US attributes federal network intrusions to PRC state-sponsored 'QTFY' hacking group
Federal authorities publicly attributed a sprawling intrusion campaign against U.S. government and infrastructure targets to a People’s Republic of China state-sponsored hacking group known as “QTFY,” an operation the FBI says is run by Nanjing Xinjiuwei Network Technology Company. Unsealed court documents in the Southern District of California allege the group “created and operated” two hacking platforms that were used to conceal attacks on, among others, the Department of Justice, NASA, the Federal Reserve, and the U.S. Senate.
The disclosure landed alongside a coordinated disruption: federal agents shut down the two hacking platforms the group relied on to hide its activity, cutting off a channel U.S. officials say had been burrowing into federal networks and critical infrastructure. The case is part of a wider pattern documented by CISA and allied agencies, who earlier warned that PRC-linked actors are compromising networks worldwide — including telecom providers and edge devices — to feed a global espionage system.
The court action is one of the most explicit recent examples of the PRC’s state-backed cyber operations being named, indicted, and disrupted in public, and it reinforces ongoing attributions of Chinese state-sponsored espionage to targets across the U.S. government and critical infrastructure.