CVE Tools
Back to feed
Incident QScan QTFY nation-state QTRouter Ivanti

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

The U.S. Department of Justice has announced the seizure of infrastructure supporting the Chinese state-sponsored threat actor QTFY, specifically targeting the QScan and QTRouter botnets.

These platforms were utilized to breach critical U.S. institutions, including NASA, the Federal Reserve, and the Department of Energy, by exploiting vulnerabilities in vendor products such as Ivanti, Fortinet, Citrix, Microsoft, F5, Atlassian, Check Point, and BeyondTrust.

Notable exploits included zero-days like CVE-2024-8190 in Ivanti appliances and N-days such as CVE-2018-13379 in Fortinet SSL-VPN, allowing the group to maintain persistence and obfuscate traffic through compromised OpenWrt-based devices.