Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH Cyberattacks

US Disables China-Linked Hacking Tools, Urges Banks to Tighten Defenses

1 reports · First detected 2026-08-29 · Last active 2026-08-29

China-linked hacking group QTFY has operated since at least 2018, developing tools for Nanjing Xinjiuwei Network Technology, a contractor that U.S. authorities say served clients including China’s Ministry of State Security and People’s Liberation Army. Its QScan platform found and compromised vulnerable internet-connected devices, while QTRouter routed attacks through those devices and commercial proxies, obscuring their origin. The infrastructure raised particular concerns for banks because financial networks hold valuable data and support systemically important services.

The U.S. Justice Department and FBI said on Aug. 26, 2026, that court-authorized seizures of domains hard-coded into QScan and QTRouter rendered both platforms inoperable. Investigators said QTFY exfiltrated data from more than 300 organizations worldwide in 2024, with financial and insurance companies accounting for many victims. Authorities and cybersecurity specialists urged banks to review historical logs for indicators of compromise, patch software and firmware promptly, audit internet-facing applications and separate critical systems from vulnerable edge devices.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)