ThreatPaperBeta
State-SponsoredHigh

Chinese State-Sponsored QTFY Campaign: Disruption of QScan and QTRouter Hacking Platforms

By Sethu Satheesh · 28 Aug 2026 · 10 min read

Threat Actor: QTFY · Target: U.S. Government

Source: www.hindustantimes.com


Executive Summary

The cyber espionage landscape has evolved toward an industrialized "quartermaster" model of network obfuscation and reconnaissance. On August 26, 2026, the United States Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI), acting on warrants unsealed in the Southern District of California, dismantled the core infrastructure of an advanced state-sponsored hacking operation attributed to the People's Republic of China (PRC). Operating under the moniker "QTFY" (also tracked as QT and QTCYBER), the threat actor utilized a distributed mesh network of hijacked Internet of Things (IoT) devices, leased virtual private servers (VPS), and co-opted commercial proxy services to mask the origins of its cyber espionage activities.

The operation was masterminded by Nanjing Xinjiuwei Network Technology Company, a private Chinese contractor established in 2018. Operating as a cyber-enabling firm, Nanjing Xinjiuwei commercialized offensive cyber capabilities, acting as an infrastructure quartermaster that leased pre-packaged stealth, target verification telemetry, and non-attributable transit layers to paying clients, including China's Ministry of State Security (MSS) and the People's Liberation Army (PLA). The campaign leveraged two complementary platforms: QScan, an automated reconnaissance and exploitation engine deploying over 200 Python-based exploits against edge appliances, and QTRouter, an obfuscation layer utilizing custom OpenWrt software and the Clash proxy utility.

The DOJ's disruption capitalized on a critical operational security failure: the reliance on hard-coded command-and-control domains (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com). By seizing these domains, federal authorities severed the authentication and communication lifelines of the malware, rendering the QScan and QTRouter ecosystem inoperable.

Verification of Claims

  1. Claim: The hacking platforms QScan and QTRouter were created, operated, and maintained by a Chinese state-sponsored contractor named Nanjing Xinjiuwei Network Technology Company. → Verified → Corroborated by unsealed federal court documents in the Southern District of California, the official DOJ press release, and joint cybersecurity advisory JCSA-20260826-01.

  2. Claim: QTFY successfully breached the core classified networks of NASA, the U.S. Senate, and the Federal Reserve, resulting in massive data exfiltration. → Partially verified → While widespread scanning, vulnerability exploitation attempts, and routing through compromised proxy infrastructure were confirmed against these entities, specific details regarding the extent of data stolen remain undisclosed by the DOJ.

  3. Claim: The U.S. government disabled the QTFY botnet by physically confiscating command-and-control servers located within mainland China. → Unverified → There is no public evidence of physical server confiscation within Chinese territorial jurisdiction; the disruption was executed via court-authorized seizure of hard-coded domain names registered through U.S. or allied jurisdictions.

  4. Claim: QTFY utilized zero-day vulnerabilities in Ivanti Cloud Services Appliances (CSA) to breach U.S. targets in September 2024. → Verified → The FBI and CISA confirmed the rapid exploitation of zero-day flaws (CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380) in Ivanti CSA devices targeting three Department of Energy (DOE) laboratories, the NIH, and an HHS agency.

  5. Claim: QTFY integrated commercial Chinese "Airport" proxy services into their obfuscation network. → Verified → Threat research by Lumen Technologies' Black Lotus Labs details how QTFY purchased high-tier corporate subscriptions to commercial proxy networks to funnel state-sponsored traffic through high-bandwidth international transit hubs.

Timeline

Date Actor Event Source
May 2018 QTFY Conducted extensive vulnerability scanning of the U.S. Department of Energy. FBI/NSA Advisory JCSA-20260826-01
August 2019 QTFY Deployed exploits for the Pulse Secure VPN vulnerability (CVE-2019-11510) against the DOJ, Federal Reserve, and NASA. FBI/NSA Advisory JCSA-20260826-01
May 2024 QTFY Leveraged QScan to scan U.S. power and telecom companies, exploiting Check Point Quantum Gateway (CVE-2024-24919) to exfiltrate data from over 300 organizations. FBI/NSA Advisory JCSA-20260826-01
September 2024 QTFY Conducted successful intrusions at three DOE laboratories, NIH, an HHS agency, and a U.S. security device manufacturer using Ivanti CSA zero-days. DOJ Affidavit
December 2024 QTFY Breached the U.S. Treasury Department by compromising third-party provider BeyondTrust, accessing unclassified documents via compromised cloud keys. Congressional Letter / Media Reports
August 24, 2026 U.S. Government A federal court in the Southern District of California granted seizure warrants for three primary QTFY command domains. DOJ Affidavit
August 26, 2026 U.S. Government Domains seized, rendering QScan and QTRouter inoperable. The FBI, NSA, and CNMF published joint advisory JCSA-20260826-01. DOJ Press Release / FBI

Attack Anatomy

Initial Access: QTFY's automated reconnaissance was executed via QScan, utilizing a RabbitMQ and Celery task broker framework to distribute targeting tasks across global worker nodes. The platform leveraged a repository of over 200 Python-based exploits to target internet-facing edge appliances, VPN concentrators, and routers.

Execution: Upon compromising edge devices, operators modified firmware—such as loading custom OpenWrt firmware onto routers—and integrated them into the QTProxy administrative control plane.

Persistence: Threat actors deployed custom remote access trojans (RATs) and stealthy web shells deep within web-root directories, while harvesting legitimate administrative credentials to maintain access via external remote services.

Collection: Operators engaged in extensive data collection, scraping webpages, parsing configurations, and harvesting research from academic, defense, and governmental targets.

Exfiltration: Malicious traffic was funneled backward through "Fast Labyrinth," an encrypted relay network utilizing commercial Chinese "Airport" proxy services (e.g., fastlink.ws) to blend espionage traffic with legitimate consumer streaming traffic.

Impact: The campaign established a global espionage pipeline, enabling the continuous theft of intellectual property and critical infrastructure mapping over an eight-year period.

Loading diagram...

Threat Actor Profile

  • Name / Alias: QTFY (also tracked as QT and QTCYBER)
  • Attribution Confidence: High — Linked via malware source code, infrastructure, and check-in logs to Nanjing Xinjiuwei Network Technology Company.
  • Motivation: Espionage — Prioritizing intelligence gathering, IP theft, and critical infrastructure mapping over financial gain.
  • Sophistication Level: Advanced — Industrialized quartermaster model, rapid zero-day weaponization, and seamless commercial proxy integration.
  • Known Previous Operations: Continuous operations since May 2018 targeting U.S. election infrastructure, South Korean financial entities, Taiwanese energy systems, and global healthcare.
  • Nation-State Nexus: Yes — Contracted by Nanjing Xinjiuwei, which recruits former PLA personnel and provides services to the MSS and PLA.
  • MITRE ATT&CK Techniques:
    • T1595.002 — Active Scanning: Vulnerability Scanning
    • T1190 — Exploit Public-Facing Application
    • T1584.005 — Compromise Infrastructure: Botnet
    • T1090.003 — Connection Proxy: Multi-hop Proxy
    • T1505.003 — Server Software Component: Web Shell
    • T1078 — Valid Accounts
    • T1133 — External Remote Services
  • Operational Security (OpSec): Advanced traffic obfuscation via "Fast Labyrinth," but critically flawed by the use of hard-coded C2 domains (qtproxy[.]xyz, qt-proxy[.]org) embedded directly into malware authentication routines, enabling single-point takedown.

Technical Indicators

domains:
  - "qtproxy[.]xyz"
  - "www[.]qtproxy[.]xyz"
  - "qt-proxy[.]org"
  - "jump[.]qt-proxy[.]org"
  - "mq-task[.]qt-proxy[.]org"
  - "mq-result[.]qt-proxy[.]org"
  - "qt-team[.]com"
  - "mq-task[.]qt-team[.]com"
  - "mq-result[.]qt-team[.]com"
  - "securelink[.]qtproxy[.]xyz"
  - "instantmessagehub[.]tech"
  - "flanycast-us[.]yotocloud[.]com"
  - "flanycast-hk[.]yotocloud[.]com"
  - "flanycast-jp[.]yotocloud[.]com"
  - "flanycast-tw[.]yotocloud[.]com"
  - "flanycast-sg[.]yotocloud[.]com"
  - "flnode-ulus[.]yotocloud[.]com"
  - "flnode-dl[.]yotocloud[.]com"
ip_addresses:
  - "154.64.238[.]222"
  - "154.64.238[.]247"
  - "1.32.216[.]171"
  - "8.148.149[.]147"
  - "47.76.131[.]175"
  - "64.32.22[.]203"
  - "148.135.90[.]22"
  - "45.202.210[.]27"
  - "1.32.216[.]3"
  - "1.32.216[.]4"
  - "1.32.216[.]27"
  - "1.32.216[.]33"
  - "1.32.216[.]49"
  - "1.32.216[.]77"
  - "1.32.216[.]83"
  - "1.32.216[.]92"
  - "1.32.216[.]94"
  - "1.32.216[.]104"
  - "1.32.216[.]113"
  - "1.32.216[.]123"
file_hashes:
  - type: "sha256"
    value: "Multiple hashes hosted via IC3"
    description: "Joint FBI/NSA advisory documented 45 distinct GTRouter firmware implant and web shell hashes available via FBI IC3 portal."
urls:
  - "hxxps://www[.]ic3[.]gov/CSA/2026/QTFY_IOC_Files.csv"
  - "hxxps://www[.]ic3[.]gov/CSA/2026/QTFY_IOC_Infrastructure.csv"
c2_infrastructure:
  - "QTRouter custom OpenWrt firmware integrated with Clash proxy utility for multi-hop traffic chaining."
  - "QScan task broker utilizing RabbitMQ and Celery on mq-task[.]qt-proxy[.]org."

Law Enforcement Actions

On August 24, 2026, the U.S. Attorney’s Office for the Southern District of California obtained seizure warrants targeting QTFY command-and-control infrastructure. Executed on August 26, 2026, federal agents seized primary domains including qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, neutralizing the QScan and QTRouter platforms globally.

Government Directives

A Joint Cybersecurity Advisory (JCSA-20260826-01) was published by the FBI, NSA, and CNMF detailing TTPs, attributing operations to Nanjing Xinjiuwei Network Technology Company, and providing defensive IoCs.

Platform Response

Lumen Technologies (Black Lotus Labs) collaborated with federal authorities, supplying telemetry that mapped the quartermaster architecture, identified the use of fastlink.ws proxy networks, and supported the seizure warrants.

Criminal Proceedings

While infrastructure was dismantled via civil seizure warrants in the Southern District of California, the DOJ has not yet publicly unsealed criminal indictments against specific executives of Nanjing Xinjiuwei.

Impact Assessment

  • Automated Reconnaissance Scale: Confirmed: QScan processed over 2 million automated scanning and penetration testing tasks globally in a single day during 2024.
  • Victim Compromises via Check Point Gateway (CVE-2024-24919): Confirmed: QTFY exfiltrated data from over 300 distinct organizations worldwide in May 2024.
  • Targeted U.S. Federal Agencies: Confirmed: Successful scanning and exploitation attempts logged against NASA, the U.S. Senate, the Federal Reserve, DOE, DOJ, HHS, and NIH.
  • U.S. Treasury Breach via Third-Party: Reported: In December 2024, hackers breached the U.S. Treasury by compromising third-party provider BeyondTrust using compromised cloud keys.
  • Data Exfiltration Volume / Financial Losses: Unknown: Specific classified data stolen and cumulative financial damages remain undisclosed by federal authorities.

Lessons and Defensive Recommendations

For Security Teams / SOC Analysts: Traditional IP reputation scoring or geo-fencing is obsolete against the QTFY model, which routes attacks through localized residential IoT nodes and commercial bypass networks. Pivot detection engineering toward post-exploitation behavioral analysis, scanning for anomalous web shells, impossible travel in VPN logs, and outbound traffic matching Clash proxy configurations.

For Developers and Architects: Adopt an "assume breach" methodology for internet-facing boundary devices. Perimeter appliances are primary targets for zero-day exploitation; ensure internal segments do not implicitly trust traffic from edge security devices.

For Platform / Cloud Providers: Implement comprehensive SASE solutions to minimize the external attack surface and abstract management interfaces away from the public internet. Audit out-of-band management interfaces and enforce phishing-resistant MFA on all remote administrative portals.

For Leadership / CISO: Infrastructure seizures neutralize future command-and-control communication but do not evict existing implants, web shells, or stolen credentials. Mandate immediate patch management for edge appliances and allocate budget for proactive threat hunting.

Sources

  1. Hindustan Times. "Chinese hackers broke into US Justice Department, NASA, Senate and more, say officials". August 26, 2026.

  2. U.S. Department of Justice. "Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers". August 26, 2026.

  3. Korea JoongAng Daily. "Korean financial group among targets of China-linked hacking network". August 27, 2026.

  4. Washington Examiner. "Chinese hackers targeted NASA, Senate, Federal Reserve, and others, Justice Department says". August 26, 2026.

  5. BleepingComputer. "FBI disrupts proxy network enabling Chinese espionage operations". August 26, 2026.

  6. Lumen Technologies (Black Lotus Labs). "Inside China-nexus cyber espionage infrastructure". August 2026.

  7. FBI, NSA, CNMF. "China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure (JCSA-20260826-01)". August 26, 2026.

  8. SecureBlink. "FBI Dismantles QScan & QTRouter, China's NASA-Hacking Botnet". August 26, 2026.

  9. Al Jazeera. "US says Chinese-linked hackers attacked NASA, Senate, and govt agencies". August 26, 2026.

  10. Telecoms.com. "US seizes domains for Chinese QScan and QTRouter hacking tools". August 27, 2026.

  11. Breached.co. "QTFY: The FBI Seized the Hacking Platforms of a Nanjing Company". August 26, 2026.

  12. Time. "U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More". August 27, 2026.

  13. Whack.sh. "The FBI QTFY Advisory: When Attackers Rent the Infrastructure". August 2026.

  14. Nextgov/FCW. "FBI disables China-linked hacking tools used against US agencies". August 26, 2026.

  15. The Hacker News. "FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data from US Organizations". August 26, 2026.

Original Incident Report →

Related Research

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

Russian state-sponsored group Midnight Blizzard (APT29) breached Microsoft's corporate environment via password spray against a legacy non-production test tenant, accessed executive and security team email, and exfiltrated OAuth tokens and source code — demonstrating sophisticated identity-based tradecraft without malware.

State-SponsoredData Breach

A sophisticated multi-year supply chain attack compromised the widely used xz compression library, embedding a backdoor in liblzma that targeted OpenSSH authentication on systemd-based Linux distributions. The attacker, operating under the persona 'Jia Tan,' spent over two years building trust as a contributor before gaining maintainership and inserting the malicious code.

Supply Chain Attack