Security advisory
CybersecurityHighMitigatedUpdated Aug 31, 2026

FBI Disrupts China-Linked QTFY Botnet Infrastructure Targeting US Networks

Court-authorized seizures took down proxy infrastructure that let a Nanjing-based cyber contractor mask intrusions against U.S. federal agencies and research institutions since 2018.

Emanuel De AlmeidaAug 31, 2026, 3:42 PM7 min read
Severity
High
Status
Mitigated
Entity
QTFY
Confirmed by
U.S. Department of Justice and FBI

The U.S. Department of Justice and FBI on Wednesday announced the court-authorized disruption of QScan and QTRouter, two hacking platforms operated by a China-linked group known as QTFY. The DoJ tied the operation to Nanjing Xinjiuwei Network Technology Company and said victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

The action targets a proxy and botnet ecosystem that Chinese state-sponsored actors reportedly rented out to hide the origin of intrusions against U.S. critical infrastructure, a model researchers describe as an industrialized, multi-tenant utility network rather than a one-off hacking crew.

Key takeaways

  • DoJ and FBI seized domains behind QScan and QTRouter, disabling both platforms since the addresses were hard-coded into the tools.
  • QTFY has been active since May 2018 and is linked to Nanjing Xinjiuwei Network Technology Company, which serves China's MSS and PLA.
  • Confirmed victims include NASA, the Federal Reserve, the DOJ, HHS, NIH, and the U.S. Senate, per the DoJ.
  • The group exploited zero-day and N-day flaws in Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Microsoft Exchange, F5 BIG-IP, Log4j, Confluence, and other products for initial access.
  • Lumen's Black Lotus Labs says an attack on a U.S. election system occurred as recently as June 2026.

Affected

Vendors
IvantiFortinetCitrixMicrosoftF5KenticoApacheAtlassianCheck PointCrushFTPBeyondTrust
Products
Ivanti CSAFortinet SSL-VPNCitrix ADCMicrosoft Exchange ServerF5 BIG-IPKentico CMSApache Log4jAtlassian ConfluenceCheck Point Quantum GatewayCrushFTPBeyondTrust Remote Support
Organizations
NASAFederal ReserveDepartment of EnergyDepartment of JusticeDepartment of Health and Human ServicesNational Institutes of HealthU.S. Senate
Threat actors
QTFY
Malware
QScanQTRouterQTBotnetFast LabyrinthQTProxy
Geography
United StatesChinaGlobal
Industry
GovernmentCritical InfrastructureEducation/ResearchFinancial Services
CVEs
CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2018-13379CVE-2019-19781CVE-2021-26855CVE-2020-5902CVE-2019-10068CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2025-31161CVE-2026-1731

What did the FBI and DoJ disrupt?

QTFY is a China-linked cyber contractor whose QScan and QTRouter platforms formed an obfuscation botnet used to mask the origin of intrusions into U.S. networks. The DoJ said on Wednesday it obtained court authorization to seize domains that both tools depended on, including qt-proxy[.]org, mq-task.qt-proxy[.]org, mq-result.qt-proxy[.]org, and the QTRouter administration servers www.qtproxy[.]xyz and securelink.qtproxy[.]xyz. Because these addresses were hard-coded into the software, the seizure caused both platforms to stop functioning.

FBI Director Kash Patel said the bureau disrupted "a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," adding that the tools let PRC cyber actors hide the origin of their attacks. The DoJ attributed the activity to Nanjing Xinjiuwei Network Technology Company, describing it as a contractor whose customers include China's Ministry of State Security and the People's Liberation Army.

Who has QTFY targeted since 2018?

According to the DoJ, confirmed QTFY victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. Damon Rouse, a researcher at Lumen's Black Lotus Labs who has tracked the group for roughly 18 months, told The Hacker News the operation has run since May 2018 and has hit targets "throughout the western world and beyond, especially with regard to academia."

Lumen said QTFY favors research communities "given the collaborative nature of advanced science," pointing to a pattern of academic and scientific-sector targeting alongside government systems. The company also told The Hacker News that an attack as recent as June 2026 hit a U.S. election system, indicating the infrastructure remained in active use up to the takedown.

How did QScan and QTRouter work?

QScan is the reconnaissance and infection tool: it scans and automatically compromises vulnerable IoT devices worldwide, feeding them into the QTRouter network as proxy nodes, per the FBI. QTRouter then combines those hijacked devices with commercial proxy service subscriptions and leased virtual private servers, using the Clash proxy tool to chain nodes together. The FBI said this design lets QTFY-affiliated actors "blend in with legitimate users when targeting victim organizations," since traffic passes through IP addresses associated with real consumer or business connections.

  • QTBotnet: a controller server plus secondary control servers that manage compromised devices and can launch DDoS attacks or run commands remotely.
  • Fast Labyrinth: an operational layer folding commercial proxy service Fastlink (fastlink.ws) into an encrypted relay alongside QTRouter.
  • QTProxy: manages Fast Labyrinth nodes, letting operators use preset relays or build custom paths to targets.

Which vulnerabilities powered the intrusions?

The FBI outlined a repeatable attack cycle: QScan conducts reconnaissance, operators exploit zero-day flaws in Ivanti CSA appliances (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) alongside a long list of N-day bugs, then establish persistence with remote access trojans, web shells, or stolen credentials before routing final access through QTRouter's compromised IoT layer. The N-day list spans CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support.

Lumen described the wider setup as an operational relay box, or ORB network: a decentralized mesh of infected IoT devices and leased servers that routes traffic through rotating IPs to defeat blocklists and geolocation-based rules. "Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat," Lumen said.

Why does this matter beyond one takedown?

Lumen frames QTFY as evidence of growing industrialization in China-nexus cyber operations. Rather than each operator building bespoke infrastructure, groups increasingly rent access to shared, multi-tenant utility networks, a model that lets state-sponsored actors run complex campaigns with more anonymity, speed, and global reach than fragmented, ad hoc setups allow, per Lumen's statement to The Hacker News.

The FBI also said Nanjing operates as an enabling company with business ties to larger China-based cyber firms specializing in critical infrastructure security, and that it draws on contacts held by former PLA members to win contracts tied to critical infrastructure targeting. QTFY actors are also alleged to have traded exploits and network access inside China-based freelance hacking-broker networks.

What should defenders watch next?

Seizing hard-coded domains stopped QScan and QTRouter from functioning, but it does not retroactively patch the edge appliances QTFY exploited for initial access, nor does it reclaim every hijacked IoT device already folded into the botnet. Organizations running Ivanti CSA, Citrix ADC, F5 BIG-IP, CrushFTP, or BeyondTrust Remote Support should confirm those systems are on patched versions and review logs for the exploitation patterns the FBI described.

Because QTRouter blended malicious traffic with legitimate commercial proxy subscriptions and compromised consumer devices, defenders should treat static IP blocklists as insufficient on their own and instead watch for behavioral anomalies tied to proxy chaining and Clash-based connections, consistent with Lumen's own guidance on the ORB model.

Impact & actions

The FBI-led seizure disabled QScan and QTRouter by taking down domains hard-coded into both platforms, cutting off a proxy and botnet network that Chinese state-linked actors used to mask intrusions into U.S. federal and critical-infrastructure networks.

Security: The takedown removes shared attacker infrastructure but does not patch the underlying vulnerabilities QTFY exploited for initial access, so organizations running unpatched instances of the named products remain exposed to reinfection or use by other actors.

Privacy: Victims listed by the DoJ, including NASA, the Federal Reserve, and the U.S. Senate, faced potential data theft during intrusions that predate the disruption, though the extent of data taken has not been detailed publicly.

Recommended actions · High urgency

  1. 1Patch or verify remediation of the specific CVEs named in the DoJ advisory across Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Exchange, F5 BIG-IP, Kentico, Log4j, Confluence, Check Point, CrushFTP, and BeyondTrust deployments
  2. 2Audit IoT and router fleets for unauthorized OpenWrt modifications or Clash proxy configurations consistent with QTRouter
  3. 3Move detection beyond static IP blocklists toward behavioral and identity-based monitoring given the use of legitimate commercial proxy services
  4. 4Review logs for connections to the seized qt-proxy[.]org, qtproxy[.]xyz, and related domains

Technical details

CVEs
CVE-2024-8190, CVE-2024-8963, CVE-2024-9380, CVE-2018-13379, CVE-2019-19781, CVE-2021-26855, CVE-2020-5902, CVE-2019-10068, CVE-2021-44228, CVE-2023-22515, CVE-2024-24919, CVE-2025-31161, CVE-2026-1731
Exploitation
Exploited in the wild
Attack vector
QTFY used QScan to run reconnaissance and exploit zero-day and N-day flaws in internet-facing appliances for initial access, then deployed RATs, web shells, and stolen credentials for persistence before routing traffic through QTRouter's compromised IoT devices and leased proxies.

Indicators of compromise

Domain
qt-proxy.org — Domain hosting QScan components, seized in the DoJ/FBI action.
Domain
mq-task.qt-proxy.org — Distributed scanning tasks to QScan worker nodes.
Domain
mq-result.qt-proxy.org — Received completed QScan reconnaissance tasks.
Domain
qtproxy.xyz — QTRouter administration server domain, hard-coded into the malware and seized.
Domain
securelink.qtproxy.xyz — Secondary QTRouter administration server domain.
Domain
fastlink.ws — Commercial proxy infrastructure incorporated into the Fast Labyrinth relay layer, per Lumen Black Lotus Labs.

Mitigations

  • Patch the named CVEs in Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Exchange, F5 BIG-IP, Kentico, Log4j, Confluence, Check Point, CrushFTP, and BeyondTrust products
  • Rotate credentials and review persistence mechanisms (web shells, RATs) on internet-facing systems that ran affected software

Response

Authorities

FBI Director Kash Patel said the bureau disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure, adding that the tools were used by PRC cyber actors to hide the origin of their attacks.

Customer guidance

Organizations that ran any of the internet-facing products named in the DoJ advisory should verify patch status for the associated CVEs, audit IoT and router fleets for signs of QTRouter compromise, and move detection away from static IP blocklists toward behavioral monitoring.

FAQ

What are QScan and QTRouter?

QScan is a scanning tool that automatically finds and infects vulnerable IoT devices, while QTRouter is an obfuscation network combining hijacked IoT devices, commercial proxies, and leased VPSs to hide the origin of QTFY's intrusions.

Who is QTFY and who do they work for?

QTFY is a China-linked hacking group active since May 2018, tied to Nanjing Xinjiuwei Network Technology Company, which the DoJ says serves both China's Ministry of State Security and the People's Liberation Army as clients.

Which organizations were confirmed as victims?

The DoJ named NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate as victims of QTFY intrusion activity.

How did QTFY gain initial access to victim networks?

QTFY exploited zero-day flaws in Ivanti CSA and N-day vulnerabilities in products including Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Log4j, and Confluence, then established persistence with RATs, web shells, and stolen credentials.

Did the takedown fix the vulnerabilities QTFY exploited?

No. The disruption seized domains hard-coded into QScan and QTRouter, disabling the obfuscation infrastructure, but it did not patch the underlying software vulnerabilities QTFY used for initial access.

Why are static IP blocklists no longer enough to stop this activity?

Lumen Black Lotus Labs said QTFY's traffic passes through legitimately purchased commercial proxy subscriptions and hijacked IoT devices, mixing malicious traffic with legitimate users so static blocks miss it.

The bottom line

The DoJ and FBI seized domains that disabled QScan and QTRouter, dismantling obfuscation infrastructure that China-linked group QTFY used to hide intrusions into NASA, the Federal Reserve, and other U.S. organizations since 2018.

What happens next

Defenders should expect QTFY-linked actors to attempt to rebuild proxy infrastructure using new domains and commercial services, while researchers such as Lumen continue tracking related botnet components like Fast Labyrinth and QTProxy. Related articles: Hide Category View in Windows 11 Start Menu Using Intune · Next.js Patches Critical AVIF and Windows RCE Flaws · CISA Orders Federal Agencies to Patch Exploited Langflow Auth Bypass by Friday · Pulumi vs Terraform: Which IaC Tool Should You Choose? · Zabbix vs PRTG: Which Network Monitoring Tool Should You Choose? · Cloudflare vs Akamai: Which CDN and Edge Security Platform Should You Choose?.

What to do

Check whether your organization runs any of the named vulnerable products and confirm the associated CVEs are patched.
Topics:#Fbi

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles