FBI urgent mitigation advisory for QTFY
Advisory/Mitigation
Summary
Hide ▲
Show ▼
The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mission Force on 2026-08-26, responds to an active threat that uses custom malicious platforms to reach targeted networks. QTFY has used zero-day and N-day vulnerabilities, reconnaissance tooling, and traffic-obfuscation infrastructure to support the activity.
Related Happenings
QTFY US government and critical infrastructure targeting campaign
Campaign
H score40
First: 27.08.2026 15:00
Last: 27.08.2026 15:00
Sources 1
How related:
A sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms, the FBI has warned.
About this happening:
The QTFY campaign is a Chinese targeting activity against U.S. government and critical infrastructure systems, with reported focus on defense industrial base,...
QTFY US government and critical infrastructure targeting campaign
CampaignHow related: A sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms, the FBI has warned.
About this happening: The QTFY campaign is a Chinese targeting activity against U.S. government and critical infrastructure systems, with reported focus on defense industrial base,...
QTFY's freelance PRC hacker-network and cyber-contracting ecosystem
Threat Actor Meta
H score40
First: 27.08.2026 15:00
Last: 27.08.2026 15:00
Sources 1
How related:
The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.
About this happening:
QTFY is a PRC-affiliated threat actor tied to freelance hacker networks and malicious cyber contracting that support reconnaissance, proxy management, and operat...
QTFY's freelance PRC hacker-network and cyber-contracting ecosystem
Threat Actor MetaHow related: The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.
About this happening: QTFY is a PRC-affiliated threat actor tied to freelance hacker networks and malicious cyber contracting that support reconnaissance, proxy management, and operat...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementAbout this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
Campaign
H score17
First: 19.08.2026 20:50
Last: 19.08.2026 20:50
Sources 1
About this happening:
The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
CampaignAbout this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
White House NSPM creates NCC cyber-operations program
Public Sector Action
H score31
First: 13.08.2026 16:30
Last: 13.08.2026 16:30
Sources 1
About this happening:
The White House memo now directs the National Coordination Center (NCC) to create a vetting program for private security companies to conduct limited cyber operations...
White House NSPM creates NCC cyber-operations program
Public Sector ActionAbout this happening: The White House memo now directs the National Coordination Center (NCC) to create a vetting program for private security companies to conduct limited cyber operations...
Timeline
-
27.08.2026 15:00 2 articles · 13d ago
FBI warns US government and critical infrastructure about QTFY
Initial DisclosureThe FBI, coordinated with the National Security Agency and Cyber National Mission Force, published an advisory on August 26 warning that QTFY is actively targeting US government and critical infrastructure systems and urging affected entities to take urgent action to mitigate the threat. The advisory says QTFY, also tracked as QT and QTCYBER, is attributed to Nanjing Xinjiuwei Network Technology Co. and uses zero-day and N-day vulnerabilities, QScan reconnaissance, and QTRouter traffic obfuscation.
Show sources
- Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns — www.infosecurity-magazine.com — 27.08.2026 15:00
- Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns — www.infosecurity-magazine.com — 27.08.2026 15:00