CyberzSOC

Publication detail
← Back to advisories & guidance

Joint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems ↗ source

August 26, 2026 NSA Advisory
Co-sealed by: CNMF, FBI, NSA

Summary

The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. The cyber actors’ products have enabled hackers to obfuscate their location and target systems in critical infrastructure sectors including defense industrial base (DIB), communications, government, and higher education. This advisory provides details on the actors’ activities; tactics, techniques, and procedures (TTPs); infrastructure details; and indicators of compromise (IOCs). The information is derived from incident response and investigative techniques.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2026-1731
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2021-26855

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2023-22515 10.0 Critical Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence …
CVE-2019-11510 9.9 Critical Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTP…
CVE-2026-1731 9.9 Critical BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow …
CVE-2019-10068 9.8 Critical Kentico Xperience Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVE-2019-19781 9.8 Critical Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticate…
CVE-2020-5902 9.8 Critical F5 BIG-IP F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
CVE-2025-31161 9.8 Critical CrushFTP CrushFTP CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authentica…
CVE-2024-8963 9.4 Critical Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricte…
CVE-2018-13379 9.1 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil…
CVE-2021-26855 9.1 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon e…
CVE-2024-24919 8.6 High Check Point Quantum Security Gateways Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker t…
CVE-2024-8190 7.2 High Ivanti Cloud Services Appliance Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated a…
CVE-2024-9380 7.2 High Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated a…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.