A joint FBI, NSA and U.S. Cyber Command advisory attributed the China-linked QTFY hacking group to Nanjing Xinjiuwei Network Technology Co. (XJW), alleging the group has operated since at least 2018 to develop malware, trade exploits, run an obfuscation botnet, and target U.S. government and critical-infrastructure organizations. U.S. authorities assessed that XJW maintained links to China’s Ministry of State Security through business relationships and personnel networks that include former People’s Liberation Army members.
In a May 2024 campaign, QTFY used its QScan tool to identify U.S. power and telecommunications targets and exploited CVE-2024-24919 in internet-facing Check Point Quantum Gateway appliances. The operation reportedly exfiltrated data from more than 300 organizations globally, including U.S. defense contractors, financial institutions, and universities; operators retained access through remote-access trojans, web shells, and legitimate credentials. Reporting also identifies Bozhi Security Technology/Elextec Cybersecurity and Nanjing Lexbell Information Technology as firms with client, leadership, product, and contract ties suggestive of links to Chinese intelligence, public-security, and military bodies.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The FBI, NSA, and U.S. Cyber Command Cyber National Mission Force issued a joint advisory attributing QTFY to Nanjing Xinjiuwei Network Technology Co. The advisory assessed links between XJW and China’s Ministry of State Security, reported its relationships with firms including ELEX and Lexbell, and described QTFY targeting of U.S. government and critical-infrastructure organizations.
QTFY used its QScan tool to target U.S. power and telecommunications companies and exploited CVE-2024-24919 in Check Point Quantum Gateway appliances. The campaign reportedly exfiltrated data from more than 300 organizations globally, including U.S. defense contractors, financial institutions, and universities.
The joint U.S. advisory assessed that the China-linked QTFY hacking group had been active since at least 2018, developing malicious tools, trading malware and exploits, and maintaining an obfuscation botnet.
A court-authorized U.S. Department of Justice action seized hard-coded domains used by QTFY's QScan and QTRouter platforms for essential communications and authentication. The DOJ reported that the seizure rendered both platforms inoperable.
Referenced analysis reported that ELEX had intelligence, public-security, and PLA-affiliated customers and capabilities including cyber-range, vulnerability-scanning, and influence-operation support. It also reported that Lexbell had military-use products, PLA-linked leadership and use, and contracts involving the PLA-affiliated National University of Defense Technology.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
blog.alphahunt.io
Open sourcemalware.news
Open sourcenattothoughts.com
Open sourceblackfog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.