Published by Emerging Technologies Laboratory · via ETL Newswire
Security· 

DOJ Seizes Hacking Platforms as FBI and NSA Warn of China-Linked QTFY Group Targeting U.S. Critical Infrastructure

A joint advisory from the FBI, NSA, and Cyber National Mission Force names QTFY, a PRC-sponsored group operating since 2018, and the Justice Department simultaneously seized two of its primary intrusion platforms.

By Renée Kovac, Correspondent · Security Desk

The Justice Department and FBI moved against a China-linked hacking operation last week, seizing domains tied to two intrusion platforms and releasing a detailed advisory intended to help network defenders spot the group's fingerprints before they do more damage.

The advisory, published September 2 and reviewed by this reporter in its public PDF form on the IC3 and Defense Department websites, names the group as QTFY, also written QT and QTCYBER. According to the joint cybersecurity advisory issued by the FBI, NSA, and Cyber National Mission Force, the group has been operating since at least 2018 and is employed by China-based Nanjing Xinjiuwei Network Technology Company.

The scope of confirmed targets is broad. According to an unsealed Justice Department filing, QTFY's victim list includes NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. On the critical infrastructure side, the advisory identifies the defense industrial base, telecommunications providers, local government networks, and higher education as sectors under active targeting.

The two platforms DOJ seized, called QScan and QTRouter, were not passive surveillance tools. According to the Justice Department press release, they were designed to let operators obfuscate their location while working their way into sensitive networks. The advisory adds that QTFY operators rely on both zero-day flaws and unpatched vulnerabilities to break into victim networks, then harvest valid credentials to maintain long-term access. That's a persistence-focused playbook, not smash-and-grab.

The tradecraft detail that stands out analytically is the freelance dimension. The advisory states that QTFY maintains ties to the broader exploit development community and participates in freelance hacking circles as well as marketplaces where malicious cyber contracting and subcontracting occur. That structure complicates attribution and gives the PRC plausible organizational distance from specific intrusions. It's the same contractor buffer model U.S. agencies have documented with other PRC-linked groups, and it's worth treating the advisory's group attribution with moderate confidence rather than certainty, because the contracting layer introduces noise.

The DOJ framed the seizures as part of a continuing series. In its press release, the department noted that it disabled a Flax Typhoon botnet in 2024, disrupted Volt Typhoon infrastructure in 2023, and removed PlugX malware from over 4,000 U.S. computers in 2025. QTFY is the latest name on a list that keeps growing.

The NIH and HHS appearing on the target list is the detail that sits squarely on this beat. Neither agency confirmed any specific breach in public statements tied to this advisory, and the advisory itself doesn't characterize the depth of access QTFY achieved at any named target. That's an important gap. Listing an organization as a target is not the same as confirming data loss or operational disruption, and the advisory is careful not to conflate the two.

For defenders, the joint advisory includes indicator-of-compromise files in CSV format, covering both network infrastructure and malicious tooling. The authoring agencies recommend isolating critical internal systems from internet-facing edge devices, patching promptly, and auditing public-facing web applications for unintended operational disclosure, the kind of reconnaissance-enabling exposure that groups like this rely on before they ever touch a zero-day.

The CIRCIA final rule, expected from CISA this month, would require covered entities to report incidents like these to the government within 72 hours. Whether that reporting mandate would have changed how quickly QTFY's activity was detected at any of the named federal targets is a question the advisory doesn't answer.

Sources cited:
- Joint Cybersecurity Advisory JCSA-20260826-01 (FBI/NSA/CNMF, via IC3) (https://www.ic3.gov/CSA/2026/260826.pdf)
- Justice Department press release on QScan and QTRouter domain seizures (https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers)
- NSA press release on QTFY advisory (https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4583539/nsa-joins-fbi-in-issuing-warning-about-chinese-hacking-group-qtfy-cyber-activity/)
- Intelligence Community News: NSA and FBI issue warning about QTFY (https://intelligencecommunitynews.com/nsa-and-fbi-issue-warning-about-chinese-hacking-group-qtfy/)
- ExecutiveGov: FBI Issues Warning, Seizes Tools Owned by QTFY Hacking Group (https://www.executivegov.com/articles/fbi-nsa-doj-qtfy-hackers)
- Federal News Network: CIRCIA final rule expected September 2026 (https://federalnewsnetwork.com/cybersecurity/2026/07/circia-other-big-cyber-rules-expected-to-get-finalized-this-fall/)

Reporting by Renée Kovac, Correspondent, for the Security desk · ETL Newswire staff
Read more at the source

This release was originally distributed via ETL Newswire. Visit Joint Cybersecurity Advisory JCSA-20260826-01 (FBI/NSA/CNMF, via IC3) for the full story, related releases, and contact information.

Visit Joint Cybersecurity Advisory JCSA-20260826-01 (FBI/NSA/CNMF, via IC3) →