The Justice Department and FBI recently dismantled platforms used by Chinese state-sponsored hackers to infiltrate critical U.S. infrastructure. An affidavit reveals over 300 U.S. organizations were compromised in a 2024 campaign, including financial institutions, though none were named publicly.
Here's what your fraud risk management team needs to know about the campaign, what went wrong, and how you can improve your defenses.
What Happened
QTFY, a group linked to Nanjing Xinjiuwei Network Technology Co., sold hacking services to China's Ministry of State Security and the People's Liberation Army. They operated two platforms: QScan, which identified and exploited vulnerable machines, and QTRouter, a botnet network that masked attack origins by routing traffic through compromised home routers and security cameras.
The attackers exploited unpatched vulnerabilities in remote-access and network security products from Check Point, Pulse Secure, Citrix, Ivanti, and BeyondTrust. They stole server configurations and user account details from victims in defense contracting, financial services, and universities.
The FBI affidavit details four earlier victims who reported suspicious activity to Hostwinds, a U.S. hosting company used by the attackers. Three were financial or insurance firms: a South Korean financial group reported scanning activity, a Michigan financial group documented eight attack addresses over a month, and a Missouri insurance agency reported targeting through a Citrix flaw.
Timeline
QTFY has exploited unpatched software since 2019. The affidavit focuses on a 2024 campaign affecting over 300 organizations. The Justice Department's recent platform seizures rendered QScan and QTRouter inoperable.
This seven-year window is significant. If your team uses any products named in the advisory, you're not just looking for current threats. You need to check historical logs for potential exposure dating back years.
Which Controls Failed
Patch management was inadequate. Exploiting unpatched software accounts for 22% of breaches in the financial sector, according to Verizon's 2026 Data Breach Investigations Report. The advisory highlights vulnerabilities in common remote-access and network security products. These are not rare cases; they're the systems your employees use daily.
Network segmentation was lacking. The advisory recommends isolating critical systems from edge devices like firewalls and remote-access gateways. While large banks should already have this separation due to regulatory expectations, implementing it later requires significant investment and time.
Traditional IP-based blocking was ineffective. QTRouter routed attacks through a botnet of compromised consumer devices. When malicious traffic originates from a home router, you can't rely on geography or reputation lists. Detection requires behavioral analysis and context, not just source addresses.
Detection capabilities varied by institution size. The fact that three of the four victims were financial institutions likely reflects the sector's stronger detection and reporting capabilities, but "stronger" doesn't mean "sufficient." Large banks generally have the tools for behavioral detection, but coverage isn't guaranteed. Midsize banks can achieve meaningful coverage with internal controls and an external provider, but not with the same depth.
What the Standards Require
PCI DSS Requirement 6.3.1 requires removing or patching security vulnerabilities within defined time frames based on risk ranking, with critical patches needing action within one month of release.
The FFIEC IT Examination Handbook expects financial institutions to maintain current patch levels and implement compensating controls when patching isn't feasible. It also requires network segmentation to limit compromise scope.
The NIST Cybersecurity Framework function PR.IP-12 calls for a vulnerability management plan addressing newly discovered vulnerabilities promptly. The detection function (DE.CM) requires monitoring for unauthorized activity, including the behavioral analysis needed to catch botnet-routed traffic.
These requirements aren't new. What's new is the consequence of ignoring them: a state-sponsored actor had years to map your environment, extract credentials, and establish persistence before detection.
Lessons and Action Items
Search your logs for the 390 indicators of compromise listed in the advisory. Route this task to your managed security provider or incident-response firm if internal staff is insufficient. This isn't a heavy lift for a midsize bank, but someone must triage the results.
If you use Check Point, Pulse Secure, Citrix, Ivanti, or BeyondTrust products, confirm they were patched and check for exposure from 2019 onward. This is about historical logs, not real-time threats.
Check the Chinese companies named in the advisory against your business relationships. A match should trigger further investigation.
Audit for equipment past its end of support. Unsupported products don't receive patches, making them permanent vulnerabilities. Replace or isolate them completely.
Stop leaking operational details through internet-facing applications. Error messages, version banners, and directory listings reveal vulnerabilities to attackers.
Build segmentation between critical systems and edge devices. Treat this as a business decision. Agree on which services are critical before designing isolation around them.
Implement behavioral detection for traffic from consumer IP addresses. Source address blocking won't catch botnet-routed attacks. Use tools that analyze session behavior and context instead.
The seizures disrupted QTFY's operations, but this disruption is temporary. The Chinese market has other scanning services. How you use the seven-year window documented in this advisory will determine if you're prepared for the next campaign.



