Find notable cyber news and cases, enriched with sources, timelines, and signals.

QTFY's freelance PRC hacker-network and cyber-contracting ecosystem

Threat Actor Meta
First reported
Last updated
Happening score
H score 40
2 unique sources, 2 articles

Summary

Hide ▲

QTFY is a PRC-affiliated threat actor tied to freelance hacker networks and malicious cyber contracting that support reconnaissance, proxy management, and operational routing for espionage activity. The FBI said the group, also tracked as QT and QTCYBER, uses that ecosystem and is tied to Nanjing Xinjiuwei Network Technology Co., an enabling company for PRC-linked cyber operations. The activity is linked to QScan and QTRouter, and the reporting says the group has been active since 2018. A related DoJ correction says several U.S. agencies, including NASA, were targets of QTFY rather than confirmed victims, while the FBI disrupted related domains and the reporting cites an attempted 2019 break-in to NASA via CVE-2019-11510 against Pulse Secure VPN.

Related Happenings

QTFY US government and critical infrastructure targeting campaign

Campaign
H score40 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors.

About this happening: The QTFY campaign is a Chinese targeting activity against U.S. government and critical infrastructure systems, with reported focus on defense industrial base,...

FBI urgent mitigation advisory for QTFY

Advisory/Mitigation
H score39 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

How related: US government and critical infrastructure entities have been advised to take urgent action to mitigate the threat from QTFY.

About this happening: The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...

The “quartermaster” alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score31 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: The “quartermaster” has industrialized Operational Relay Box (ORB) networks for China-linked espionage operators, expanding stealthy routing and proxy management at sc...

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
H score62 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign
H score45 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...

Timeline

  1. 27.08.2026 03:00 3 articles · 14d ago

    FBI links QTFY to freelance PRC hacker networks

    Initial Disclosure

    The FBI advisory published on August 26 says QTFY, also tracked as QT and QTCYBER, participates in freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces, a support model that helps the group obtain new exploits and attack techniques and is tied to Nanjing Xinjiuwei Network Technology Co., an enabling company for PRC-linked cyber operations.

    Show sources