Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    What It Does to Your SOC

    September 12, 2026

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
    Cybersecurity

    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

    InfoForTechBy InfoForTechAugust 27, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.

    The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). 

    “Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate,” DoJ said.

    Damon Rouse, a security researcher at Lumen Black Lotus Labs who has been tracking the activity for over the past 18 months, told The Hacker News that the digital quartermaster has been active since May 2018. Nanjing counts both China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA) among its customers.

    Lumen said it began collaborating with the U.S. Federal Bureau of Investigation (FBI) on QTFY about a year ago. “The targeting was throughout the western world and beyond, especially with regard to academia,” the company added. “They just love hitting research communities given the collaborative nature of advanced science.”

    “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks.”

    Two of the prominent tools are QScan, which scans and automatically infects IoT devices worldwide, and then adds them to the QTRouter network. QTRouter comprises both the compromised devices and commercial proxy service devices and leased virtual private servers (VPSs).

    QTRouter effectively serves as an obfuscation network that allows QTFY and other Chinese cyber actors to conceal the true origins of their computer intrusion activities, giving the impression that the communications are coming from endpoints that are geolocated outside China and possibly local to the targeted networks.

    QScan has been associated with a number of domains that host different components of the system –

    • qt-proxy[.]org
    • mq-task.qt-proxy[.]org (previously, mq-task.qt-team[.]com), which provides scanning tasks to a pool of worker nodes primarily housed on leased servers located outside of China
    • mq-result.qt-proxy[.]org (previously, mq-result.qt-team[.]com), which receives completed tasks

    “QScan is used to exploit vulnerable IoT devices and identify vulnerabilities in victim networks. QTFY uses botnet products to control the compromised IoT devices and include them as QTRouter proxy nodes,” the FBI said. “This enables QTFY-affiliated actors to blend in with legitimate users when targeting victim organizations.”

    QTRouter, which functions as a network traffic obfuscation network running on routers with custom OpenWrt software, authenticates to administration servers located at “www.qtproxy[.]xyz” and “securelink.qtproxy[.]xyz.”

    “QTRouter uses Clash to establish proxy connections,” the FBI explained. “Its functionality includes viewing available nodes and chaining nodes together to obfuscate the actor behind the malicious activity. Additionally, by mixing the malicious traffic with legitimate traffic on commercial proxy services and using compromised IoT devices to utilize the locations of legitimate users, QTRouter makes it difficult to identify and track the malicious activity.”

    The botnets of hacked devices are commandeered using three major platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, the last of which includes a controller server, secondary-level control servers to maintain communication between the main control server and compromised devices, and compromised devices. The control server is also equipped to launch DDoS attacks and run commands on infected nodes.

    The entire attack cycle is as follows –

    • Use QScan to conduct reconnaissance against victim networks
    • Exploit zero-day (e.g., CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances) and N-day vulnerabilities (CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange Server, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support) to gain initial access to victim networks
    • Establish persistence using remote access trojans (RAT), web shells, and legitimate credentials
    • Use QTRouter to accès the victim network from nearby compromised IoT to fly under the radar

    The seized domains are said to have been hard-coded into both products, causing them to cease operations following the court-authorized action.

    The distributed architecture is a set of interconnected components that includes QScan, QTRouter, and two others, per Lumen –

    • Fast Labyrinth, which provides the operational layer by incorporating commercial proxy infrastructure such as Fastlink (“fastlink.ws”) into an encrypted relay network along with QTRouter that obfuscates traffic to and from target entities
    • QTProxy, which manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or configure unique paths to target entities

    The infrastructure has been likened to an operational relay box (ORB), a decentralized mesh that comprises infected IoT devices and leased VPSs and allows malicious traffic to be routed through rotating IPs and evade traditional defenses like IP blocklists and location-based policies.

    “Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States,” the FBI said.

    The agency described Nanjing as an enabling company that has business relationships with larger private China-based cyber-enabling companies with expertise in critical infrastructure security to target victim organizations. It also encompasses former PLA members and takes advantage of their contacts to land contracts related to critical infrastructure targeting.

    What’s more, QTFY actors are alleged to have participated in China-based freelance brokering networks to acquire and sell cyber exploit items, including access to victim networks. Attacks as recent as June 2026 have targeted a U.S. election system.

    “The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations,” Lumen said. “By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale.”

    “Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.