
CVE-2024-24919 et al.: Multi-vendor IoT — Espionage, Data Theft, Persistence (June 2024)
CVE-2024-24919 et al. — Multi-vendor IoT
CVE-2024-24919, CVE-2024-8190, CVE-2024-8963, CVE-2024-9380, CVE-2025-31161, and CVE-2026-1731 are critical vulnerabilities affecting IoT and network devices, actively exploited by the China-linked QTFY threat group. These flaws enable remote code execution, credential theft, and persistent access, with a CVSS score of 9.8 (critical). Federal authorities confirm active exploitation in a multi-year espionage campaign targeting US government and critical infrastructure.
Attack Vector
QTFY leveraged zero-day and known critical vulnerabilities to compromise thousands of IoT devices globally. Attackers exploited weakly secured or unpatched endpoints, deployed custom malware, and established long-term persistence. The campaign included credential harvesting and lateral movement, allowing exfiltration of sensitive data from over 300 organizations. Indicators of compromise include unexpected outbound connections to QTFY-controlled domains and anomalous authentication attempts from IoT device subnets.
Who Is at Risk
All organizations deploying affected IoT and network devices are at risk, especially those in critical infrastructure sectors. Confirmed victims include the Department of Justice, NASA, Federal Reserve, Department of Energy, Department of Health and Human Services, NIH, U.S. Senate, telecom firms, hospitals, defense contractors, power companies, financial institutions, a US biotechnology firm, state government, and water districts. Any unpatched device in these environments is a potential entry point.
Patch & Mitigate
- Patch: Apply vendor security updates for all affected CVEs immediately. Prioritize firmware and OS updates for IoT and network equipment. Check vendor advisories for specific patch versions.
- Workaround: If patching is not immediately possible, segment vulnerable devices from critical networks and restrict outbound traffic.
- Detect: Monitor logs for anomalous authentication, unexpected device-to-internet connections, and traffic to known QTFY infrastructure. Review for signs of credential theft and persistence mechanisms on IoT endpoints.
MITRE ATT&CK
- TA0001 — Initial Access: QTFY exploited public-facing devices using zero-day vulnerabilities to gain entry.
- TA0007 — Discovery: Attackers performed internal reconnaissance to identify high-value targets and move laterally.
- TA0008 — Lateral Movement: Credential theft enabled movement across segmented networks and persistent access.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

