Skip to content
skopnix
← adversaries
Unknown · assessed origin China

QTFY

misp-galaxyrefreshed 2026-09-15

sigil

Last 30 days

last seen 5 d ago

3
dispatches
0
victims
0
CVEs seen
What changed
  • 4 d agoresurfacedback on the wire after 15 quiet days
Analyst brief

QTFY is a state-sponsored group from the People's Republic of China, operating as an infrastructure quartermaster that provides reconnaissance, access, and obfuscation services to various state customers, including the MSS and PLA. It developed QScan and QTRouter, leveraging high-tier commercial proxy services like fastlink.ws to obscure its traffic. QTFY personnel, including former PLA members, engage in exploit brokering and operate within a supply chain rather than merely deploying malware. The group has been linked to specific domains and infrastructure, with evidence of TLS certificate collection as part of its operational tactics.

Take it with you
References
Early access

Track QTFY on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected