QTFY, also known as QT and QTCYBER, is a PRC state-sponsored cyber-espionage threat group active since at least 2018. U.S. authorities attribute the group to Nanjing Xinjiuwei Network Technology Co. (XJW), a China-based cyber-enabling company assessed to have relationships with China’s Ministry of State Security and personnel connections to the People’s Liberation Army. QTFY operates as a technical quartermaster and service provider within the PRC cyber ecosystem, developing tooling, brokering exploits and network access, and supplying reconnaissance, exploitation, proxy-routing, and traffic-obfuscation services. The group operates QScan, a distributed high-volume reconnaissance and exploitation platform, and QTRouter, a multi-hop proxy and obfuscation network. QScan conducts active vulnerability scanning, web scraping, certificate collection, subdomain enumeration, system fingerprinting, and automated exploitation of internet-facing devices. QTRouter uses compromised IoT devices and routers, commercial proxy services, and leased virtual private servers to relay malicious traffic and obscure its Chinese origin. QTFY also operates botnet-management platforms that support command execution on compromised devices and distributed denial-of-service capability. QTFY has targeted U.S. government, critical-infrastructure, defense-industrial-base, telecommunications, energy, water, financial-services, health-care, and higher-education organizations, as well as targets in Taiwan and South Korea. Its operations have exploited zero-day and known vulnerabilities in public-facing applications, including VPN gateways, file-transfer products, security appliances, content-management systems, and remote-support software. Following compromise, QTFY has maintained access through remote-access trojans, web shells, and stolen legitimate credentials, and has exfiltrated data. U.S. law-enforcement action in August 2026 disrupted core QScan and QTRouter infrastructure, but QTFY’s use of distributed compromised devices, proxies, and leased infrastructure enables resilient operational routing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
In May 2024, QTFY used QScan against U.S. power and telecommunications companies, leveraging CVE-2024-24919, a vulnerability affecting Check Point Quantum Gateway appliances. According to the joint advisory, the campaign resulted in data being exfiltrated from more than 300 organizations.
CVE-2026-1731, affecting BeyondTrust Remote Support, was used in February 2026 against a US state government and a water district.
In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN.
In January 2020, QTFY used an exploit for the Citrix Application Delivery Controller (ADC) and Gateway vulnerability (CVE-2019-19781) against numerous U.S. targets.
The advisory's targeting timeline includes "ProxyLogon in March 2021."
9 more CVEs tied to this actor tracked in Mallory.
434 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked state-sponsored cyber-espionage activity using commercial scanning and router-obfuscation platforms to identify and compromise internet-connected devices, route operations through third-party equipment outside China, and target critical infrastructure and government-related organizations. Some intrusions reportedly resulted in data theft.
China-linked cyber-espionage activity attributed to XJW, targeting U.S. government and critical-infrastructure networks since at least 2018. It develops malicious tooling, trades malware and exploits through freelance hacking networks, and operates an obfuscation botnet.
Since at least 2018, QTFY has allegedly developed malicious tooling, traded malware and exploits through freelance hacking networks, maintained an obfuscation botnet, and targeted U.S. government and critical-infrastructure networks.
Conducted automated reconnaissance and exploitation of Check Point Quantum Gateway appliances, then maintained persistence and exfiltrated data from over 300 organizations, including critical-infrastructure entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.