Incident QScan QTFY nation-state QTRouter Ivanti
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
CVE Tools coverage
The U.S. Department of Justice has announced the seizure of infrastructure supporting the Chinese state-sponsored threat actor QTFY, specifically targeting the QScan and QTRouter botnets.
These platforms were utilized to breach critical U.S. institutions, including NASA, the Federal Reserve, and the Department of Energy, by exploiting vulnerabilities in vendor products such as Ivanti, Fortinet, Citrix, Microsoft, F5, Atlassian, Check Point, and BeyondTrust.
Notable exploits included zero-days like CVE-2024-8190 in Ivanti appliances and N-days such as CVE-2018-13379 in Fortinet SSL-VPN, allowing the group to maintain persistence and obfuscate traffic through compromised OpenWrt-based devices.