top of page

FBI Dismantles China-Linked Hacking Infrastructure Targeting U.S. Critical Systems

Aug 27
3 min read

Key Findings


  • FBI disrupted QScan and QTRouter, two hacking platforms operated by Chinese state-sponsored group QTFY used to target U.S. critical infrastructure

  • QTFY is employed by Nanjing Xinjiuwei Network Technology Company, which serves China's Ministry of State Security and People's Liberation Army

  • Victims include NASA, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate

  • The disruption was achieved by seizing hard-coded domains essential to the platforms' operations, rendering them inoperable

  • QScan has been active since May 2018 and was tracked by security researchers for over 18 months before the operation


Background


QTFY operates as what security researchers call a "digital quartermaster" - essentially a supplier of hacking infrastructure and services used by multiple Chinese cyber operations. The group primarily targets critical infrastructure and research institutions throughout the western world, with particular focus on academic communities due to their collaborative nature and access to advanced scientific research.


The FBI began collaborating with security firm Lumen Black Lotus Labs approximately one year before the disruption announcement. The investigation revealed that QTFY's services were available to paying customers including both state and military entities within China, indicating a structured, industrialized approach to cyber operations.


How QScan Worked


QScan functioned as an automated reconnaissance and compromise tool that scanned the internet for vulnerable Internet of Things devices. Once identified, the tool automatically infected thousands of exposed IoT devices including routers, cameras, and other connected appliances worldwide.


The tool communicated through several hard-coded domains including qt-proxy[.]org, mq-task.qt-proxy[.]org, and mq-result.qt-proxy[.]org. These domains served specific functions - one distributed scanning tasks to worker nodes housed on leased servers outside China, while another received results from completed scanning operations.


QScan exploited both zero-day and known vulnerabilities in common network appliances. Targeted systems included Ivanti CSA appliances, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, and numerous others. This dual-vulnerability approach maximized the number of devices that could be compromised.


The QTRouter Obfuscation Network


Once QScan compromised IoT devices, they were added to QTRouter, a network designed specifically to hide the origin of attacks. QTRouter mixed malicious traffic with legitimate traffic by routing communications through compromised IoT devices, commercial proxy services, and rented virtual private servers located outside China.


This layering made attribution nearly impossible. Targeted organizations saw attack traffic appearing to originate from local routers, legitimate commercial proxies, or servers in other countries. Traditional geographic blocking and IP-based filtering became ineffective.


QTRouter used Clash software to establish proxy connections and allowed operators to chain nodes together for additional obfuscation. The network included authentication servers at www.qtproxy[.]xyz and securelink.qtproxy[.]xyz, which were also seized in the operation.


The infrastructure utilized three major management platforms: Proxy Platform Management for overall network control, Proxy Pool Management System for device resource allocation, and QTBotnet for command and control of infected nodes. The QTBotnet controller also had capability to launch distributed denial of service attacks directly from compromised devices.


Attack Methodology


QTFY followed a consistent operational pattern. First, QScan conducted reconnaissance against target networks to identify vulnerabilities and exposed systems. The group then exploited both zero-day vulnerabilities and older known flaws to achieve initial access to victim networks.


Once inside, operators established persistence through remote access trojans, web shells, and harvested legitimate credentials. Finally, QTRouter was used to route all subsequent access through nearby compromised IoT devices, making the traffic appear local and blending malicious activity with normal network operations.


This approach allowed operators to maintain long-term access while remaining difficult to detect and attribute. The mixing of malicious and legitimate traffic was particularly effective at evading security monitoring.


The Disruption Method


Rather than simply taking servers offline, U.S. authorities seized the domains that were hard-coded into both QScan and QTRouter. This proved far more effective than traditional takedowns because these domains were essential to core operations including authentication and command-and-control communication.


When the FBI took control of the domains through court authorization, both platforms became inoperable. QScan could no longer receive scanning instructions or report results, and QTRouter could no longer authenticate nodes or manage proxy chains. Operators could not simply switch to backup servers since the domain names were embedded directly in the malware.


This represented a technical disruption rather than mere attribution - taking away the infrastructure criminals needed to manage their operations.


Sources


  • https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html

  • https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html

  • https://securityarsenal.com/blog/fbi-disrupts-china-linked-qtfy-infrastructure-defending-against-qscan-and-qtrouter-edge-device-compromise

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page