Joint Cybersecurity Advisory: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure

Joint Cybersecurity Advisory: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems

To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact the FBI’s Internet Crime Complaint Center (IC3), and/or your local FBI field office. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA-client requirements or cybersecurity inquiries, contact CybersecurityReports@nsa.gov.

This document is distributed as TLP:CLEAR. Recipients may only share this information without restriction. Information is subject to standard copyright rules. For more information on the Traffic Light Protocol, see Traffic Light Protocol (TLP) Definitions and Usage.


Publication: August 26, 2026

Federal Bureau of Investigation     National Security Agency     Cyber National Mission Force

Advisory at a Glance

Title: 
China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems

Original Publication:  
August 26, 2026

Executive Summary:

The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. The cyber actors’ products have enabled hackers to obfuscate their location and target systems in critical infrastructure sectors including defense industrial base (DIB), communications, government, and higher education. This advisory provides details on the actors’ activities; tactics, techniques, and procedures (TTPs); infrastructure details; and indicators of compromise (IOCs). The information is derived from incident response and investigative techniques.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272