logo

Officials disrupt Chinese espionage operation that hit multiple federal agencies

ID: 24d5a415-3cf3-52b5-9922-923bc57bfccf

STIX ID: report--24d5a415-3cf3-52b5-9922-923bc57bfccf

Feed Name: CyberScoop

Threat Score
92/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

Author: Matt Kapko

...
...

Federal authorities disclosed and disrupted a China state-sponsored espionage campaign dubbed QTFY that targeted and compromised U.S. critical infrastructure and multiple federal agencies since 2018; investigators seized domains used to run QScan and QTRouter, tools that performed large-scale reconnaissance, exploitation (including Ivanti zero-days), IoT botnet operations, and traffic concealment. The takedown prevented further access to the group’s infrastructure, and U.S. agencies released a joint advisory with known indicators of compromise and details of the intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.