(TLP:CLEAR) Joint Cybersecurity Advisory Warns of China-Linked Threat Group QTFY Targeting Critical Infrastructure
Created: Thursday, August 27, 2026 - 15:30
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: Yesterday, the FBI, NSA, and Cyber National Mission Force (CNMF) released a joint cybersecurity advisory warning of ongoing activity by QTFY, a China-linked hacking group also operating under the names QT and QTCYBER. Active since 2018 and attributed to Nanjing Xinjiuwei Network Technology Co., QTFY has developed malicious tooling, traded exploits within freelance hacking networks, and maintained an obfuscation botnet used to compromise U.S. and foreign networks. Targeted sectors include defense industrial base, telecommunications, local government, and higher education. The advisory names the water and wastewater sector among its intended audiences.
QTFY relies on a set of branded, interconnected products. QScan is a distributed vulnerability scanning and exploitation platform that has processed over two million scanning tasks in a single day and draws on a database of more than 200 proof-of-concept exploits. QTRouter is an obfuscation network built on compromised routers, commercial proxy services, and hijacked Internet of Things (IoT) devices, allowing the actors to blend malicious traffic with legitimate user activity. Three additional platforms (Proxy Platform Management, Proxy Pool Management System, and QTBotnet) manage botnets of compromised IoT devices. QTFY gains initial access by exploiting zero-day and N-day vulnerabilities, then uses remote access trojans, web shells, and stolen credentials to persist.
Analyst Note: The advisory’s targeting timeline is directly relevant to the water sector. In February 2026, QTFY used QScan to exploit a BeyondTrust Remote Support vulnerability (CVE-2026-1731) against a U.S. state government and targeted a U.S. water district. See the below screenshot taken from the advisory:

The group’s pattern of pre-positioning through internet-facing and edge devices also mirrors concerns raised about other PRC-linked actors targeting critical infrastructure.
Because QTFY obfuscates its activity through compromised IoT and proxy infrastructure, blocking individual IP addresses offers limited protection, and the authoring agencies recommend vetting IOCs before taking action such as blocking.
Additional Reading:
- (TLP:CLEAR) Joint Cybersecurity Advisory – Defending Against China-Nexus Covert Networks of Compromised Devices
- CISA Zero Trust Best Practices
- Detect and Prevent Web Shell Malware
Related WaterISAC PIRs: 6 – 12
