CSIDB logo
Incident

National Aeronautics and Space Administration

Incident posture

Attack window
2019
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 12:19

Linked entities

Victim
National Aeronautics and Space Administration
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A China-linked hacking group known as QTFY, operating through a China-based company with ties to the Ministry of State Security and the People's Liberation Army, conducted widespread cyber intrusions against over 300 organizations, including U.S. defense contractors, financial institutions, universities, and government agencies. The hackers exploited multiple vulnerabilities—including a Check Point flaw that stole data from hundreds of victims and zero-day flaws in Ivanti Cloud Services Appliance software—to breach three Department of Energy national laboratories, the National Institutes of Health, and the Health Resources and Services Administration. An attempt to infiltrate the National Aeronautics and Space Administration in 2019 through a virtual private network vulnerability failed because the agency had already patched the flaw. The FBI ultimately seized three domains powering QTFY's QScan scanning platform and QTRouter anonymization network, disrupting the group's ability to operate.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Chinese state-linked hackers operating under the group name QTFY conducted a large-scale cyber campaign that compromised more than 300 organizations in the United States and abroad, including U.S. defense contractors, financial institutions, universities, three U.S. Department of Energy national laboratories, the National Institutes of Health, and the Health Resources and Services Administration, according to court records and advisories unsealed after an FBI takedown operation in August 2026. QTFY operated through a China-based company that the FBI said sold hacking services to clients including China's Ministry of State Security and the People's Liberation Army. Former PLA members worked for the company and used military relationships to secure contracts and subcontracts for offensive cyber operations, according to an FBI affidavit. The group paired mass internet scanning with a network of compromised routers, cameras, and other internet-connected devices to disguise the origin of their attacks, routing malicious traffic through devices near a victim's network so that activity would blend in with legitimate local traffic and become harder to trace.

The FBI and Justice Department seized three domains on a Wednesday in August 2026 that powered QTFY's two main platforms: QScan, which hunted for vulnerable systems, and QTRouter, which masked hackers' identities by routing their traffic through compromised devices. Federal authorities said the seizures crippled both platforms by cutting off domains used for core communications and authentication. The scale of QTFY's operations was significant; on a single day in 2024, QScan processed more than 2 million scanning and penetration-testing tasks, according to the FBI affidavit. The platform contained more than 200 proof-of-concept exploits and searched the internet for vulnerable software, exposed services, and other openings hackers could exploit. Federal authorities said QTFY targeted NASA, the Justice Department, the Federal Reserve, and Senate systems, along with power companies, hospitals, telecommunications providers, defense contractors, and election infrastructure.

Not every attack succeeded. In 2019, QTFY tried to break into NASA using a vulnerability in the agency's virtual private network, but the attempt failed because NASA had already patched the flaw, according to the affidavit. A separate advisory from the FBI, NSA, and Cyber National Mission Force said the group scanned Senate and hospital-system networks in March and a U.S. election system in June but failed to gain access in those cases as well. Other attacks did succeed. In May 2024, QTFY exploited a recently disclosed Check Point vulnerability while scanning U.S. power and telecommunications companies and stole data from more than 300 organizations in the United States and abroad, according to the advisory. Four months later, in September 2024, hackers exploited zero-day flaws in Ivanti Cloud Services Appliance software to gain access to three Department of Energy national laboratories, the National Institutes of Health, the Health Resources and Services Administration, and a U.S. security-device manufacturer. The advisory did not disclose what information was accessed, how long the hackers remained inside the networks, or whether the breaches disrupted operations. Attorney General Todd Blanche stated, "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," in announcing the seizures. The takedown adds to a series of FBI operations targeting Chinese government-linked hacking infrastructure, including the 2023 disruption of a botnet used by Volt Typhoon, the 2024 disabling of a botnet linked to Flax Typhoon, and last year's removal of PlugX surveillance malware from more than 4,000 U.S. computers infected by Mustang Panda.

Sources

Sources available to members: 1 source.

CSIDB