Cyber Update: China’s hacking assembly line has been interrupted, not dismantled

US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.

Cyber Update: China’s hacking assembly line has been interrupted, not dismantled

Cyber Update

American authorities have dismantled the core infrastructure of QTFY, a China-linked cyber group accused of systematically breaching government, defence, energy and telecommunications networks across the United States and beyond.

What investigators uncovered was not a string of isolated intrusions but something closer to an industrial enterprise. QScan automated the discovery and exploitation of vulnerabilities at a scale no human team could match. QTRouter funnelled malicious traffic through hijacked home routers, commercial proxies and rented servers, laundering the group's Chinese origin until its attacks appeared to come from inside the very networks it was targeting.

A joint FBI, NSA and Cyber National Mission Force advisory says QScan carried more than 200 proof-of-concept exploits and processed over two million scanning and penetration-testing tasks in one day. QTFY used zero-day and known vulnerabilities, then relied on web shells, remote-access tools and stolen credentials for persistence.

The US Department of Justice seized domains hard-coded into both platforms, disabling their communications and authentication. Attorney General Todd Blanche said state-sponsored hackers targeting American infrastructure “will be stopped and prosecuted”. The advisory also says QTFY has researched and integrated artificial intelligence into its processes over the past two years.

Why Does It Matter?

Cyber News Centre has tracked how automation is shortening the interval between disclosure and exploitation. QTFY shows what happens when that speed is combined with an exploit marketplace and a global pool of compromised devices.

The outlook is mixed. Removing the platforms imposes cost, but does not erase the expertise, customer relationships or targeting data behind them. Australian organisations should not treat this as a distant US case. Internet-facing edge devices, contractor access and poorly segmented management systems remain attractive entry points anywhere.

The practical response is familiar but urgent: patch edge infrastructure, isolate critical systems, audit exposed applications and hunt for published indicators. The strategic lesson is larger. Modern cyber campaigns are becoming businesses, with platforms, subcontractors and automation. Defenders must disrupt the machinery, not simply clean up after each intrusion.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.