The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).
"Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate," DoJ said.
Damon Rouse, a security researcher at Lumen Black Lotus Labs who has been tracking the activity for over the past 18 months, told The Hacker News that the digital quartermaster has been active since May 2018. Nanjing counts both China's Ministry of State Security (MSS) and the People's Liberation Army (PLA) among its customers.
Lumen said it began collaborating with the U.S. Federal Bureau of Investigation (FBI) on QTFY about a year ago. "The targeting was throughout the western world and beyond, especially with regard to academia," the company added. "They just love hitting research communities given the collaborative nature of advanced science."
"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," said FBI Director Kash Patel. "These tools were used by PRC cyber actors to hide the origin of their attacks."
Two of the prominent tools are QScan, which scans and automatically infects IoT devices worldwide, and then adds them to the QTRouter network. QTRouter comprises both the compromised devices and commercial proxy service devices and leased virtual private servers (VPSs).
QTRouter effectively serves as an obfuscation network that allows QTFY and other Chinese cyber actors to conceal the true origins of their computer intrusion activities, giving the impression that the communications are coming from endpoints that are geolocated outside China and possibly local to the targeted networks.
QScan has been associated with a number of domains that host different components of the system -
- qt-proxy[.]org
- mq-task.qt-proxy[.]org (previously, mq-task.qt-team[.]com), which provides scanning tasks to a pool of worker nodes primarily housed on leased servers located outside of China
- mq-result.qt-proxy[.]org (previously, mq-result.qt-team[.]com), which receives completed tasks
"QScan is used to exploit vulnerable IoT devices and identify vulnerabilities in victim networks. QTFY uses botnet products to control the compromised IoT devices and include them as QTRouter proxy nodes," the FBI said. "This enables QTFY-affiliated actors to blend in with legitimate users when targeting victim organizations."
QTRouter, which functions as a network traffic obfuscation network running on routers with custom OpenWrt software, authenticates to administration servers located at "www.qtproxy[.]xyz" and "securelink.qtproxy[.]xyz."
"QTRouter uses Clash to establish proxy connections," the FBI explained. "Its functionality includes viewing available nodes and chaining nodes together to obfuscate the actor behind the malicious activity. Additionally, by mixing the malicious traffic with legitimate traffic on commercial proxy services and using compromised IoT devices to utilize the locations of legitimate users, QTRouter makes it difficult to identify and track the malicious activity."
The botnets of hacked devices are commandeered using three major platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, the last of which includes a controller server, secondary-level control servers to maintain communication between the main control server and compromised devices, and compromised devices. The control server is also equipped to launch DDoS attacks and run commands on infected nodes.
The entire attack cycle is as follows -
- Use QScan to conduct reconnaissance against victim networks
- Exploit zero-day (e.g., CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances) and N-day vulnerabilities (CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange Server, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support) to gain initial access to victim networks
- Establish persistence using remote access trojans (RAT), web shells, and legitimate credentials
- Use QTRouter to accès the victim network from nearby compromised IoT to fly under the radar
The seized domains are said to have been hard-coded into both products, causing them to cease operations following the court-authorized action.
The distributed architecture is a set of interconnected components that includes QScan, QTRouter, and two others, per Lumen -
- Fast Labyrinth, which provides the operational layer by incorporating commercial proxy infrastructure such as Fastlink ("fastlink.ws") into an encrypted relay network along with QTRouter that obfuscates traffic to and from target entities
- QTProxy, which manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or configure unique paths to target entities
The infrastructure has been likened to an operational relay box (ORB), a decentralized mesh that comprises infected IoT devices and leased VPSs and allows malicious traffic to be routed through rotating IPs and evade traditional defenses like IP blocklists and location-based policies.
"Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States," the FBI said.
The agency described Nanjing as an enabling company that has business relationships with larger private China-based cyber-enabling companies with expertise in critical infrastructure security to target victim organizations. It also encompasses former PLA members and takes advantage of their contacts to land contracts related to critical infrastructure targeting.
What's more, QTFY actors are alleged to have participated in China-based freelance brokering networks to acquire and sell cyber exploit items, including access to victim networks. Attacks as recent as June 2026 have targeted a U.S. election system.
"The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations," Lumen said. "By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale."
"Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat."
Facts Only
* The U.S. Department of Justice announced the disruption of hacking platforms QScan and QTRouter.
* These platforms were operated by Chinese threat actors targeting critical infrastructure and sensitive networks.
* The activity was attributed to a Chinese state-sponsored group named QTFY, employed by Nanjing Xinjiuwei Network Technology Company.
* Victims included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.
* A security researcher tracked activity for over 18 months; the digital quartermaster has been active since May 2018.
* Nanjing counts China's Ministry of State Security (MSS) and the People's Liberation Army (PLA) among its customers.
* QScan scans and automatically infects IoT devices worldwide, adding them to the QTRouter network.
* QTRouter serves as an obfuscation network using compromised devices and proxy services.
* QScan is associated with domains qt-proxy[.]org, mq-task.qt-proxy[.]org, and mq-result.qt-proxy[.]org.
* QTRouter authenticates to administration servers at www.qtproxy[.]xyz and securelink.qtproxy[.]xyz.
* The botnets use Proxy Platform Management, Proxy Pool Management System, and QTBotnet.
* The attack cycle involves reconnaissance via QScan, exploiting vulnerabilities, establishing persistence, and using QTRouter to access networks from compromised IoT devices.
Executive Summary
The U.S. Department of Justice announced the disruption of two hacking platforms, QScan and QTRouter, operated by Chinese threat actors targeting critical infrastructure and sensitive networks. This activity is attributed to a group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company. Victims of this intrusion included the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. Security researchers noted that these tools have been active since May 2018.
The disruption involved a global botnet and hacking platform used by Chinese state-sponsored hackers to obscure their attack origins. QScan is used to scan and automatically infect IoT devices worldwide and add them to the QTRouter network. QTRouter functions as an obfuscation network, utilizing compromised devices and proxy services to hide intrusion activity. The infrastructure includes components like qt-proxy[.]org for task distribution and mq-task/mq-result domains for handling scanning tasks. QTRouter uses Clash to establish proxy connections and mixes malicious traffic with legitimate traffic via commercial proxies and compromised IoT devices to evade tracking.
The overall attack cycle involves reconnaissance using QScan, gaining initial access through exploiting zero-day and N-day vulnerabilities in various systems, establishing persistence with RATs and web shells, and then using QTRouter to access the victim network from nearby compromised IoT devices. The architecture relies on interconnected components like Fast Labyrinth and QTProxy to create a decentralized mesh that routes traffic through rotating IPs, enabling complex campaigns with high anonymity and speed globally.
Full Take
The operational description reveals a systematic industrialization of cyber operations by state-sponsored actors, shifting from fragmented methods to shared, multi-tenant utility networks for enhanced anonymity and speed. The reliance on infrastructure like QScan and QTRouter, which leverage commercially available proxy services and compromised IoT devices in a decentralized mesh (ORB), demonstrates an operational paradigm where legitimate commercial services are co-opted to mask malicious transit. This suggests that targeting security defenses is increasingly focused not just on patching specific vulnerabilities but on controlling the entire communication ecosystem through shared infrastructure.
The involvement of enabling companies with links to MSS and PLA, alongside freelance brokering networks for exploit acquisition, indicates a complex supply chain where state interests are operationalized through private entities and contractor channels. The shift to tooling that allows blending malicious traffic with legitimate user activity through proxy chains suggests that static blocking measures become insufficient when the attack mechanism integrates ubiquitous, commercially accepted services. This forces scrutiny on the efficacy of perimeter defenses versus the integrity of the underlying network fabric itself, and questions the limitations of traditional attribution methods against such highly distributed, layered obfuscation techniques.
What are the long-term implications for digital sovereignty if operational security becomes entirely dependent on the trustworthiness of commercial proxy infrastructure and IoT device integrity? How does the industrialization of cyber tooling change the risk profile when private entities act as essential components in state-sponsored attacks? If traditional blocking fails against transit loops procured via legitimate subscriptions, what alternative models for network control and trust are necessary to maintain security?
Sentinel — Human
The text appears to be a structured report synthesizing specific attribution details, technical methodologies, and quotes from named sources regarding a cyber operation.
