Find notable cyber news and cases, enriched with sources, timelines, and signals.

QTFY US government and critical infrastructure targeting campaign

Campaign
First reported
Last updated
Happening score
H score 40
2 unique sources, 2 articles

Summary

Hide ▲

The QTFY campaign is a Chinese targeting activity against U.S. government and critical infrastructure systems, with reported focus on defense industrial base, communications, government, and higher education targets since 2018. The FBI, with the NSA and Cyber National Mission Force, said QTFY used QScan for reconnaissance and exploitation and QTRouter to route traffic through compromised IoT devices and custom OpenWrt systems. In 2024, the group exfiltrated data from over 300 organizations by exploiting a Check Point Quantum Gateway vulnerability. The U.S. Department of Justice later corrected a prior statement to say several agencies, including NASA, were targets of QTFY rather than confirmed victims, and the affidavit-linked reporting says the group attempted to break into NASA in 2019 by exploiting CVE-2019-11510 against Pulse Secure VPN.

Related Happenings

FBI urgent mitigation advisory for QTFY

Advisory/Mitigation
H score39 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: US government and critical infrastructure entities have been advised to take urgent action to mitigate the threat from QTFY.

About this happening: The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...

QTFY's freelance PRC hacker-network and cyber-contracting ecosystem

Threat Actor Meta
H score40 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: The threat actors also participate in a range of freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces.

About this happening: QTFY is a PRC-affiliated threat actor tied to freelance hacker networks and malicious cyber contracting that support reconnaissance, proxy management, and operat...

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
H score33 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

German draft legislation expanding intelligence hack-back powers

Public Sector Action
H score32 First: 14.08.2026 12:38 Last: 14.08.2026 12:38 Sources 1

About this happening: Germany approved draft legislation that expands foreign and domestic intelligence agencies’ cyber powers, giving them new authority to dismantle hostile servers and disr...

Timeline

  1. 26.08.2026 03:00 3 articles · 15d ago

    FBI warns QTFY is targeting US government and critical infrastructure

    Initial Disclosure

    The FBI, in coordination with the National Security Agency and Cyber National Mission Force on August 26, warned that QTFY, also tracked as QT and QTCYBER, is targeting US government and critical infrastructure systems with custom-built malicious platforms. The group has focused on defense industrial base, communications, government, and higher education targets since being established in 2018, and in 2024 it exfiltrated data from over 300 organizations by exploiting a Check Point Quantum Gateway vulnerability. The FBI also attributed QTFY to Nanjing Xinjiuwei Network Technology Co., and described QScan for reconnaissance and exploitation and QTRouter for traffic obfuscation through compromised IoT devices running custom OpenWrt software.

    Show sources