QScan is an IoT-focused scanning and automated-compromise platform attributed by U.S. authorities to QTFY, a PRC state-sponsored and hacker-for-hire group linked to Nanjing Xinjiuwei Network Technology Company. It searches the public internet for vulnerable internet-connected devices, including routers and security cameras, and automatically compromises susceptible systems at scale. Compromised devices are enrolled into the associated QTRouter infrastructure, which is used as an obfuscation network for subsequent intrusion activity. QTFY operations have targeted U.S. government entities, critical infrastructure, healthcare, telecommunications, financial organizations, and defense contractors. The platform was disrupted through seizure of infrastructure required for its communication and authentication functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
QScan scans and automatically infects thousands of internet-of-things (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Large-scale internet scanning and exploitation tool containing code for more than 200 attacks. It identified vulnerable systems and attempted intrusion; court records state it processed more than 2 million scanning or exploitation tasks on one day in 2024.
A large-scale reconnaissance and exploitation tool attributed to QTFY. It scans the internet for vulnerable systems, attempts intrusion, and includes code for more than 200 attacks; it reportedly processed over 2 million scanning or exploitation tasks in one day in 2024.
An IoT scanning and automated-infection platform used to identify vulnerable internet-facing smart devices, compromise them, and enroll them into an adversary-controlled botnet or proxy network.
A QTFY-operated malware platform that scans for and automatically compromises vulnerable IoT devices, enrolling them into the QTRouter-controlled device network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.