US Disrupts Chinese Cyber Espionage Operation Targeting Critical Infrastructure
ID: 220af7c5-8bb8-5d38-b3b9-50f0af09b45c
STIX ID: report--220af7c5-8bb8-5d38-b3b9-50f0af09b45c
Feed Name: ThreatCluster
Threat Score
On August 26, 2026 the US DOJ and FBI seized domains tied to Chinese platforms QScan and QTRouter used by the state-sponsored group QTFY (operated by Nanjing Xinjiuwei) to scan for vulnerabilities, exploit IoT and other systems, and route intrusions through a botnet; the infrastructure targeted US critical networks (including NASA and the Federal Reserve) and multiple sectors since at least 2018, and the seizure disrupted a significant cyber espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
