The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).
“Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate,” DoJ said.
Damon Rouse, a security researcher at Lumen Black Lotus Labs who has been tracking the activity for over the past 18 months, told The Hacker News that the digital quartermaster has been active since May 2018. Nanjing counts both China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA) among its customers.
Lumen said it began collaborating with the U.S. Federal Bureau of Investigation (FBI) on QTFY about a year ago. “The targeting was throughout the western world and beyond, especially with regard to academia,” the company added. “They just love hitting research communities given the collaborative nature of advanced science.”
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks.”
Two of the prominent tools are QScan, which scans and automatically infects IoT devices worldwide, and then adds them to the QTRouter network. QTRouter comprises both the compromised devices and commercial proxy service devices and leased virtual private servers (VPSs).
QTRouter effectively serves as an obfuscation network that allows QTFY and other Chinese cyber actors to conceal the true origins of their computer intrusion activities, giving the impression that the communications are coming from endpoints that are geolocated outside China and possibly local to the targeted networks.
QScan has been associated with a number of domains that host different components of the system –
- qt-proxy[.]org
- mq-task.qt-proxy[.]org (previously, mq-task.qt-team[.]com), which provides scanning tasks to a pool of worker nodes primarily housed on leased servers located outside of China
- mq-result.qt-proxy[.]org (previously, mq-result.qt-team[.]com), which receives completed tasks
“QScan is used to exploit vulnerable IoT devices and identify vulnerabilities in victim networks. QTFY uses botnet products to control the compromised IoT devices and include them as QTRouter proxy nodes,” the FBI said. “This enables QTFY-affiliated actors to blend in with legitimate users when targeting victim organizations.”
QTRouter, which functions as a network traffic obfuscation network running on routers with custom OpenWrt software, authenticates to administration servers located at “www.qtproxy[.]xyz” and “securelink.qtproxy[.]xyz.”
“QTRouter uses Clash to establish proxy connections,” the FBI explained. “Its functionality includes viewing available nodes and chaining nodes together to obfuscate the actor behind the malicious activity. Additionally, by mixing the malicious traffic with legitimate traffic on commercial proxy services and using compromised IoT devices to utilize the locations of legitimate users, QTRouter makes it difficult to identify and track the malicious activity.”
The botnets of hacked devices are commandeered using three major platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, the last of which includes a controller server, secondary-level control servers to maintain communication between the main control server and compromised devices, and compromised devices. The control server is also equipped to launch DDoS attacks and run commands on infected nodes.
The entire attack cycle is as follows –
- Use QScan to conduct reconnaissance against victim networks
- Exploit zero-day (e.g., CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances) and N-day vulnerabilities (CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange Server, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support) to gain initial access to victim networks
- Establish persistence using remote access trojans (RAT), web shells, and legitimate credentials
- Use QTRouter to accès the victim network from nearby compromised IoT to fly under the radar
The seized domains are said to have been hard-coded into both products, causing them to cease operations following the court-authorized action.
The distributed architecture is a set of interconnected components that includes QScan, QTRouter, and two others, per Lumen –
- Fast Labyrinth, which provides the operational layer by incorporating commercial proxy infrastructure such as Fastlink (“fastlink.ws”) into an encrypted relay network along with QTRouter that obfuscates traffic to and from target entities
- QTProxy, which manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or configure unique paths to target entities
The infrastructure has been likened to an operational relay box (ORB), a decentralized mesh that comprises infected IoT devices and leased VPSs and allows malicious traffic to be routed through rotating IPs and evade traditional defenses like IP blocklists and location-based policies.
“Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States,” the FBI said.
The agency described Nanjing as an enabling company that has business relationships with larger private China-based cyber-enabling companies with expertise in critical infrastructure security to target victim organizations. It also encompasses former PLA members and takes advantage of their contacts to land contracts related to critical infrastructure targeting.
What’s more, QTFY actors are alleged to have participated in China-based freelance brokering networks to acquire and sell cyber exploit items, including access to victim networks. Attacks as recent as June 2026 have targeted a U.S. election system.
“The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations,” Lumen said. “By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale.”
“Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat.”
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.




