Aliases: QTFY, QT, QTCYBER
Attribution: China-linked / PRC state-sponsored cyber operations
Associated organization: Nanjing Xinjiuwei Network Technology Co. (XJW / 南京鑫玖维网络科技有限公司)
First known activity: Infrastructure observed as early as 2017; organization established in 2018
Primary objectives: Cyber espionage, vulnerability exploitation, credential/access acquisition, infrastructure provisioning, reconnaissance, data theft, and operational obfuscation
Assessment date: August 27, 2026
QTFY is a newly publicly identified but long-running China-linked cyber threat organization attributed by the FBI, NSA, and U.S. Cyber National Mission Force to Nanjing Xinjiuwei Network Technology Co. (XJW). U.S. authorities describe XJW as a cyber-enabling company with relationships to elements of the People\'s Republic of China\'s Ministry of State Security (MSS). QTFY personnel reportedly include former People\'s Liberation Army (PLA) members who have leveraged government and industry contacts to obtain cyber contracts and subcontracts.
The group is unusual because it functions partly as an intrusion organization and partly as an infrastructure quartermaster for other Chinese cyber operators. It developed QScan, QTRouter, QTBotnet, Proxy Platform Management, and Proxy Pool Management System. These systems collectively discover vulnerable targets, compromise IoT devices, maintain botnets, and route offensive operations through compromised or commercial infrastructure.
The FBI/NSA/CNMF advisory documents QTFY activity against the U.S. Senate, NASA, Federal Reserve, Departments of Energy, Justice, and Health and Human Services, NIH, defense contractors, telecommunications companies, universities, financial institutions, hospitals, biotechnology companies, semiconductor companies, state and local governments, election infrastructure, and energy and water organizations. In one particularly significant 2024 operation, QTFY reportedly exploited CVE-2024-24919 and exfiltrated information from more than 300 organizations worldwide.
On August 26, 2026, the U.S. Department of Justice and FBI announced court-authorized seizures targeting QScan and QTRouter infrastructure. Because the seized domains were hard-coded into the platforms and performed critical communications and authentication functions, DOJ stated that the seizures rendered QScan and QTRouter inoperable.
