NSA and FBI Warn Chinese Hackers Are Actively Targeting US Critical Infrastructure The US National Security Agency, Federal Bureau of Investigation and Cyber National Mission Force have issued a joint warning about a China-linked hacking group accused of building an industrial-scale cyberattack infrastructure capable of scanning, exploiting and concealing intrusions against government agencies, defence contractors and critical infrastructure operators. The group, tracked as QTFY and also known by the abbreviations QT and QTCYBER, allegedly developed an interconnected collection of hacking platforms, botnets and proxy services that allowed operators to discover vulnerable systems, compromise internet-connected devices and route malicious traffic through systems located close to intended victims. The joint cybersecurity advisory was released alongside a court-authorised US operation that seized domains supporting two of the group’s most important platforms, QScan and QTRouter. Because those domains were embedded in the malware and required for core communication and authentication functions, the Justice Department said the seizures rendered both platforms inoperable. However, the disruption does not mean every compromised device has been cleaned or that the wider threat has disappeared. The advisory identifies additional botnet-management systems, historical infrastructure and compromised devices that may continue to present risks. Security teams are therefore being urged to hunt for evidence of earlier QTFY activity rather than treating the domain seizures as a complete resolution. QTFY linked to Chinese hacking contractor US authorities attribute QTFY’s infrastructure to Nanjing Xinjiuwei Network Technology Company, a China-based business that allegedly provides stolen information and offensive cyber services to customers that include China’s Ministry of State Security and People’s Liberation Army. According to the US Department of Justice, the company created and operated QScan and QTRouter as complementary platforms. QScan supplied large-scale reconnaissance and exploitation, while QTRouter helped customers conceal the source of their operations. The case highlights what US agencies and