The Federal Reserve has a great cybersecurity program. So does the Department of Justice, the Department of Energy, the National Institutes of Health, and the U.S. Senate. All were on the confirmed victim list when the Justice Department and FBI seized QTFY’s hacking platforms last week. All were running security appliances that were, in a technical sense, doing exactly what they were designed to do.
That is the point. The security appliances were doing their job. They were doing it for the attacker.
The DOJ announcement documented a Chinese state-sponsored operation, QTFY, linked to China’s Ministry of State Security and People’s Liberation Army, active since May 2018. Eight years. The platforms seized, QScan and QTRouter, were purpose-built to find, compromise, and weaponize edge devices: the firewalls, VPN concentrators, and network appliances organizations install specifically to protect their perimeters. Once QTRouter deployed custom OpenWrt firmware to a compromised device, that device stopped being a security control. It became an operational relay node under PRC control.
This is the third major PRC operation in recent years following the same strategic playbook. Volt Typhoon ran for five years through compromised SOHO routers before CISA began formally documenting the campaign in 2023. Salt Typhoon worked through telecommunications network edge infrastructure, touching more than 200 organizations across 80 countries. QTFY did not invent a new strategy. It industrialized the one that kept working.
TL;DR
The DOJ and FBI seized QTFY’s QScan and QTRouter platforms in August 2026, disrupting a PRC state-sponsored operation that had been running since May 2018 against the Federal Reserve, DOE, DOJ, NIH, and the U.S. Senate
QTFY’s tooling was purpose-built to exploit edge security appliances (Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, F5 BIG-IP, Check Point Quantum Gateway) and convert them into persistent operational relay nodes running custom firmware
QTFY is the third confirmed PRC operation following the same edge-device playbook: Volt Typhoon used SOHO routers; Salt Typhoon used telecom network infrastructure; QTFY built automation to scale both approaches
Owning the device that enforces your security policy is operationally superior to defeating the policy; once inside an edge appliance, attackers route traffic through your own controls
Containing the blast radius from a compromised boundary device requires Communication Governance at the workload level, not just at the perimeter
What the Seizure Actually Revealed
QTFY’s tooling is not a collection of improvised scripts. It is a product suite.
QScan is an IoT device scanner and exploitation framework built specifically to identify and compromise edge devices at scale. QTRouter is a traffic obfuscation platform that installs custom OpenWrt firmware on compromised routers and chains them together as persistent operational relay nodes. Fast Labyrinth is a commercial proxy relay network layered on top of QTRouter, providing geographic distribution and attribution masking. QTProxy manages the resulting node infrastructure across active operations.
A criminal group improvises. A nation-state builds a product roadmap. The existence of QTRouter, a purpose-built firmware deployment and management system for maintaining persistent control over compromised edge devices, tells you exactly how QTFY categorized those devices: not as targets, but as infrastructure.
The vulnerability list confirms the intent. According to the DOJ complaint, QTFY exploited a zero-day in Ivanti CSA, plus known vulnerabilities in Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Check Point Quantum Gateway, BeyondTrust Remote Support, Apache Log4j, Atlassian Confluence, CrushFTP, and Kentico CMS. Look at the first entries on that list. Ivanti CSA. Fortinet SSL-VPN. Citrix ADC. F5 BIG-IP. Check Point Quantum Gateway. These are security appliances. Network edge devices. The products organizations procured specifically to protect the perimeter.
The attacker’s goal was not to find a way past the security stack. It was to find a way into it. FBI Director Kash Patel put the operational purpose plainly: “These tools were used by PRC cyber actors to hide the origin of their attacks.” The compromised devices were not collateral victims. They were the operational infrastructure.
The Third Chapter of the Same Manual
QTFY is not an anomaly. It is a progression.
Volt Typhoon, documented in CISA advisories beginning in 2023, built persistent access through compromised small office and home office routers. The technique was consistent: compromise the device that sits between the internet and the internal network, use it as a relay to mask origin and blend with legitimate traffic, and move slowly enough to avoid triggering automated alerting. In some victim environments, CISA documented access maintained for at least five years. Five years of attacker-controlled traffic flowing through devices nobody had treated as a meaningful attack surface.
Salt Typhoon worked through the network edge of the telecommunications sector. AT&T, Verizon, T-Mobile, and more than 200 other organizations across 80 countries confirmed compromise. The entry point was not a phishing campaign or a malicious package in a software registry. It was the network infrastructure itself: the switches, routers, and management systems that sit at the boundary of carrier networks.
The through line across all three, documented in depth at the Aviatrix Threat Research Center, is not technical sophistication. It is consistency. PRC actors have returned to the same attack surface for the better part of a decade because it keeps working.
QTFY extends the pattern from manual exploitation to systematic tooling. QScan automates the edge device discovery and exploitation workflow that Volt Typhoon ran by hand. QTRouter automates the firmware deployment and relay chaining that Salt Typhoon’s operators configured manually. The tactics are not new. The scaling mechanism is.
When a threat actor stops doing something manually and starts building tools to do it automatically, that is not a sign of desperation. It is a sign they have found an attack surface worth industrializing. Eight years of undetected operations across federal agencies, research institutions, and critical infrastructure confirms the assessment was correct.
What Happens When the Firewall Is the Foothold
The reason this pattern persists across three separate operations, two administrations, and nearly a decade is structural. It is not a gap in any specific product. It is a gap in the underlying architectural assumption.
Most security architectures are built on Chokepoint Security: the premise that the edge device is the primary trust boundary and that traffic clearing it can be trusted. The enforcement model depends entirely on the assumption that the boundary device is trustworthy.
QTFY, Volt Typhoon, and Salt Typhoon are all built on the inverse. They target boundary devices precisely because owning the device that enforces policy is operationally superior to defeating the policy. Once QTRouter installs custom firmware on a compromised router or firewall, the situation is no longer “attacker bypassed the firewall.” The situation is “the firewall is now routing attacker traffic as legitimate.”
Downstream security controls, SIEM detections, behavioral analytics, endpoint agents, see that traffic originating from a trusted network device. Attribution masking is architectural, not just technical. Dwell time extends because there is no signature to match and no obvious anomaly to surface. Mandiant and Google Threat Intelligence Group documented an average dwell time of 393 days across BRICKSTORM-affected environments, and those were VMware appliances sitting outside most SIEM scopes. Edge devices managed by vendor firmware face the same visibility gap.
The blast radius from a compromised edge device under this model is everything the device can reach. For a VPN concentrator or perimeter firewall, that is typically the entire internal network.
Closing this gap requires a different architectural posture: treat every internal network path as something that requires explicit governance, independent of whether traffic crossed the perimeter cleanly. Communication Governance at the workload level, where each workload is permitted only the connections it explicitly requires, means a compromised boundary device can route traffic through the paths it controls. What it cannot do is use that position to reach workloads that do not permit connections from that path. The blast radius becomes the specific traffic the compromised device handles, not every system in the environment.
This is not a firewall replacement. It is the architectural layer that makes a compromised firewall a contained problem instead of a complete loss.
Four Questions for Your Next Architecture Review
Is your security architecture designed to function if a perimeter device is compromised? Most environments are designed to prevent perimeter compromise, not to contain the blast radius when it occurs. QTFY’s eight-year campaign is the cost of that assumption. The strategic question for your next board or leadership review is not whether you have good edge appliances. It is whether your internal architecture still enforces meaningful constraints if those appliances are working against you. If the answer depends entirely on the perimeter device being clean, that is an architectural gap worth closing.
What is the blast radius from your most critical boundary devices, documented concretely? Map it. Not as a concept but as a specific list: if your Fortinet SSL-VPN or Ivanti CSA appliance were running firmware you did not install, what internal systems could it reach? What authentication sessions transit through it? What east-west traffic is it positioned to intercept or redirect? That is the blast radius QTFY was operating inside for eight years at your federal counterparts. It should be a finite, known number at your organization, not something you have to reason through on the fly.
How quickly would you detect unauthorized firmware changes on managed network devices? QTRouter works by deploying custom OpenWrt to compromised routers. That requires either a firmware-level exploit or access to a privileged management account. Both leave traces if monitoring is in place. If your answer to detection time is measured in weeks or months, the exposure is worth quantifying. Firmware integrity monitoring for internet-facing network appliances is not a sophisticated ask. It is the specific control that QTRouter was designed to circumvent.
Are your edge security appliances inside your visibility perimeter or outside it? The question sounds redundant. It is not. In the environments most severely affected by prior PRC operations, network appliances sat outside SIEM scope: excluded from centralized logging, with no detection logic written for their behavior. The devices that should have been part of the answer were outside the question entirely. Your Fortinet, Ivanti, and Citrix appliances need to generate logs your team can actually query, with detection rules written for the specific attacker behaviors these campaigns demonstrated.
The Bottom Line
The Justice Department’s QTFY seizure does not close a chapter. It documents a strategy that three independent PRC operations confirmed across eight years: edge devices, specifically the security appliances organizations trust to enforce the perimeter, are the preferred entry point for China’s most capable state-sponsored actors. The tooling exists. The target list includes the most security-conscious organizations in the federal government. The operations ran for nearly a decade before disruption.
The environments that contained the damage had stopped treating perimeter clearance as the final trust decision. In those architectures, a compromised router routes attacker traffic through the paths it controls. What it cannot do is reach workloads that do not permit connections from that path. The Containment Era is not about stopping the edge device from being targeted. It is about making sure the blast radius stops there. Communication Governance at the workload level is what closes the gap between a compromised boundary device and a compromised network.
If you want to see where your current architecture’s blast radius extends from any compromised boundary device, the free Workload Attack Path Assessment maps it for you. If you want the full operational analysis of QTFY, Volt Typhoon, Salt Typhoon, and how PRC actors move through cloud and enterprise infrastructure, that research is at the Aviatrix Threat Research Center.
FAQ
Why do PRC-linked threat actors consistently target edge devices rather than endpoints or applications? Edge devices handle authentication, routing, and traffic inspection for the entire environment from a single privileged position. Compromising one device with that level of network access is more operationally valuable than compromising many individual endpoints. A Fortinet SSL-VPN or Ivanti CSA appliance sees every transiting session and controls what traffic reaches internal systems. For a nation-state actor conducting long-term espionage, that vantage point is worth the investment in purpose-built tooling. QScan and QTRouter exist because that investment paid off for years before disruption.
The FBI disrupted QTFY’s infrastructure. Does that mean the risk is resolved? Seizure of command-and-control infrastructure disrupts active operations but does not remove implants already deployed in victim environments. If edge devices in your environment were compromised by QTFY tooling before the seizure, the custom firmware QTRouter installs may still be present. The immediate operational priority is firmware integrity verification on internet-facing network appliances, particularly those running Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, F5 BIG-IP, and Check Point Quantum Gateway.
The confirmed victim list looks like a government target list. Should private sector organizations be concerned? Yes. QTFY’s confirmed victims include agencies with clear national security profiles, but the same tooling also operated against academic research institutions and commercial infrastructure. Nation-state actors targeting critical infrastructure do not observe a firm government-to-private-sector boundary when both sectors carry sensitive data or connect to systems that touch government operations. The sectors most at risk are those with research data, financial system access, or vendor and contractor relationships to critical infrastructure.
How is QTFY different from Volt Typhoon or Salt Typhoon? All three are PRC state-sponsored operations following the same strategic edge-device playbook. The primary difference is tooling maturity. Volt Typhoon relied on living-off-the-land techniques using existing device capabilities. Salt Typhoon targeted purpose-built telecommunications infrastructure. QTFY built a dedicated toolchain: QScan for discovery and exploitation, QTRouter for firmware deployment, Fast Labyrinth for relay orchestration. This is a progression from manual intrusion operations to scalable campaign infrastructure. The target and technique are the same. The operational throughput is not.
What does workload-level Communication Governance actually change in this scenario? When a compromised edge device routes traffic under attacker control, the attacker gains a privileged network position. What they can do from that position depends on what the rest of the environment permits. Workloads governed by explicit Communication Governance policies, where only known-required connections are permitted and everything else is denied, limit what is reachable from any compromise point, including a compromised boundary device. The architecture does not prevent the initial edge device compromise. It contains the blast radius of that compromise to the specific paths the attacker controls rather than every path in the environment.
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.




