Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign

The August 26 advisory, written with the NSA and Cyber National Mission Force, describes QTFY running its own scanning, proxying and botnet platforms since 2018. Commodity indicator feeds will not find it.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign
Generated illustration

What happened

  • The FBI published an advisory on August 26 in coordination with the National Security Agency and the Cyber National Mission Force covering a Chinese group tracked as QTFY.
  • Its in-house QScan platform ran over two million scanning and penetration testing tasks in a single day during 2024, according to the FBI.
  • Named targets in the advisory include the US Department of Justice, the Federal Reserve and NASA, alongside attempted intrusions at hospitals and election systems.

Why it matters

  • constraint Custom platforms leave shared indicator feeds with nothing to match on: no rented C2, no commodity malware hashes, so each victim pays for behavioural detection and appliance forensics itself.
  • exposure Because the final hop comes from compromised IoT devices near the target, geolocation scoring and ASN reputation clear the session before any content inspection happens.
  • decision Persistence through valid credentials turns a gateway patch into a credential-rotation scoping call, and the honest scope is every account that authenticated through the device.
  • precedent A maintained target database means the interval between a vulnerability becoming public and a matched victim list existing is close to zero for the next N-day, not just this one.

The detection problem sits in the sequencing. QScan keeps a standing database of scraped webpages, collected TLS certificates and enumerated subdomains, so when a new vulnerability drops the target list already exists [8][9]. Scanning is not the reconnaissance step here; it is the follow-through. The FBI puts QScan at more than two million scanning and penetration testing tasks in a single day during 2024 [7]. Spread across 86,400 seconds, that is roughly 23 tasks per second, sustained for a day [21].

Volume like that only works if it arrives from somewhere unremarkable. QTRouter is the layer that provides it: a traffic obfuscation network running on devices including routers loaded with custom OpenWrt software [10], fed by botnet products that fold compromised IoT devices into proxy nodes [11], with at least three major platforms managing those botnets [12]. The last hop into a victim network comes from a compromised device near the victim, blending with legitimate users [13]. Gabrielle Hempel of Exabeam described the result as an ecosystem designed to make malicious activity look geographically and operationally ordinary [14].

One line in the advisory goes past tradecraft. The FBI says unique user agent strings originating from IP addresses in China indicated QTRouter was used by QTFY personnel and by PRC government personnel [15]. Contractor and state operators on the same proxy fabric.

The entry point of record is an appliance. In 2024 the group exfiltrated data from more than 300 organisations in the US and globally after using an exploit for a Check Point Quantum Gateway vulnerability, with US defense contractors, financial institutions and universities among the victims [4]. The Infosecurity account of the advisory names the product but no CVE [22], which leaves anyone doing an audit matching on a product, not on a patch level. Post-access, the group holds ground with remote access trojans, web shells and legitimate credentials [16]. That last item sets the remediation scope: the appliance is the door, the credentials that passed through it are the residue.

QTFY was established in 2018 and has worked the defense industrial base, communications, government and higher education for close to a decade [3]; six years separate that start from the 2024 Check Point campaign [23]. The FBI attributes the group, which also uses the acronyms QT and QTCYBER, to Nanjing Xinjiuwei Network Technology Co., an enabling company for PRC-linked cyber operations [17]. It says the group works freelance PRC hacker networks and contracting and subcontracting marketplaces to keep pace with new exploits and techniques, including AI integration [19], and concentrates on zero-day and N-day flaws for initial access [18].

Named targets include the Department of Justice, the Federal Reserve and NASA [5], with attempts against hospitals and election systems [6]. The advisory did not state the group's aims; Infosecurity assesses espionage as the likely motivation [24]. Nick Tausek of Swimlane noted that even limited access to defense-linked networks yields intelligence useful well beyond the organisation first breached [20]. For anyone who ran a Quantum Gateway at the border in 2024, the auditable question is which credentials transited it.

What to watch

  • Whether the FBI or Check Point publishes the CVE and a compromise-assessment procedure for Quantum Gateway devices.
  • Whether QTRouter proxy nodes, including the OpenWrt routers and IoT devices, are released as queryable indicators rather than described in prose.
  • Whether the attribution to Nanjing Xinjiuwei Network Technology Co. is followed by sanctions or indictments.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence63
Adoption
Insufficient
Hype gap+12
Incentives60
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The FBI warned that a Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms.

    ReportedSupportedSource: FBI advisory, as reported by Infosecurity MagazineView cited source
  2. [2]

    The FBI advisory was published in coordination with the National Security Agency and Cyber National Mission Force on August 26.

    ReportedSupportedView cited source
  3. [3]

    QTFY has focused on critical infrastructure sectors including the defense industrial base, communications, government and higher education for close to a decade since being established in 2018.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · August 27, 2026

    Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories