Joint Cybersecurity Advisory: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure
Joint Cybersecurity Advisory: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact the FBI’s Internet Crime Complaint Center (IC3), and/or your local FBI field office. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA-client requirements or cybersecurity inquiries, contact CybersecurityReports@nsa.gov.
This document is distributed as TLP:CLEAR. Recipients may only share this information without restriction. Information is subject to standard copyright rules. For more information on the Traffic Light Protocol, see Traffic Light Protocol (TLP) Definitions and Usage.
Publication: August 26, 2026
Federal Bureau of Investigation National Security Agency Cyber National Mission Force
Advisory at a Glance
Title:
China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
Original Publication:
August 26, 2026
Executive Summary:
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. The cyber actors’ products have enabled hackers to obfuscate their location and target systems in critical infrastructure sectors including defense industrial base (DIB), communications, government, and higher education. This advisory provides details on the actors’ activities; tactics, techniques, and procedures (TTPs); infrastructure details; and indicators of compromise (IOCs). The information is derived from incident response and investigative techniques.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: