All incidents

US disrupts Chinese QTFY botnet targeting military infrastructure

outageopenAug 27, 2026 — Aug 27, 2026
FBI Alert: Chinese QTFY Hackers Hit US Government Systems

THE FBI has issued a warning that a Chinese hacking group known as QTFY has been infiltrating US government and critical infrastructure networks.

The group has been exfiltrating data from hundreds of organisations across multiple sectors.

QTFY employs custom tools QScan for scanning IoT devices and QTRouter to hide traffic.

These tools allow the actors to remain undetected while probing for weaknesses in target networks.

The group has been active since 2018, focusing on defence, communications and education sectors.

It has leveraged known flaws in widely used software to gain footholds, although no specific CVE was cited in the alert.

The warning notes that QTFY’s activity overlaps with other cyberespionage campaigns.

US authorities have already moved to seize domains and dismantle the associated botnet, as reported by SecurityWeek.

Defenders should ensure all internet‑facing devices run the latest firmware and conduct regular vulnerability scans of internal networks.

They should also hunt for indicators such as unusual DNS queries to the seized domains or signatures of QScan/QTRouter traffic.

Organisations are encouraged to share any suspicious activity with the FBI’s Internet Crime Complaint Centre.

Applying network segmentation to limit lateral movement and reviewing access controls on privileged accounts are also recommended steps.

Intelligence briefing updated Aug 27, 2026

QTFY
Root sourcewww.ic3.gov
Timeline Coverage

Swipe to explore timeline