QTFY Advisory Exposes a Contractor Network

On August 26, the FBI, NSA, and U.S. Cyber Command’s Cyber National Mission Force tied China-linked QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW) and said the group targeted U.S. government and critical-infrastructure networks, including NASA, the Federal Reserve, and the Department of Energy. The same advisory points to business ties with ELEX and Lexbell, widening the attribution from a single actor to the companies and people around it. The reporting says ELEX’s public client lists showed years of work for state and public-security customers, while Lexbell’s leadership and contract history point to People’s Liberation Army connections. In plain terms, the advisory is not just naming who QTFY is; it is showing how commercial cyber firms and former military personnel can provide the delivery path for state operations. For defenders, the exposure sits in the vendor ecosystem as much as in any one tool or account. If a security supplier, subcontractor, or training provider also has public ties into state customers or military-linked staffing, that relationship can be part of the targeting model that reaches agencies and critical infrastructure.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: QTFY Advisory Exposes a Contractor Network

Sources