US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
The AI race is accelerating faster than the real economy can adapt. Sam Altman concedes adoption is slower than expected, while Nvidia’s record results, Musk’s ambitions, Chinese open models and new jailbreak risks reveal an intensifying contest for compute, influence and control. Across the world.
Brazil is investing US$444 million in AI infrastructure spanning Chinese and US technology. Its strategy avoids dependence on one power, using rival suppliers to build sovereign compute, domestic models and leverage, although genuine autonomy will depend on its energy, skills and strong execution.
Cyber Update: China’s hacking assembly line has been interrupted, not dismantled
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
American authorities have dismantled the core infrastructure of QTFY, a China-linked cyber group accused of systematically breaching government, defence, energy and telecommunications networks across the United States and beyond.
What investigators uncovered was not a string of isolated intrusions but something closer to an industrial enterprise. QScan automated the discovery and exploitation of vulnerabilities at a scale no human team could match. QTRouter funnelled malicious traffic through hijacked home routers, commercial proxies and rented servers, laundering the group's Chinese origin until its attacks appeared to come from inside the very networks it was targeting.
A joint FBI, NSA and Cyber National Mission Force advisory says QScan carried more than 200 proof-of-concept exploits and processed over two million scanning and penetration-testing tasks in one day. QTFY used zero-day and known vulnerabilities, then relied on web shells, remote-access tools and stolen credentials for persistence.
The US Department of Justice seized domains hard-coded into both platforms, disabling their communications and authentication. Attorney General Todd Blanche said state-sponsored hackers targeting American infrastructure “will be stopped and prosecuted”. The advisory also says QTFY has researched and integrated artificial intelligence into its processes over the past two years.
Why Does It Matter?
Cyber News Centre has tracked how automation is shortening the interval between disclosure and exploitation. QTFY shows what happens when that speed is combined with an exploit marketplace and a global pool of compromised devices.
The outlook is mixed. Removing the platforms imposes cost, but does not erase the expertise, customer relationships or targeting data behind them. Australian organisations should not treat this as a distant US case. Internet-facing edge devices, contractor access and poorly segmented management systems remain attractive entry points anywhere.
The practical response is familiar but urgent: patch edge infrastructure, isolate critical systems, audit exposed applications and hunt for published indicators. The strategic lesson is larger. Modern cyber campaigns are becoming businesses, with platforms, subcontractors and automation. Defenders must disrupt the machinery, not simply clean up after each intrusion.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Unitree’s Shanghai IPO puts a fast-growing humanoid-robot maker at the centre of China’s effort to turn embodied AI from a laboratory theme into an exportable industrial platform.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!