QTFY Distributed Scan & Relay Infrastructure

QT / QTCYBER · QScan, QTRouter, Fast Labyrinth · detection, response, and hardening
Threat
QTFY / QT / QTCYBER
Severity
HIGH
Type
PRC-linked cyber enablement / APT infrastructure
Access
Zero-day and N-day edge exploitation
Version
v0.1 Draft · 2026-09-01
Author
HuntPack
Confidence
High intelligence / static detections
STATIC REVIEW PASSED
01

Executive Summary

QTFY is a PRC-linked cyber-enablement operation attributed by U.S. authorities to Nanjing Xinjiuwei Network Technology. Its QScan platform performs high-volume reconnaissance and exploitation; QTRouter/Fast Labyrinth relays downstream intrusion traffic through compromised IoT devices, commercial proxy services, and leased infrastructure. The documented target set spans government, defense, communications, energy, water, healthcare, finance, higher education, and technology.

Detection strategy: static indicators are useful for retrospective scoping, but the durable signal is a chain: edge scanning or exploitation → web shell or suspicious child process → relay-backed network or authenticated access. The report therefore covers both the edge/endpoint plane and the identity/authentication plane.

Defender priority: hunt current worker and control-plane activity first, then require endpoint, authentication, or follow-on process evidence before containment. The three seized control domains are retrospective evidence, not proof the actor is still operating through those exact names.
02

Source and Claim Review

Five primary-source streams support the pack. The official JCSA and IOC appendices provide the authoritative actor facts and indicators; Black Lotus Labs independently corroborates the platform architecture and observed targeting.

IDPublisherTierVersionContribution
S01FBI / NSA / CNMFT1 government primaryJCSA-20260826-01Attribution, timeline, TTPs, IOCs, mitigations
S02FBI / NSA / CNMFT1 government IOCQTFY_IOC_Files.csv45 exact SHA-256 indicators
S03FBI / NSA / CNMFT1 government IOCQTFY_IOC_Infrastructure.csv390 infrastructure records with dates and roles
S04Lumen Black Lotus LabsT1 independent technical research2026-08-26Fast Labyrinth architecture, telemetry, targets, defensive implications
S05U.S. Department of JusticeT1 government primary2026-08-26 / updated 2026-08-28Domain seizure, platform/customer relationships, disruption status
S06MITRE ATT&CKT1 canonical frameworkEnterprise Groups directoryConfirmed no QTFY group object yet; technique IDs checked
Source discipline: the DOJ seizure made the hard-coded implementation inoperable, but it does not prove permanent actor cessation. Lumen prints two hyphenated task/result hostnames that differ from the dotted government IOC names; those variants remain hunt leads and are not shipped as block indicators.
03

Hunt Brief and Attack Chain

The hunt model deliberately separates the platform/edge plane from identity/authentication. A single IOC hit is triage input; the strongest case joins behavior across two or more stages.

StepPhaseBehaviorATT&CKBucket
1ReconnaissanceQScan maps exposed services and vulnerable configurations at scaleT1595.002Edge/network
2Initial accessZero-day or N-day exploitation of public-facing appliances and applicationsT1190Edge/application
3PersistenceWeb shells, RATs, and obtained legitimate credentialsT1505.003 / inferred T1078Endpoint + identity
4ObfuscationQTRouter chains IoT, commercial proxy, and VPS nodesinferred T1090.002Network
5Follow-on accessLocally plausible relay traffic and valid-account use reach sensitive systemsinferred T1078Identity/auth

Detection hypotheses

IDHypothesisTelemetryQueryBucket
H01Published binaries execute on Falcon-covered systemsProcess hash telemetryQ01Edge/endpoint
H02Systems resolve or contact platform infrastructureDNS and network telemetryQ02–Q03Edge/endpoint
H03An unexpected proxy client supports relay activityProcess telemetryQ04Edge/endpoint
H04Public-facing service exploitation creates a shell or transfer processProcess lineageQ05Edge/endpoint
H05Current workers reach Falcon-covered public servicesAccepted network telemetryQ06Edge/endpoint
H06Relay infrastructure is followed by successful remote authenticationLogon telemetryQ07Identity/auth
H07One remote source fans out across accounts and hostsLogon aggregationQ08Identity/auth
04

Consolidated IOC Table

This view shows 12 representative hashes plus all 13 indicators marked Present. The machine-readable appendix carries all 45 hashes and the current subset; the source snapshots retain all 390 infrastructure records.

TypeValueConfidenceActionContext
SHA-256d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357highdetectagent_linux_386
SHA-2567a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300highdetectagent_linux_amd64
SHA-256c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7ahighdetectagent_linux_arm
SHA-256e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664highdetectagent_linux_arm64
SHA-2566decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224highdetectagent_linux_armhf
SHA-2565329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2highdetectagent_linux_mips
SHA-25669a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089highdetectagent_linux_mips64
SHA-2569759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fahighdetectagent_linux_mips64le
SHA-256dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381ehighdetectagent_linux_mipsle
SHA-256c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3highdetectagent_linux_powerpc
SHA-2564a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009highdetectagent_linux_riscv32
SHA-2566547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87highdetectagent_linux_riscv64
domainsecurelink.qtproxy.xyzmediumhuntactor controlled; marked Present
ipv41.32.216.171mediumhuntactor controlled; marked Present
ipv423.95.220.192mediumhuntactor controlled; marked Present
ipv439.104.208.77mediumhuntactor controlled; marked Present
ipv445.202.210.27mediumhuntactor controlled; marked Present
ipv4206.119.167.207mediumhuntactor controlled; marked Present
ipv4154.64.238.222mediumhuntqscan server; marked Present
ipv4154.64.238.247mediumhuntqscan server; marked Present
ipv427.124.24.220mediumhuntqscan worker; marked Present
ipv427.124.24.237mediumhuntqscan worker; marked Present
ipv445.196.221.138mediumhuntqscan worker; marked Present
ipv4134.122.150.22mediumhuntqscan worker; marked Present
ipv4134.122.150.25mediumhuntqscan worker; marked Present
No blind blocking: IPs can be leased, compromised, shared, or reassigned. Seized domains and post-seizure traffic require resolution/ownership checks. Start all infrastructure indicators in hunt or enrichment mode.
05

ATT&CK Mapping

TacticTechniqueNameBehaviorCoverage
ReconnaissanceT1595.002Vulnerability ScanningQScan checks whether exposed systems match vulnerable configurationsQ06 / native edge logs
Initial AccessT1190Exploit Public-Facing ApplicationZero-day and N-day exploitation of public servicesQ05 / hardening
PersistenceT1505.003Web ShellScripts expose internet-accessible backdoor capabilityQ05 / native web logs
Resource DevelopmentT1583.003Virtual Private ServerLeased VPS nodes support scanning and relay infrastructureQ03 / enrichment
Resource DevelopmentT1587Develop CapabilitiesCustom QScan, QTRouter, and multi-architecture toolingQ01
Command and ControlT1090.002 (inferred)External ProxyCompromised IoT and commercial proxy nodes conceal operator originQ02–Q04
Defense Evasion / PersistenceT1078 (inferred)Valid AccountsObtained legitimate credentials support persistent accessQ07–Q08

The first five mappings are explicitly published in JCSA-20260826-01. T1090.002 and T1078 are analyst mappings retained as inferred because MITRE has not yet published a QTFY group object.

06

Native / Non-CQL Hunts

HuntRequired logsLogicPriority
Edge scan-to-session correlationFirewall, WAF, VPN, IDS/NDR, load balancerJoin low-volume probing to later stable bidirectional sessions or authentication from different relay nodesHigh
Exposed appliance inventoryASM, vulnerability scanner, CMDB, firmware managerFind unsupported firmware, public management planes, known-vulnerable services, and unowned IoT devicesCritical
Web-shell reviewWeb server, EDR, file integrity, reverse proxyCorrelate suspicious requests with new scripts, service child processes, and outbound connectionsHigh
Relay-backed authenticationVPN, IdP, PAM, RDP/SMB, ADFind successful privileged access from consumer/commercial proxy space after edge scanningHigh
DNS and egress baselineRecursive DNS, netflow, proxy, router telemetryFind management/IoT segments contacting new control infrastructure or using unexpected proxy protocolsHigh
Infrastructure lifecyclePassive DNS and certificate historyRevalidate indicator ownership and resolution, especially after the DOJ seizureMedium
Coverage note: QScan reconnaissance often occurs before traffic reaches a Falcon-instrumented host. Perimeter telemetry is required to see denied scans and complete the scan-to-session chain.
07

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Eight hunt-only queries: six cover edge/endpoint behavior and two cover identity/authentication. They passed static checks only and have not been parsed or executed in a Falcon tenant.
Q01 · Published multi-architecture tool hashes
CONF highFP lowCOST medium

Looks for: execution of any of the 45 government-published Linux agent, client, and script hashes. FP: Exact SHA-256 matches should be rare; confirm local sample provenance before containment.

// HUNT: Published multi-architecture Linux tool hashes
// WHAT IT CATCHES: Exact process execution matching the government-published malicious tool set
// MITRE: T1587 Develop Capabilities
// CONF: high | FP: low | COST: medium
// REQUIRES: ProcessRollup2 or SyntheticProcessRollup2 with SHA256HashData
// TIMEFRAME: 365d in the Falcon time picker
// FP NOTES: Exact hashes are campaign-specific; verify the file and host role before response
// TUNING: Do not exclude by filename; exclude only a cryptographically verified authorized sample
#event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/
| in(SHA256HashData, values=["d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357","7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300","c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a","e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664","6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224","5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2","69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089","9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa","dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e","c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3","4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009","6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87","12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec","27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3","32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33","00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188","ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31","7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721","26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c","bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f","ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878","ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651","996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a","ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1","08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9","ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb","5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09","0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2","ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846","dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3","86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb","dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991","239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a","b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce","2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562","5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5","ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c","92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245","c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7","bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990","a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a","c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb","5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7","c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35","0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656"])
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, SHA256HashData, CommandLine, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q02 · Control-plane DNS lookups
CONF mediumFP lowCOST low

Looks for: DNS activity to the published QScan/QTRouter control-plane roots and subdomains. FP: Several domains were seized; post-seizure lookups may be research, security tooling, or sinkhole traffic.

// HUNT: Distributed scan and relay control-plane DNS
// WHAT IT CATCHES: Endpoint DNS requests to published actor-controlled platform infrastructure
// MITRE: T1090.002 External Proxy (analyst mapping)
// CONF: medium | FP: low | COST: low
// REQUIRES: DnsRequest with DomainName and process context
// TIMEFRAME: 90d in the Falcon time picker
// FP NOTES: Threat-intelligence tools and post-seizure sinkhole checks can resolve these names
// TUNING: Exclude only documented security scanners by aid and owner after confirming their purpose
#event_simpleName = DnsRequest
| DomainName = /(^|\.)(qtproxy\.xyz|qt-proxy\.org|qt-team\.com|instantmessagehub\.tech)$/i
| table([@timestamp, aid, ComputerName, UserName, DomainName, ContextBaseFileName, ContextProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q03 · Current infrastructure network contact
CONF mediumFP mediumCOST low

Looks for: endpoint connections to infrastructure marked Present in the official appendix. FP: Proxy, VPS, and compromised-device addresses can be shared or reassigned; require process and timing corroboration.

// HUNT: Current distributed scan and relay infrastructure contact
// WHAT IT CATCHES: Network connections to addresses marked Present in the official IOC appendix
// MITRE: T1090.002 External Proxy (analyst mapping)
// CONF: medium | FP: medium | COST: low
// REQUIRES: NetworkConnectIP4 with remote IP and process context
// TIMEFRAME: 30d in the Falcon time picker
// FP NOTES: Commercial proxies, leased VPSs, and compromised nodes may carry unrelated traffic
// TUNING: Correlate with process rarity, DNS, edge exploitation, and authentication before escalation
#event_simpleName = NetworkConnectIP4
| in(RemoteAddressIP4, values=["1.32.216.171","23.95.220.192","39.104.208.77","45.202.210.27","206.119.167.207","154.64.238.222","154.64.238.247","27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"])
| table([@timestamp, aid, ComputerName, UserName, ContextBaseFileName, RemoteAddressIP4, RemotePort, Protocol_decimal, ContextProcessId_decimal])
| sort(@timestamp, order=desc, limit=1000)
Q04 · Unexpected Clash proxy execution
CONF mediumFP highCOST low

Looks for: Clash execution on endpoints where a commercial proxy client is not approved. FP: Clash is legitimate dual-use software and may be common for developers, researchers, or international users.

// HUNT: Unexpected commercial proxy client execution
// WHAT IT CATCHES: Clash execution that may support chained relay or traffic-obfuscation activity
// MITRE: T1090.002 External Proxy (analyst mapping)
// CONF: medium | FP: high | COST: low
// REQUIRES: ProcessRollup2 or SyntheticProcessRollup2
// TIMEFRAME: 30d in the Falcon time picker
// FP NOTES: Approved developers, researchers, and privacy tooling can legitimately run Clash
// TUNING: Join hits to the approved-software inventory and exclude only owner-approved hashes and hosts
#event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/
| FileName = /^(clash)(\.exe)?$/i
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, SHA256HashData, CommandLine, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q05 · Web service spawning a shell or transfer tool
CONF mediumFP mediumCOST low

Looks for: internet-facing web services creating shells, interpreters, or download utilities after exploitation. FP: Deployment automation and support scripts can create the same parent-child pattern.

// HUNT: Web service child shell or transfer utility
// WHAT IT CATCHES: Suspicious post-exploitation process creation from common web-service parents
// MITRE: T1190 Exploit Public-Facing Application; T1505.003 Web Shell
// CONF: medium | FP: medium | COST: low
// REQUIRES: ProcessRollup2 or SyntheticProcessRollup2 with parent and child fields
// TIMEFRAME: 30d in the Falcon time picker
// FP NOTES: Deployment agents, health checks, and administrator-run web maintenance may match
// TUNING: Baseline approved parent-child-command combinations; never exclude an entire web-service parent
#event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/
| ParentBaseFileName = /^(httpd|apache2|nginx|php-fpm|tomcat|java)(\.exe)?$/i
| FileName = /^(sh|bash|dash|zsh|cmd|powershell|pwsh|python|perl|curl|wget)(\.exe)?$/i
| table([@timestamp, aid, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, SHA256HashData, CommandLine, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q06 · Inbound contact from current scan workers
CONF mediumFP mediumCOST low

Looks for: accepted inbound connections from QScan workers observed in August 2026. FP: Worker IPs rotate and may be reassigned; a connection alone does not prove exploitation.

// HUNT: Inbound contact from current distributed scan workers
// WHAT IT CATCHES: Server-side accepted connections from the newest published worker addresses
// MITRE: T1595.002 Vulnerability Scanning
// CONF: medium | FP: medium | COST: low
// REQUIRES: NetworkReceiveAcceptIP4 on Falcon-covered internet-facing systems
// TIMEFRAME: 30d in the Falcon time picker
// FP NOTES: Reassigned hosting addresses and authorized external scanning can match
// TUNING: Require an exposed-service match or follow-on process, file, or authentication evidence
#event_simpleName = NetworkReceiveAcceptIP4
| in(RemoteAddressIP4, values=["27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"])
| table([@timestamp, aid, ComputerName, ContextBaseFileName, LocalAddressIP4, LocalPort, RemoteAddressIP4, RemotePort, Protocol_decimal, ContextProcessId_decimal])
| sort(@timestamp, order=desc, limit=1000)
Q07 · Remote logon from current infrastructure
CONF mediumFP mediumCOST low

Looks for: successful remote or network logons associated with infrastructure marked Present. FP: Shared commercial proxies and reassigned addresses can create unrelated matches.

// HUNT: Remote authentication from current distributed relay infrastructure
// WHAT IT CATCHES: Successful remote or network logons from published current infrastructure
// MITRE: T1078 Valid Accounts (analyst mapping)
// CONF: medium | FP: medium | COST: low
// REQUIRES: UserLogon with RemoteAddressIP4 and LogonType
// TIMEFRAME: 30d in the Falcon time picker
// FP NOTES: Authorized VPN, proxy, jump-host, or reassigned-IP activity may match
// TUNING: Confirm the account owner, device, MFA record, source ASN, and preceding edge activity
#event_simpleName = UserLogon
| in(LogonType, values=[3,8,9,10])
| in(RemoteAddressIP4, values=["1.32.216.171","23.95.220.192","39.104.208.77","45.202.210.27","206.119.167.207","154.64.238.222","154.64.238.247","27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"])
| table([@timestamp, aid, ComputerName, UserName, UserSid, LogonType, RemoteAddressIP4])
| sort(@timestamp, order=desc, limit=1000)
Q08 · Remote logon source fan-out
CONF lowFP highCOST medium

Looks for: one remote source authenticating to several accounts and hosts, consistent with relay-backed credential reuse. FP: VPN concentrators, jump hosts, VDI, scanners, and help-desk infrastructure commonly fan out.

// HUNT: Remote authentication source fan-out
// WHAT IT CATCHES: One source address successfully authenticating across multiple users and hosts
// MITRE: T1078 Valid Accounts (analyst mapping)
// CONF: low | FP: high | COST: medium
// REQUIRES: UserLogon with remote IP, account, host, and LogonType
// TIMEFRAME: 7d in the Falcon time picker
// FP NOTES: VPN concentrators, jump servers, VDI brokers, scanners, and help-desk systems fan out legitimately
// TUNING: Exclude approved infrastructure by exact address only after ownership and expected account scope are documented
#event_simpleName = UserLogon
| in(LogonType, values=[3,8,9,10])
| RemoteAddressIP4 = *
| groupBy([RemoteAddressIP4], function=[count(as=SuccessfulLogons), count(UserName, distinct=true, as=DistinctUsers), count(aid, distinct=true, as=DistinctHosts), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen), collect(UserName, limit=20), collect(ComputerName, limit=20)], limit=5000)
| DistinctUsers >= 3
| DistinctHosts >= 3
| sort(SuccessfulLogons, order=desc, limit=500)
08

Operationalization and IOA Candidates

All queries remain manual hunt content. No scheduled alert, Custom IOA deployment, or prevention policy is claimed.

IOABehaviorRule typeModeSourcePromotion gate
IOA-01Unexpected web-service child shellProcess CreationDetectQ05Pilot 14+ days; exclude only approved parent-child-command triples
IOA-02Unexpected Clash proxy clientProcess CreationDetectQ04Inventory legitimate use first; do not promote without measured FP rate

Promotion gates

  1. Confirm event and field population in the intended repository.
  2. Run the query over a one-hour window, then the documented lookback.
  3. Execute a benign, non-destructive positive test in an isolated sensor group.
  4. Measure representative benign volume and document exclusions.
  5. Keep detect mode for at least 14 days and require an FP rate below 5% before any prevention review.
09

Machine-Readable IOC Appendix

The import block contains 58 rows: 45 exact hashes and 13 infrastructure indicators marked Present. All are detect-first; operational blocking requires local review.

Falcon IOC Management CSV58 rows
type,value,action,severity,expiration,description,tags
sha256,d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
sha256,0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01
domain,securelink.qtproxy.xyz,detect,medium,2026-11-30,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,1.32.216.171,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,23.95.220.192,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,39.104.208.77,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,45.202.210.27,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,206.119.167.207,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,154.64.238.222,detect,medium,2026-10-01,qscan server marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,154.64.238.247,detect,medium,2026-10-01,qscan server marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,27.124.24.220,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,27.124.24.237,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,45.196.221.138,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,134.122.150.22,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
ipv4,134.122.150.25,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
Published SHA-256 values45 values
d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357
7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300
c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a
e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664
6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224
5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2
69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089
9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa
dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e
c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3
4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009
6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87
12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec
27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3
32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33
00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188
ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31
7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721
26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c
bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f
ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878
ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651
996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a
ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1
08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9
ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb
5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09
0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2
ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846
dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3
86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb
dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991
239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a
b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce
2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562
5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5
ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c
92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245
c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7
bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990
a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a
c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb
5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7
c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35
0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656
Indicators marked Present13 values
domain,securelink.qtproxy.xyz,actor controlled
ipv4,1.32.216.171,actor controlled
ipv4,23.95.220.192,actor controlled
ipv4,39.104.208.77,actor controlled
ipv4,45.202.210.27,actor controlled
ipv4,206.119.167.207,actor controlled
ipv4,154.64.238.222,qscan server
ipv4,154.64.238.247,qscan server
ipv4,27.124.24.220,qscan worker
ipv4,27.124.24.237,qscan worker
ipv4,45.196.221.138,qscan worker
ipv4,134.122.150.22,qscan worker
ipv4,134.122.150.25,qscan worker
Behavioral signaturesdurable pivots
QScan: distributed vulnerability scanning and exploitation
QTRouter: IoT/commercial-proxy/VPS relay chaining
Web service -> shell/interpreter/transfer-tool process
Edge probe -> stable session -> remote authentication
Unexpected Clash execution on managed systems
One remote source -> multiple users and hosts
10

Hardening — Tiered and Deployable

Immediate — this week
  • Patch exposed edge and web systems. Prioritize internet-facing firmware and applications, enable automatic updates where operationally safe, and replace end-of-support devices. Trace: T1190 → MITRE M1051, M1016; JCSA-20260826-01.
  • Remove public management exposure. Bind administration to dedicated interfaces or VPN/jump paths and allowlist approved sources. Trace: T1190 → MITRE M1030, M1037; vendor appliance hardening guidance.
  • Hunt before eviction. Preserve edge, DNS, authentication, and process evidence; isolate only demonstrated-compromised devices and revoke only exposed credentials. Trace: T1505.003 / inferred T1078; JCSA incident-response guidance.
Near term — 1 to 4 weeks
  • Segment edge and IoT from critical systems. Deny direct management-plane and lateral paths except documented flows. Trace: T1190 / inferred T1090.002 → MITRE M1030, M1037; CISA zero-trust guidance.
  • Constrain relay and proxy software. Inventory Clash and other approved proxy clients; use application control and egress policy on fixed-purpose systems. Trace: inferred T1090.002 → MITRE M1037, M1038.
  • Harden remote identity. Require phishing-resistant MFA and PAM for privileged/remote access; rotate secrets reachable from compromised edge devices. Trace: inferred T1078 → MITRE M1032, M1026, M1018.
Strategic — 1 to 3 months
  • Build long-window scan-to-session analytics. Retain passive DNS, perimeter, VPN, authentication, and endpoint telemetry long enough to correlate rotating workers with later access. Trace: T1595.002 / T1190 → MITRE M1047.
  • Establish edge lifecycle governance. Maintain owner, support date, firmware, exposure, and recovery records for routers, VPNs, firewalls, IoT, and remote-support systems. Trace: T1190 → MITRE M1016, M1051.

Deployable change checklist

1. Export the internet-facing asset inventory and current configurations.
2. Identify end-of-support devices and public management interfaces.
3. Patch a representative pilot; validate service health and rollback artifacts.
4. Restrict management to approved VPN/jump sources; test normal and emergency access.
5. Forward DNS, auth, edge, and configuration-change logs to protected storage.
6. Inventory proxy clients and relay protocols; baseline before enforcing egress controls.
7. Expand only after owners sign off and the pilot has no unexplained impact.

Rollback: restore the exported configuration, previous ACL/policy, and approved firmware image; verify service, logging, and emergency access.
11

Containment Runbook

PhaseTriggerOwnerEvidenceSafety constraint
1. ConfirmCorrelated IOC or behavior across edge/endpoint and authSOCRaw logs, timeline, asset ownerDo not block shared infrastructure on one hit
2. ScopeEvidence suggests exploitation or unauthorized sessionIR leadAffected devices, accounts, adjacent systemsPreserve volatile appliance data first
3. ContainCompromise confirmedIR + service ownerIsolation and dependency recordUse tested bypass/rollback path
4. EvictEvidence collection sufficientIR + identity/networkRebuild record, credential revocation, control-plane changesRebuild edge devices; do not trust in-place cleanup alone
5. RecoverKnown-good configuration and credentials readyService ownerHealth checks, monitoring, business validationRestore in stages with heightened logging
6. Re-huntRecovery complete or new IOC publishedDetection engineeringQuery results and closure decisionReopen if relay/auth behavior persists

Escalate immediately: a published hash on an edge device, a web-service child shell followed by relay traffic, or privileged authentication from current infrastructure with no approved business explanation.

12

Detection Coverage and Validation Evidence

Validation state: STATIC REVIEW PASSED. This label covers local structure, active-content safety, field, syntax-heuristic, and IOC-provenance gates only. It is not Falcon tenant parsing, canary success, or deployment evidence.

TechniqueBehaviorCQLIOACoverageGap
T1595.002Vulnerability scanningQ06 + native perimeter huntPartialDenied probes require firewall/IDS telemetry
T1190Public-facing exploitationQ05IOA-01PartialExploit-specific appliance logs are tenant/product dependent
T1505.003Web shellQ05 + native web huntIOA-01PartialFile paths and web-shell families were not published
T1583.003VPS infrastructureQ03PartialShared hosting reduces indicator confidence
T1587Develop capabilitiesQ01Good45 exact published hashes
T1090.002 inferredExternal proxyQ02–Q04IOA-02PartialProxy telemetry and device coverage vary
T1078 inferredValid accountsQ07–Q08PartialMFA/IdP evidence requires native logs

Required tenant gates

  • Confirm every event and field exists in the selected Falcon repository.
  • Parse each query manually in a one-hour window.
  • Measure returned volume and review representative benign hits.
  • Run only benign tests in an isolated sensor group.
  • Keep every IOA in Detect until the false-positive rate is measured and approved.
13

Hunt Summary Ticket

TITLE:        QTFY distributed scanning and relay infrastructure hunt
SEVERITY:     HIGH — state-linked enablement targeting government and critical infrastructure
SCOPE:        Internet-facing edge, Linux/endpoint process, DNS/network, and remote-authentication telemetry
HYPOTHESIS:   QScan/QTRouter activity creates a scan or IOC signal followed by process, relay, or valid-account evidence
QUERIES:      Q01–Q06 edge/endpoint; Q07–Q08 identity/authentication
DO FIRST:     Q01, Q02, Q03, Q06, and Q07 using the card-specific lookbacks
FINDINGS:
GAPS:         Denied scans, appliance telemetry, proxy attribution, MFA/IdP detail, and tenant parse evidence
ACTIONS:      Correlate before blocking; preserve edge evidence; verify current indicator ownership
OWNER:        SOC / Detection Engineering / Network / Identity / Edge Platform
VERSION:      v0.1 Draft · 2026-09-01 · STATIC REVIEW PASSED
14

Changelog

v0.1 Draft2026-09-01Initial QTFY pack: eight hunt-only CQL queries, 45 file hashes, 390 preserved infrastructure indicators, tiered hardening, and a six-phase containment runbook.
15

References

IDPublisherVersion/dateAccessedUseURL
S01FBI / NSA / CNMFJCSA-20260826-012026-09-01Attribution, timeline, TTPs, IOCs, mitigationshttps://www.ic3.gov/CSA/2026/260826.pdf
S02FBI / NSA / CNMFQTFY_IOC_Files.csv2026-09-0145 exact SHA-256 indicatorshttps://www.ic3.gov/CSA/2026/QTFY_IOC_Files.csv
S03FBI / NSA / CNMFQTFY_IOC_Infrastructure.csv2026-09-01390 infrastructure records with dates and roleshttps://www.ic3.gov/CSA/2026/QTFY_IOC_Infrastructure.csv
S04Lumen Black Lotus Labs2026-08-262026-09-01Fast Labyrinth architecture, telemetry, targets, defensive implicationshttps://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model
S05U.S. Department of Justice2026-08-26 / updated 2026-08-282026-09-01Domain seizure, platform/customer relationships, disruption statushttps://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
S06MITRE ATT&CKEnterprise Groups directory2026-09-01Confirmed no QTFY group object yet; technique IDs checkedhttps://attack.mitre.org/groups/