An official website of the United States government
A .gov website belongs to an official government organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Press Release | Aug. 26, 2026

NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity

FORT MEADE, Md. — Today, the National Security Agency (NSA) joins the Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF) in releasing a joint cybersecurity advisory titled, “China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems.”

This guidance alerts organizations about China-linked cyber threat actors using the acronyms QTFY, QT and QTCYBER who have developed malicious distributed platforms to compromise the networks of U.S. and foreign organizations.

Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet and ultimately targeted critical systems in the U.S. Organizations from multiple sectors have been targeted including the Defense Industrial Base, telecommunications, local government and higher education, among others.

QTFY actors have developed branded products that work in conjunction with each other and include the vulnerability scanning and exploitation platform “QScan” to conduct reconnaissance, exploit vulnerable Internet of Things (IoT) devices and identify vulnerabilities in networks, an obfuscation network named “QTRouter” to blend in with legitimate users, and at least three major platforms that can manage botnets of compromised IoT devices and include them as obfuscation network nodes (“Proxy Platform Management,” “Proxy Pool Management System” and “QTBotnet”).

QTFY threat actors exploit zero-day and N-day vulnerabilities to gain initial access to victim networks and obtain legitimate credentials from compromised systems to maintain persistence and are active in the exploit development community via freelance hacker networks and malicious cyber contracting and subcontracting marketplaces.

The authoring agencies recommend organizations implement the following mitigations to improve overall cybersecurity posture based on QTFY activity:

  • Apply the latest software and firmware updates to your organization’s devices.
  • Regularly audit your organization’s webpages and internet-facing apps to protect operational information from unintended disclosure.
  • Isolate critical systems from edge devices.
  • Hunt for the provided indicators of compromise.

Visit our full library for more cybersecurity information and technical guidance.

Visit the Zero Trust Implementation Guidelines for adaptable, interactive cybersecurity frameworks.

Visit the Cybersecurity Collaboration Center page to explore free resources for defense industrial base contractors.


 

NSA Media Relations
MediaRelations@nsa.gov
443-634-0721
 


About the National Security Agency

Founded in 1952, NSA is a U.S. Department of War combat support agency and element of the U.S. Intelligence Community. The Agency’s mission is to provide foreign signals intelligence to policy makers and our military, and to prevent and eradicate cybersecurity threats to U.S. National Security Systems, with a focus on the Defense Industrial Base and the improvement of U.S. weapons’ security. From protecting U.S. warfighters around the world to enabling and supporting operations on land, in the air, at sea, in space, and in the cyber domain, NSA is committed to building public trust through transparency and protecting civil liberties and privacy consistent with our nation’s values.

###