist at Exabeam, said the group's vulnerability scanning tool gives them "a head start when a new vulnerability emerges" because they may already have a list of exposed systems ready to exploit.

The agencies recommended that government and critical infrastructure organizations apply the latest software and firmware updates, regularly audit web pages and applications for exposed secrets like API keys, proactively hunt for indicators of compromise included in the advisory, isolate critical systems from edge devices, and test security programs against the threat behaviors detailed in the MITRE ATT&CK framework. In a separate announcement on August 26, the Justice Department and FBI said they had successfully disrupted the QScan and QTRouter platforms, denying malicious actors access to the tools. Court documents showed that QTFY offers hacking services including QScan and QTRouter to paying customers, and the law enforcement action represents the latest in a series of court-authorized technical operations against indiscriminate hacking activities by the PRC. The commercial nature of QTFY's infrastructure suggests that defending against state-sponsored threats now requires organizations to anticipate not just centralized campaigns but also diffuse networks of contractors operating with varying levels of oversight. As these ecosystems mature, the line between government intelligence operations and for-hire cyber services will likely continue to blur, complicating attribution and response strategies for both the public and private sectors.