US Agencies Warn of China-Linked Hackers Targeting Critical Infrastructure
US Agencies Warn of China-Linked Hackers

US Agencies Warn of China-Linked Hackers Targeting Critical Infrastructure

By Mintesinot Nigussie  |  August 27, 2026

US intelligence and law enforcement agencies have warned organisations about a China-linked hacking group that has developed malicious systems to penetrate networks belonging to military and critical infrastructure operators.

The National Security Agency, Federal Bureau of Investigation and Cyber National Mission Force said the group, known as QTFY, QT or QTCYBER, has targeted organisations in the US and abroad across sectors including the defence industrial base, telecommunications, local government and higher education.

Datanomics

QTFY has been active since 2018, developing hacking tools, trading malware and exploits through freelance networks and maintaining an obfuscation botnet, according to a joint cybersecurity advisory issued by the agencies on August 26.

The group has built a collection of interconnected platforms to support reconnaissance, exploitation and the concealment of malicious activity. One of them, QScan, scans for vulnerabilities and can exploit weaknesses in internet-connected devices, including vulnerable internet-of-things equipment.

Sheway Hair

QTFY also operates QTRouter, an obfuscation network designed to make malicious activity appear similar to legitimate internet traffic. At least three other platforms — Proxy Platform Management, Proxy Pool Management System and QTBotnet — can manage botnets made up of compromised internet-of-things devices and use them as nodes within the obfuscation network.

The agencies said QTFY actors use both zero-day and known vulnerabilities to gain initial access to targeted networks. Once inside, they can obtain legitimate credentials from compromised systems to maintain persistence.

The group is also active in the exploit-development community, using freelance hacker networks and cyber-contracting and subcontracting marketplaces to develop and obtain malicious capabilities, the agencies said.

HypeFitness

The NSA, FBI and CNMF recommended that organisations install the latest software and firmware updates, regularly review internet-facing websites and applications for unintended exposure of operational information, and isolate critical systems from edge devices.

They also urged organisations to search their networks for the indicators of compromise contained in the advisory as part of efforts to detect QTFY activity.

Source: FSX Business News