highAPT

QTFY (QScan/QTRouter) Chinese State-Sponsored Infrastructure

First seen Aug 27, 2026 · Updated Aug 27, 2026

chinastate-sponsoredcritical-infrastructurenetwork-reconnaissancerouter-exploitationbotnetfbi-disruptionQTFY

The U.S. DoJ and FBI disrupted infrastructure operated by China-linked threat actor QTFY, tied to Nanjing Xinjiuwei Network Technology Company, which used two custom hacking platforms—QScan and QTRouter—to target U.S. critical infrastructure and sensitive networks. The takedown highlights ongoing state-sponsored efforts to compromise network edge devices for espionage and data theft purposes.

Technical Analysis

QScan appears to function as a large-scale network reconnaissance and vulnerability scanning tool used to identify exposed and exploitable devices, while QTRouter is reported as a platform designed to compromise and control routers and other network edge devices, likely leveraging known firmware vulnerabilities for initial access. Once compromised, these devices may have been used as relay nodes or proxy infrastructure to obscure further intrusions into critical infrastructure networks and exfiltrate sensitive data. The operation reflects tactics consistent with Chinese state-sponsored actors who prepositions access within edge devices (routers, IoT, VPN gateways) for long-term espionage campaigns. No specific CVEs were disclosed in the source reporting, though such campaigns typically exploit known unpatched vulnerabilities in SOHO/enterprise routers and network appliances. Organizations running AI agents or LLM-based tooling on networks with compromised edge routers could face exposure of API keys, credentials, and RAG pipeline data through man-in-the-middle traffic interception or lateral movement enabled by this infrastructure.

Affected Systems

Routers and network edge devices (make/model unspecified in source reporting), critical infrastructure networks, and other sensitive U.S. organizational networks targeted for reconnaissance and compromise

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) disclosed in source reporting; associated with Nanjing Xinjiuwei Network Technology Company (南京鑫九维网络科技有限公司) and threat actor designation QTFY

Remediation Steps

  1. 1

    Patch and update edge devices

    Ensure all routers, firewalls, and network appliances are running the latest firmware with all security patches applied.

  2. 2

    Network segmentation

    Segment critical infrastructure and sensitive networks from general internet-facing devices to limit lateral movement.

  3. 3

    Monitor for anomalous router behavior

    Deploy monitoring for unusual outbound traffic, configuration changes, or unauthorized administrative access on network edge devices.

  4. 4

    Rotate exposed credentials

    Rotate API keys, VPN credentials, and administrative passwords on any devices that may have transited compromised network infrastructure.

  5. 5

    Threat intelligence integration

    Ingest IOCs and TTPs released by DoJ/FBI advisories into SIEM and threat detection platforms as they become available.

Industries Most Exposed

critical infrastructuregovernmenttelecommunicationsenergytechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.