QTFY is a People’s Republic of China state-sponsored cyber group operating through Nanjing Xinjiuwei Network Technology Company. The group has provided hacking services to customers including the Ministry of State Security and the People’s Liberation Army, and has conducted espionage-oriented operations against U.S. critical infrastructure, government networks, and other sensitive targets since at least 2018. QTFY created and operated the QScan and QTRouter platforms. QScan conducts high-volume internet scanning and automated exploitation of vulnerable internet-connected and IoT devices, while QTRouter uses compromised devices, commercial proxy infrastructure, and leased virtual servers to route traffic and conceal the origin of intrusion activity. QTFY has targeted and breached U.S. federal entities including NASA, the Federal Reserve, the Departments of Energy and Justice, and the U.S. Senate. Other documented targets include healthcare organizations, telecommunications providers, power companies, financial institutions, defense contractors, and U.S. national laboratories. The group has rapidly operationalized publicly disclosed and previously unknown vulnerabilities, conducted large-scale scanning and exploitation, stolen server configuration and user-account information, and used compromised systems as an obfuscation layer for its own operations and those of other malicious actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China government-backed cyber-espionage operator providing large-scale scanning, exploitation, and traffic-obfuscation infrastructure. It targeted U.S. government agencies, critical infrastructure, healthcare, telecommunications, power, banking, defense, and financial organizations; it also rapidly exploited publicly disclosed and previously unknown vulnerabilities.
China government-backed cyber-operations provider conducting large-scale internet scanning, exploitation, target reconnaissance, traffic anonymization, and data theft against U.S. government agencies, critical infrastructure, health-care entities, financial organizations, telecommunications providers, power companies, and defense contractors. It allegedly rapidly exploited publicly disclosed and previously unknown flaws in Check Point and Ivanti products.
China-sponsored cyber-espionage and intrusion group operating a hackers-for-hire and government-client network. It used QScan to scan for and automatically infect vulnerable IoT devices, and QTRouter to route and conceal attacks, including attacks against U.S. government agencies, critical infrastructure, healthcare, telecommunications, power, financial, and defense organizations.
Chinese state-sponsored hacker-for-hire group conducting espionage against US federal institutions and critical infrastructure. It operates QScan to scan for and automatically infect vulnerable IoT devices, then uses the QTRouter compromised-device, proxy, and VPS network to obscure operational origin and conduct follow-on attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.