SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign
The August 26 advisory, written with the NSA and Cyber National Mission Force, describes QTFY running its own scanning, proxying and botnet platforms since 2018. Commodity indicator feeds will not find it.
The Watch · Security desk

What happened
- The FBI published an advisory on August 26 in coordination with the National Security Agency and the Cyber National Mission Force covering a Chinese group tracked as QTFY.
- Its in-house QScan platform ran over two million scanning and penetration testing tasks in a single day during 2024, according to the FBI.
- Named targets in the advisory include the US Department of Justice, the Federal Reserve and NASA, alongside attempted intrusions at hospitals and election systems.
Why it matters
- constraint Custom platforms leave shared indicator feeds with nothing to match on: no rented C2, no commodity malware hashes, so each victim pays for behavioural detection and appliance forensics itself.
- exposure Because the final hop comes from compromised IoT devices near the target, geolocation scoring and ASN reputation clear the session before any content inspection happens.
- decision Persistence through valid credentials turns a gateway patch into a credential-rotation scoping call, and the honest scope is every account that authenticated through the device.
- precedent A maintained target database means the interval between a vulnerability becoming public and a matched victim list existing is close to zero for the next N-day, not just this one.
The detection problem sits in the sequencing. QScan keeps a standing database of scraped webpages, collected TLS certificates and enumerated subdomains, so when a new vulnerability drops the target list already exists [8][9]. Scanning is not the reconnaissance step here; it is the follow-through. The FBI puts QScan at more than two million scanning and penetration testing tasks in a single day during 2024 [7]. Spread across 86,400 seconds, that is roughly 23 tasks per second, sustained for a day [21].
Volume like that only works if it arrives from somewhere unremarkable. QTRouter is the layer that provides it: a traffic obfuscation network running on devices including routers loaded with custom OpenWrt software [10], fed by botnet products that fold compromised IoT devices into proxy nodes [11], with at least three major platforms managing those botnets [12]. The last hop into a victim network comes from a compromised device near the victim, blending with legitimate users [13]. Gabrielle Hempel of Exabeam described the result as an ecosystem designed to make malicious activity look geographically and operationally ordinary [14].
One line in the advisory goes past tradecraft. The FBI says unique user agent strings originating from IP addresses in China indicated QTRouter was used by QTFY personnel and by PRC government personnel [15]. Contractor and state operators on the same proxy fabric.
The entry point of record is an appliance. In 2024 the group exfiltrated data from more than 300 organisations in the US and globally after using an exploit for a Check Point Quantum Gateway vulnerability, with US defense contractors, financial institutions and universities among the victims [4]. The Infosecurity account of the advisory names the product but no CVE [22], which leaves anyone doing an audit matching on a product, not on a patch level. Post-access, the group holds ground with remote access trojans, web shells and legitimate credentials [16]. That last item sets the remediation scope: the appliance is the door, the credentials that passed through it are the residue.
QTFY was established in 2018 and has worked the defense industrial base, communications, government and higher education for close to a decade [3]; six years separate that start from the 2024 Check Point campaign [23]. The FBI attributes the group, which also uses the acronyms QT and QTCYBER, to Nanjing Xinjiuwei Network Technology Co., an enabling company for PRC-linked cyber operations [17]. It says the group works freelance PRC hacker networks and contracting and subcontracting marketplaces to keep pace with new exploits and techniques, including AI integration [19], and concentrates on zero-day and N-day flaws for initial access [18].
Named targets include the Department of Justice, the Federal Reserve and NASA [5], with attempts against hospitals and election systems [6]. The advisory did not state the group's aims; Infosecurity assesses espionage as the likely motivation [24]. Nick Tausek of Swimlane noted that even limited access to defense-linked networks yields intelligence useful well beyond the organisation first breached [20]. For anyone who ran a Quantum Gateway at the border in 2024, the auditable question is which credentials transited it.
What to watch
- Whether the FBI or Check Point publishes the CVE and a compromise-assessment procedure for Quantum Gateway devices.
- Whether QTRouter proxy nodes, including the OpenWrt routers and IoT devices, are released as queryable indicators rather than described in prose.
- Whether the attribution to Nanjing Xinjiuwei Network Technology Co. is followed by sanctions or indictments.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence63
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The FBI warned that a Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms.
- [2]
The FBI advisory was published in coordination with the National Security Agency and Cyber National Mission Force on August 26.
- [3]
QTFY has focused on critical infrastructure sectors including the defense industrial base, communications, government and higher education for close to a decade since being established in 2018.
- [4]
In 2024 QTFY exfiltrated data from over 300 organizations in the US and globally after leveraging an exploit for a Check Point Quantum Gateway vulnerability; victims included US defense contractors, financial institutions and universities.
- [5]
Other entities targeted by the group include the US Department of Justice, the US Federal Reserve and NASA.
- [6]
Attempts have been made by the group to compromise hospitals and election systems in the US.
- [7]
The FBI said QTFY used QScan to conduct over two million scanning and penetration testing tasks in a single day in 2024.
- [8]
QScan conducts reconnaissance against victim networks including webpage scraping, TLS certificate collection, subdomain enumeration and penetration testing, and is designed to rapidly identify vulnerabilities and exploit vulnerable IoT devices.
- [9]
QScan maintains a large database to quickly identify targets of interest when a new vulnerability is identified.
- [10]
QTFY developed QTRouter, a network traffic obfuscation network running on devices that include routers with custom OpenWrt software.
- [11]
QTFY uses botnet products to control compromised IoT devices and include them as QTRouter proxy nodes.
- [12]
QTFY has developed and maintained at least three major platforms that can manage botnets of compromised IoT devices as part of the obfuscation network.
- [13]
The QTRouter obfuscation network enables the group to access victim networks from nearby compromised IoT devices, blending in with legitimate users.
- [14]
Gabrielle Hempel, security operations strategist at Exabeam, said the group has built an ecosystem designed to make malicious activity look geographically and operationally ordinary.
- [15]
The FBI revealed that unique user agent strings originating from IP addresses in China indicated QTRouter was used by QTFY personnel and PRC government personnel.
- [16]
Once inside a network QTFY attempts to maintain persistence through techniques ranging from deploying remote access trojans and web shells to obtaining legitimate credentials.
- [17]
The FBI attributed QTFY, which also uses the acronyms QT and QTCYBER, to Nanjing Xinjiuwei Network Technology Co., an enabling company for cyber operations linked to the People's Republic of China.
- [18]
The advisory highlighted QTFY's focus on exploiting zero-day and N-day vulnerabilities to gain initial access to victim networks.
- [19]
The threat actors participate in freelance PRC hacker networks and malicious cyber contracting and subcontracting marketplaces, enabling them to keep up with new exploits and attack techniques, including the integration of AI into their processes.
- [20]
Nick Tausek, lead security automation architect at Swimlane, said even limited access to military and defense-linked networks can give an adversary intelligence useful far beyond the organization initially breached.
- [21]
Two million tasks in one day is approximately 23 tasks per second sustained across the day.
- [22]
The Infosecurity Magazine account of the advisory identifies the Check Point Quantum Gateway product but gives no CVE identifier for the exploited vulnerability.
- [23]
Six years elapsed between QTFY's establishment in 2018 and the 2024 Check Point Quantum Gateway exfiltration campaign.
- [24]
The advisory did not disclose the aims of the attackers; Infosecurity Magazine assessed that espionage is likely a key motivation.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- QTFYFollow
- Nanjing Xinjiuwei Network Technology CompanyFollow
- QScanFollow
- QTRouterFollow
- Federal Bureau of InvestigationFollow
- National Security AgencyFollow
- US Cyber Command – Cyber National Mission ForceFollow
- U.S. Department of JusticeFollow
- Check Point Quantum GatewayFollow
- OpenWrtFollow
- MITRE ATT&CK for EnterpriseFollow
- ExabeamFollow
- Swimlane Inc.Follow
- Gabrielle HempelFollow
- Nick TausekFollow
- NASAFollow
- U.S. Federal ReserveFollow