Post

Widening the Circle of Chinese Hacker Group QTFY ELEX's Intelligence Client List and Lexbell's PLA Contracts

Widening the Circle of Chinese Hacker Group QTFY ELEX's Intelligence Client List and Lexbell's PLA Contracts

Widening the Circle of Chinese Hacker Group QTFY: ELEX’s Intelligence Client List and Lexbell’s PLA Contracts

On August 26, 2026, the FBI, NSA, and U.S. Cyber Command’s Cyber National Mission Force released a joint cybersecurity advisory on the China-linked hacking group QTFY, attributing it to Nanjing Xinjiuwei Network Technology Co. (XJW) (南京鑫玖维网络科技有限公司). Since at least 2018, QTFY has allegedly developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and targeted a wide range of U.S. government and critical-infrastructure networks, including the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. 🚀

In its “QTFY Background” section, the advisory argues that XJW is linked to China’s Ministry of State Security (MSS) and highlights two primary channels of contact with state entities: Business relationships, where XJW maintains business ties with larger China-based cybersecurity firms specializing in critical infrastructure security that allegedly facilitate operations against victim organizations; and Personnel networks, where QTFY actors include former People’s Liberation Army (PLA) members who leverage military contacts to obtain contracts and subcontracting opportunities related to critical infrastructure targeting.

The advisory named entities with which XJW had business relationships as of June 2026, including two MSS units - Unit 0718 and Unit 9086; two state entities - the Hunan Province Ecological and Environmental Construction Management Office and the China Information Technology Testing and Evaluation Center, Jilin Subcenter; and five companies, including Bozhi Security Technology (ELEX) and Nanjing Lexbell Information Technology. This piece examines ELEX and Lexbell as case studies of these two channels in practice.

The analysis found that ELEX’s capabilities include its status as a leading cyber range provider in China and its expertise in vulnerability scanning and influence operations, alongside products with intelligence and military applications. ELEX’s activity extends well beyond its stated business relationship with XJW, as the company’s own website listed its clients, including MSS and Ministry of Public Security (MPS) provincial bureaus alongside PLA-affiliated entities. For Lexbell, the examination revealed its products with explicit military applications and reported PLA use, its leadership’s PLA-linked background, and its growing record of contract wins with PLA-affiliated National University of Defense Technology (NUDT).

Read full article

This post is licensed under CC BY 4.0 by the author.