US Disables China-Linked Hacking Tools, Urges Banks to Tighten Defenses
China-linked hacking group QTFY has operated since at least 2018, developing tools for Nanjing Xinjiuwei Network Technology, a contractor that U.S. authorities say served clients including China’s Ministry of State Security and People’s Liberation Army. Its QScan platform found and compromised vulnerable internet-connected devices, while QTRouter routed attacks through those devices and commercial proxies, obscuring their origin. The infrastructure raised particular concerns for banks because financial networks hold valuable data and support systemically important services.
The U.S. Justice Department and FBI said on Aug. 26, 2026, that court-authorized seizures of domains hard-coded into QScan and QTRouter rendered both platforms inoperable. Investigators said QTFY exfiltrated data from more than 300 organizations worldwide in 2024, with financial and insurance companies accounting for many victims. Authorities and cybersecurity specialists urged banks to review historical logs for indicators of compromise, patch software and firmware promptly, audit internet-facing applications and separate critical systems from vulnerable edge devices.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →