Security1 distinct publisher3 min readPublished
The August 26 advisory, written with the NSA and Cyber National Mission Force, describes QTFY running its own scanning, proxying and botnet platforms since 2018. Commodity indicator feeds will not find it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The detection problem sits in the sequencing. QScan keeps a standing database of scraped webpages, collected TLS certificates and enumerated subdomains, so when a new vulnerability drops the target list already exists [9][10]. Scanning is not the reconnaissance step here; it is the follow-through. The FBI puts QScan at more than two million scanning and penetration testing tasks in a single day during 2024 [7]. Spread across 86,400 seconds, that is roughly 23 tasks per second, sustained for a day [8].
Volume like that only works if it arrives from somewhere unremarkable. QTRouter is the layer that provides it: a traffic obfuscation network running on devices including routers loaded with custom OpenWrt software [11], fed by botnet products that fold compromised IoT devices into proxy nodes [12], with at least three major platforms managing those botnets [13]. The last hop into a victim network comes from a compromised device near the victim, blending with legitimate users [14]. Gabrielle Hempel of Exabeam described the result as an ecosystem designed to make malicious activity look geographically and operationally ordinary [15].
One line in the advisory goes past tradecraft. The FBI says unique user agent strings originating from IP addresses in China indicated QTRouter was used by QTFY personnel and by PRC government personnel [16]. Contractor and state operators on the same proxy fabric.
The entry point of record is an appliance. In 2024 the group exfiltrated data from more than 300 organisations in the US and globally after using an exploit for a Check Point Quantum Gateway vulnerability, with US defense contractors, financial institutions and universities among the victims [4]. The Infosecurity account of the advisory names the product but no CVE [17], which leaves anyone doing an audit matching on a product, not on a patch level. Post-access, the group holds ground with remote access trojans, web shells and legitimate credentials [18]. That last item sets the remediation scope: the appliance is the door, the credentials that passed through it are the residue.
QTFY was established in 2018 and has worked the defense industrial base, communications, government and higher education for close to a decade [3]; six years separate that start from the 2024 Check Point campaign [25]. The FBI attributes the group, which also uses the acronyms QT and QTCYBER, to Nanjing Xinjiuwei Network Technology Co., an enabling company for PRC-linked cyber operations [20]. It says the group works freelance PRC hacker networks and contracting and subcontracting marketplaces to keep pace with new exploits and techniques, including AI integration [22], and concentrates on zero-day and N-day flaws for initial access [21].
Named targets include the Department of Justice, the Federal Reserve and NASA [5], with attempts against hospitals and election systems [6]. The advisory did not state the group's aims; Infosecurity assesses espionage as the likely motivation [19]. Nick Tausek of Swimlane noted that even limited access to defense-linked networks yields intelligence useful well beyond the organisation first breached [23]. For anyone who ran a Quantum Gateway at the border in 2024, the auditable question is which credentials transited it.
Ranked by verification strength, evidence, and original report placement.
The FBI warned that a Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms.
The FBI advisory was published in coordination with the National Security Agency and Cyber National Mission Force on August 26.
QTFY has focused on critical infrastructure sectors including the defense industrial base, communications, government and higher education for close to a decade since being established in 2018.
In 2024 QTFY exfiltrated data from over 300 organizations in the US and globally after leveraging an exploit for a Check Point Quantum Gateway vulnerability; victims included US defense contractors, financial institutions and universities.
Other entities targeted by the group include the US Department of Justice, the US Federal Reserve and NASA.
Attempts have been made by the group to compromise hospitals and election systems in the US.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary government advisory, single outlet, no CVE
The substance traces to a named FBI advisory co-authored with the NSA and Cyber National Mission Force, with specific, checkable particulars: a named attributed company, a named exploited product, a 300-organization victim count, a two-million-task-per-day scanning figure, three botnet management platforms and user-agent evidence tying QTRouter to PRC government personnel. It is held back by having exactly one publisher account, no CVE identifier or reproduced indicators, no detail behind the AI-integration line, and a motive that is the publication's inference rather than an agency finding.
No defender uptake data
The supplied source documents government actions - advisory publication and a law enforcement disruption of QScan and QTRouter - but contains nothing on defender response: no patching or firmware-update rates, no counts of organizations hunting the published indicators, no telemetry on how many exposed Check Point Quantum Gateway instances remain, and no measure of how much the disruption reduced the group's capability. Adoption cannot be scored without inventing those facts.
Mildly overstated framing on a well-sourced core
The factual spine tracks the advisory closely, so the gap is small. It is positive rather than zero because the account layers interpretation onto the government record: 'extremely powerful' tooling language, an espionage motive the advisory did not state, an unexplained AI-integration reference, and threat-scale characterization supplied by two security vendors whose products address exactly this problem. Against that, key defender-actionable specifics - a CVE, concrete indicators - are missing, which pulls the practical value below the rhetorical pitch.
Vendor commentary plus agency operational narrative
Two of the article's interpretive voices are commercial: a security operations strategist at Exabeam and a security automation architect at Swimlane, both employed by vendors selling detection and automation to the audience being warned. The authoring agencies also have a stake, publishing the advisory alongside a same-day announcement that they disrupted the actor's platforms - a framing that supports continued authority for court-authorized technical operations. The underlying technical claims remain agency-sourced rather than vendor-sourced, which keeps this in the moderate band.
Strong upstream source, no lateral verification
Confidence is anchored by the multi-agency provenance and the specificity of the reported figures, and capped by the single-publisher cluster, the absence of a CVE or reproduced indicators, the unmeasurable defender-response side, and the presence of publisher inference and vendor framing inside the account.
product
DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory1 distinct publisher
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.