Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
QTFY is a state-sponsored group from the People's Republic of China, operating as an infrastructure quartermaster that provides reconnaissance, access, and obfuscation services to various state customers, including the MSS and PLA. It developed QScan and QTRouter, leveraging high-tier commercial proxy services like fastlink.ws to obscure its traffic. QTFY personnel, including former PLA members, engage in exploit brokering and operate within a supply chain rather than merely deploying malware. The group has been linked to specific domains and infrastructure, with evidence of TLS certificate collection as part of its operational tactics.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database