Treasury
3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp 3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp 3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp 3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp 3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp 3-MO 3.85% -1bp 6-MO 3.94% -1bp 1-YR 4.02% +1bp 2-YR 4.19% +2bp 3-YR 4.29% +4bp 5-YR 4.37% +2bp 7-YR 4.51% +3bp 10-YR 4.66% +2bp 20-YR 5.17% +1bp 30-YR 5.18% +1bp
US Treasury par yield curve · Aug 26 · Source: U.S. Treasury
Thursday, August 27, 2026
U.S. Edition
FBI, NSA and Cyber National Mission Force joint advisory JCSA-20260826-01, 26 August 2026

The government has named a Nanjing company as the operator of the hacking platform behind a decade of scanning, and it lists the Federal Reserve among the targets

A close up of the rear panel of a rack-mounted network appliance, with grey ethernet cables plugged into ports labelled eth0, eth1 and eth2 above a row of lit green and amber link lights, two USB sockets and an unused socket to the left, and black and orange cables curving across the top of the frame. Stock photo
Stock photo. Not the actual scene. Photo: Pixabay / Pexels

Nanjing Xinjiuwei Network Technology Company has suppliers, customers and a bid history. According to the FBI, the National Security Agency and the Cyber National Mission Force, it also ran a botnet.

The three agencies published a joint advisory on Wednesday, product number JCSA-20260826-01, attributing a hacking group that calls itself QTFY to that company. On the same morning the Justice Department announced court-authorised seizures of the domains the group used, in an operation run out of the Southern District of California. Because those domains were written into the malware itself and were used for communication and authentication, the department says the seizures made the tools inoperable.

What makes the advisory worth thirty minutes of anybody's time is not the takedown. It is the business description.

An enabling company, not a unit

The advisory does not describe a military organisation. It describes a supplier. Nanjing Xinjiuwei, abbreviated in the document to XJW, was established in 2018 and is called an enabling company for cyber operations linked to the People's Republic of China. Its people include former army members, and the advisory says they use their contacts to win contracts and subcontracts aimed at critical infrastructure. They have also traded in freelance markets, buying and selling exploits and access to victim networks.

Then the agencies print a table of the relationships XJW held as of June 2026. Two are Ministry of State Security units, one of which had two contracts in 2019 with i-Soon, the Chinese intrusion contractor whose internal documents leaked in 2024. One is a provincial environmental construction office. The rest are private technology firms in Beijing, Nanjing, Zhengzhou and Fujian, several of them described as bidding for work at China's National University of Defense Technology on power system vulnerability detection and radio frequency hardware.

The Justice Department puts the commercial relationship more plainly, saying the group offers hacking services to paying customers including the Ministry of State Security and the People's Liberation Army.

What the two products actually did

QScan is a scanner. The advisory describes a distributed system built on ordinary message-queue software, with the task server and the results server sitting on subdomains that moved from one domain to another in December 2025, and a pool of worker nodes on leased servers mostly outside China. It carried a library of more than 200 proof-of-concept exploits written in Python. On one day in 2024, the advisory says, it processed over two million scanning and penetration testing tasks.

QTRouter is the other half, and it is the reason the first half was hard to see. It is an obfuscation network running on routers with custom OpenWrt firmware, together with commercial proxy addresses, cloud addresses and compromised consumer devices. Traffic can be chained through several nodes. The effect is that an intrusion arrives at a target from an address that looks local and legitimate, and the advisory notes that user agent strings indicate the network was used by government personnel in four Chinese provinces as well as by the company's own staff.

The compromised devices sit under at least three separate management platforms, one of which can also be pointed at a target as a denial of service weapon.

The timeline is the document

Pages six and seven carry a table of observed activity going back to May 2018, and it reads like an inventory of the last eight years of edge-device vulnerabilities. Pulse Secure in 2019. Citrix in January 2020. ProxyLogon in March 2021. F5 in the summer of 2021, against a state government and a large retailer. Log4Shell that December. Atlassian Confluence in 2023, Ivanti in 2024, Check Point in the same year, CrushFTP in 2025, BeyondTrust this February.

Several rows record failures, and the agencies say so rather than glossing them: the Department of Energy in 2018, an election system in 2019, Health and Human Services in 2020, a children's hospital in 2021, the United States Senate and a hospital system in March this year, another election system in June. The word the table uses each time is unsuccessful.

The row for August 2019 is different. It records the use of a Pulse Secure exploit against the Department of Justice, the Federal Reserve and NASA, and it does not say the attempt failed. The Justice Department's release lists the same three among the victims of the group's intrusion activity, along with Energy, Health and Human Services, the National Institutes of Health and the Senate. Neither document says what, if anything, was taken from any of them.

The largest single row is May 2024, when the advisory says QScan was turned on American power and telecommunications companies through a Check Point gateway flaw and data was taken from more than 300 organisations worldwide, among them defence contractors, financial institutions and universities.

The part that is not about the past

One sentence near the end of the technical section has nothing to do with any of the seized infrastructure. The actors, the agencies write, have been heavily researching and integrating artificial intelligence into their processes over the last two years.

This is the fourth such operation the department has announced against Chinese state-linked hacking in four years, after PlugX in 2025, Flax Typhoon in 2024 and Volt Typhoon in 2023. Attorney General Todd Blanche described it as "the latest in a series of technical operations". The advisory ships two indicator files, one of malicious files and one of infrastructure, at ic3.gov.