The U.S. Department of Justice (DoJ) recently revealed the disruption of two hacking platforms, QScan and QTRouter, operated by a Chinese state-sponsored group known as QTFY. This group is associated with Nanjing Xinjiuwei Network Technology Company, which has been linked to various cyber espionage activities targeting critical infrastructure in the United States.
Victims of QTFY’s Cyber Intrusions
Among the confirmed victims of QTFY’s operations are notable U.S. entities such as the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The DoJ’s announcement highlights the extensive reach of QTFY’s cyber activities, which have been ongoing since at least May 2018.
Operational Mechanisms of QScan and QTRouter
QScan is designed to scan and exploit vulnerable Internet of Things (IoT) devices, subsequently adding them to the QTRouter network. This network serves as an obfuscation tool, allowing QTFY and other Chinese cyber actors to mask the origins of their attacks. By routing communications through compromised devices and proxy services, QTRouter creates the illusion that malicious activities are emanating from locations outside of China.
Exploited Vulnerabilities and Attack Cycle
The FBI has identified that QTFY utilizes both zero-day and N-day vulnerabilities to gain access to victim networks. Specific vulnerabilities mentioned include CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances, as well as others affecting Fortinet, Citrix, Microsoft, F5, Kentico, Apache, and Atlassian products. The attack cycle involves reconnaissance using QScan, exploiting vulnerabilities, establishing persistence through remote access tools, and utilizing QTRouter to navigate victim networks discreetly.
Impact and Future Implications
The disruption of QTFY’s infrastructure underscores the sophisticated nature of state-sponsored cyber operations emanating from China. The FBI’s actions have led to the seizure of domains integral to QScan and QTRouter, effectively halting their operations. This incident illustrates the increasing industrialization of cyber espionage, where state-sponsored actors leverage advanced tools and shared networks to conduct complex cyber campaigns with heightened anonymity.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








