- What: The U.S. Department of Justice disrupted QScan and QTRouter, two hacking platforms run by the Chinese state-sponsored group QTFY, employed by Nanjing Xinjiuwei Network Technology Company.
Damon Rouse, a security researcher at Lumen Black Lotus Labs, spent more than 18 months tracking a single Chinese crew. About a year into that work, Lumen brought the FBI in. On Wednesday the U.S. Department of Justice announced what came of it: the court-authorized disruption of two hacking platforms, QScan and QTRouter, operated by a Chinese state-sponsored group tracked as QTFY.
QTFY is not an anonymous collective with a clever logo. According to DoJ, the group is employed by Nanjing Xinjiuwei Network Technology Company, a registered business that counts both China's Ministry of State Security and the People's Liberation Army among its customers. Rouse described the operation as a digital quartermaster, active since May 2018. That is roughly eight years of a commercial vendor building, trading, and operating intrusion infrastructure for two arms of a foreign government, with the release cadence and support model of a product company.
The victim list reads like a federal org chart
DoJ named seven victims of QTFY intrusion activity: the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. That is space, monetary policy, energy, law enforcement, public health, and the legislature, all in one paragraph of one press release.
Lumen said the targeting ran throughout the western world and beyond, with a particular appetite for academia. "They just love hitting research communities given the collaborative nature of advanced science," the company said. That sentence deserves more attention than it will get. Research networks are built to federate, share credentials, and stay open to outside collaborators. Every property that makes them productive makes them soft.
Universities and national labs sit upstream of the agencies on the victim list. Access to a collaborator's account is often access to the data before it reaches a hardened federal enclave. QTFY did not need to beat NASA's perimeter if a partner institution was already inside it.
The product was never the malware, it was the return address
QScan scans the internet and automatically infects vulnerable IoT devices, then enrolls them into QTRouter. QTRouter is the obfuscation layer: compromised devices, commercial proxy service devices, and leased virtual private servers, stitched together into a relay network. It runs custom OpenWrt software on routers, uses Clash to establish proxy connections, and authenticates to administration servers at www.qtproxy[.]xyz and securelink.qtproxy[.]xyz. Operators can view available nodes and chain them together at will.
The effect is that traffic appears to originate outside China and frequently local to the targeted network. "These tools were used by PRC cyber actors to hide the origin of their attacks," said FBI Director Kash Patel. Lumen documented two further components: Fast Labyrinth, which folds commercial proxy infrastructure such as Fastlink into an encrypted relay network alongside QTRouter, and QTProxy, which manages those operational nodes and lets operators build preconfigured or custom paths to a given target. Three platforms run the botnets themselves: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, whose control server can also launch DDoS attacks and run commands on infected nodes.
Researchers call this shape an operational relay box, or ORB: a decentralized mesh of infected IoT and leased VPSs that routes malicious traffic through rotating IPs. It was purpose-built to defeat IP blocklists and location-based access policies, which is to say it was built specifically against the two controls most enterprises still lean on hardest.
The exploit kit is a museum of unpatched edge gear
The attack cycle is unglamorous. QScan performs reconnaissance, then operators exploit a mix of zero-days and N-days for initial access, establish persistence with remote access trojans, web shells, and legitimate credentials, and finally use QTRouter to reach the victim from a nearby compromised IoT device. The FBI listed 13 CVEs in total: three Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) and ten N-days spanning CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-26855 in Microsoft Exchange, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support.
An eight-year-old Fortinet bug is still in a 2026 state-sponsored toolkit. It is there because it still works.
The RedEye take
The takedown succeeded on a technicality of the adversary's own making. The seized domains were hard-coded into both QScan and QTRouter, so the court-authorized seizure caused both products to stop functioning. That is a build flaw, not a strategic defeat. QTFY lost a control plane, not a playbook, not a customer relationship, and not the engineers who wrote it.
The contractor model is what should keep IT leaders up. When espionage capability is procured from a company with a payroll and a customer list, disruption removes inventory rather than intent. Nanjing Xinjiuwei's customers still have budgets. Expect the next iteration to resolve its control servers dynamically.
There is a genuine win here worth naming: a private telemetry provider tracked this for 18 months and worked with the FBI for a year before anything was seized. That patience is why the disruption landed on the whole architecture instead of a handful of IPs. It is also the model that should be funded more, not less.
The harder lesson is what the eight-year runtime says about detection. QTFY was not caught by anyone's perimeter. It was caught by an outside researcher watching infrastructure. Seven federal agencies got hit by traffic that, by design, looked like a normal user in a normal place.
What defenders should learn
- Geolocation is now an offensive capability, not a defensive one. If your access policy grants trust because a session originates in-country or in-region, an ORB turns that policy into a shortcut for the attacker. Move the decision to device identity and credential context.
- Treat your own IoT and router fleet as somebody's rented infrastructure. QScan infects devices to use their location, not their data. Monitor for outbound proxy behavior, unexpected OpenWrt firmware, and Clash-style connections from anything that should never initiate traffic.
- N-day exposure on internet-facing appliances is the whole entry path. Nine of the 13 CVEs are years old. Inventory every VPN, gateway, file transfer, and remote support product you expose, and treat those specifically as a separate patch tier with a tighter SLA than servers.
- Retain DNS and proxy resolution logs long enough to be useful after a takedown. Domain seizures publish indicators years after first use, and the only way to answer "were we in this" is historical resolution data you kept.
- Extend threat modeling to your research and academic partners. If you collaborate with universities or national labs, their federated access is part of your attack surface, and QTFY has been targeting exactly that seam.
Search historical DNS, proxy, and firewall logs for qt-proxy[.]org, mq-task.qt-proxy[.]org, mq-result.qt-proxy[.]org, the earlier mq-task.qt-team[.]com and mq-result.qt-team[.]com, www.qtproxy[.]xyz, securelink.qtproxy[.]xyz, and fastlink[.]ws. A hit on any of these predating the seizure is not noise.
Source: "FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations," Ravie Lakshmanan, The Hacker News, August 26, 2026, with reporting from Lumen Black Lotus Labs, the FBI, and the U.S. Department of Justice.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us