The U.S. Department of Justice and FBI on Wednesday announced the court-authorized disruption of QScan and QTRouter, two hacking platforms operated by a China-linked group known as QTFY. The DoJ tied the operation to Nanjing Xinjiuwei Network Technology Company and said victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
The action targets a proxy and botnet ecosystem that Chinese state-sponsored actors reportedly rented out to hide the origin of intrusions against U.S. critical infrastructure, a model researchers describe as an industrialized, multi-tenant utility network rather than a one-off hacking crew.
Key takeaways
- DoJ and FBI seized domains behind QScan and QTRouter, disabling both platforms since the addresses were hard-coded into the tools.
- QTFY has been active since May 2018 and is linked to Nanjing Xinjiuwei Network Technology Company, which serves China's MSS and PLA.
- Confirmed victims include NASA, the Federal Reserve, the DOJ, HHS, NIH, and the U.S. Senate, per the DoJ.
- The group exploited zero-day and N-day flaws in Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Microsoft Exchange, F5 BIG-IP, Log4j, Confluence, and other products for initial access.
- Lumen's Black Lotus Labs says an attack on a U.S. election system occurred as recently as June 2026.
Affected
What did the FBI and DoJ disrupt?
QTFY is a China-linked cyber contractor whose QScan and QTRouter platforms formed an obfuscation botnet used to mask the origin of intrusions into U.S. networks. The DoJ said on Wednesday it obtained court authorization to seize domains that both tools depended on, including qt-proxy[.]org, mq-task.qt-proxy[.]org, mq-result.qt-proxy[.]org, and the QTRouter administration servers www.qtproxy[.]xyz and securelink.qtproxy[.]xyz. Because these addresses were hard-coded into the software, the seizure caused both platforms to stop functioning.
FBI Director Kash Patel said the bureau disrupted "a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," adding that the tools let PRC cyber actors hide the origin of their attacks. The DoJ attributed the activity to Nanjing Xinjiuwei Network Technology Company, describing it as a contractor whose customers include China's Ministry of State Security and the People's Liberation Army.
Who has QTFY targeted since 2018?
According to the DoJ, confirmed QTFY victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. Damon Rouse, a researcher at Lumen's Black Lotus Labs who has tracked the group for roughly 18 months, told The Hacker News the operation has run since May 2018 and has hit targets "throughout the western world and beyond, especially with regard to academia."
Lumen said QTFY favors research communities "given the collaborative nature of advanced science," pointing to a pattern of academic and scientific-sector targeting alongside government systems. The company also told The Hacker News that an attack as recent as June 2026 hit a U.S. election system, indicating the infrastructure remained in active use up to the takedown.
How did QScan and QTRouter work?
QScan is the reconnaissance and infection tool: it scans and automatically compromises vulnerable IoT devices worldwide, feeding them into the QTRouter network as proxy nodes, per the FBI. QTRouter then combines those hijacked devices with commercial proxy service subscriptions and leased virtual private servers, using the Clash proxy tool to chain nodes together. The FBI said this design lets QTFY-affiliated actors "blend in with legitimate users when targeting victim organizations," since traffic passes through IP addresses associated with real consumer or business connections.
- QTBotnet: a controller server plus secondary control servers that manage compromised devices and can launch DDoS attacks or run commands remotely.
- Fast Labyrinth: an operational layer folding commercial proxy service Fastlink (fastlink.ws) into an encrypted relay alongside QTRouter.
- QTProxy: manages Fast Labyrinth nodes, letting operators use preset relays or build custom paths to targets.
Which vulnerabilities powered the intrusions?
The FBI outlined a repeatable attack cycle: QScan conducts reconnaissance, operators exploit zero-day flaws in Ivanti CSA appliances (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) alongside a long list of N-day bugs, then establish persistence with remote access trojans, web shells, or stolen credentials before routing final access through QTRouter's compromised IoT layer. The N-day list spans CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support.
Lumen described the wider setup as an operational relay box, or ORB network: a decentralized mesh of infected IoT devices and leased servers that routes traffic through rotating IPs to defeat blocklists and geolocation-based rules. "Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat," Lumen said.
Why does this matter beyond one takedown?
Lumen frames QTFY as evidence of growing industrialization in China-nexus cyber operations. Rather than each operator building bespoke infrastructure, groups increasingly rent access to shared, multi-tenant utility networks, a model that lets state-sponsored actors run complex campaigns with more anonymity, speed, and global reach than fragmented, ad hoc setups allow, per Lumen's statement to The Hacker News.
The FBI also said Nanjing operates as an enabling company with business ties to larger China-based cyber firms specializing in critical infrastructure security, and that it draws on contacts held by former PLA members to win contracts tied to critical infrastructure targeting. QTFY actors are also alleged to have traded exploits and network access inside China-based freelance hacking-broker networks.
What should defenders watch next?
Seizing hard-coded domains stopped QScan and QTRouter from functioning, but it does not retroactively patch the edge appliances QTFY exploited for initial access, nor does it reclaim every hijacked IoT device already folded into the botnet. Organizations running Ivanti CSA, Citrix ADC, F5 BIG-IP, CrushFTP, or BeyondTrust Remote Support should confirm those systems are on patched versions and review logs for the exploitation patterns the FBI described.
Because QTRouter blended malicious traffic with legitimate commercial proxy subscriptions and compromised consumer devices, defenders should treat static IP blocklists as insufficient on their own and instead watch for behavioral anomalies tied to proxy chaining and Clash-based connections, consistent with Lumen's own guidance on the ORB model.
Impact & actions
The FBI-led seizure disabled QScan and QTRouter by taking down domains hard-coded into both platforms, cutting off a proxy and botnet network that Chinese state-linked actors used to mask intrusions into U.S. federal and critical-infrastructure networks.
Security: The takedown removes shared attacker infrastructure but does not patch the underlying vulnerabilities QTFY exploited for initial access, so organizations running unpatched instances of the named products remain exposed to reinfection or use by other actors.
Privacy: Victims listed by the DoJ, including NASA, the Federal Reserve, and the U.S. Senate, faced potential data theft during intrusions that predate the disruption, though the extent of data taken has not been detailed publicly.
Recommended actions · High urgency
- 1Patch or verify remediation of the specific CVEs named in the DoJ advisory across Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Exchange, F5 BIG-IP, Kentico, Log4j, Confluence, Check Point, CrushFTP, and BeyondTrust deployments
- 2Audit IoT and router fleets for unauthorized OpenWrt modifications or Clash proxy configurations consistent with QTRouter
- 3Move detection beyond static IP blocklists toward behavioral and identity-based monitoring given the use of legitimate commercial proxy services
- 4Review logs for connections to the seized qt-proxy[.]org, qtproxy[.]xyz, and related domains
Technical details
- CVEs
- CVE-2024-8190, CVE-2024-8963, CVE-2024-9380, CVE-2018-13379, CVE-2019-19781, CVE-2021-26855, CVE-2020-5902, CVE-2019-10068, CVE-2021-44228, CVE-2023-22515, CVE-2024-24919, CVE-2025-31161, CVE-2026-1731
- Exploitation
- Exploited in the wild
- Attack vector
- QTFY used QScan to run reconnaissance and exploit zero-day and N-day flaws in internet-facing appliances for initial access, then deployed RATs, web shells, and stolen credentials for persistence before routing traffic through QTRouter's compromised IoT devices and leased proxies.
Indicators of compromise
- Domain
- qt-proxy.org — Domain hosting QScan components, seized in the DoJ/FBI action.
- Domain
- mq-task.qt-proxy.org — Distributed scanning tasks to QScan worker nodes.
- Domain
- mq-result.qt-proxy.org — Received completed QScan reconnaissance tasks.
- Domain
- qtproxy.xyz — QTRouter administration server domain, hard-coded into the malware and seized.
- Domain
- securelink.qtproxy.xyz — Secondary QTRouter administration server domain.
- Domain
- fastlink.ws — Commercial proxy infrastructure incorporated into the Fast Labyrinth relay layer, per Lumen Black Lotus Labs.
Mitigations
- Patch the named CVEs in Ivanti CSA, Citrix ADC, Fortinet SSL-VPN, Exchange, F5 BIG-IP, Kentico, Log4j, Confluence, Check Point, CrushFTP, and BeyondTrust products
- Rotate credentials and review persistence mechanisms (web shells, RATs) on internet-facing systems that ran affected software
Response
Authorities
Customer guidance
Organizations that ran any of the internet-facing products named in the DoJ advisory should verify patch status for the associated CVEs, audit IoT and router fleets for signs of QTRouter compromise, and move detection away from static IP blocklists toward behavioral monitoring.
FAQ
What are QScan and QTRouter?
QScan is a scanning tool that automatically finds and infects vulnerable IoT devices, while QTRouter is an obfuscation network combining hijacked IoT devices, commercial proxies, and leased VPSs to hide the origin of QTFY's intrusions.
Who is QTFY and who do they work for?
QTFY is a China-linked hacking group active since May 2018, tied to Nanjing Xinjiuwei Network Technology Company, which the DoJ says serves both China's Ministry of State Security and the People's Liberation Army as clients.
Which organizations were confirmed as victims?
The DoJ named NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate as victims of QTFY intrusion activity.
How did QTFY gain initial access to victim networks?
QTFY exploited zero-day flaws in Ivanti CSA and N-day vulnerabilities in products including Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Log4j, and Confluence, then established persistence with RATs, web shells, and stolen credentials.
Did the takedown fix the vulnerabilities QTFY exploited?
No. The disruption seized domains hard-coded into QScan and QTRouter, disabling the obfuscation infrastructure, but it did not patch the underlying software vulnerabilities QTFY used for initial access.
Why are static IP blocklists no longer enough to stop this activity?
Lumen Black Lotus Labs said QTFY's traffic passes through legitimately purchased commercial proxy subscriptions and hijacked IoT devices, mixing malicious traffic with legitimate users so static blocks miss it.
The bottom line
The DoJ and FBI seized domains that disabled QScan and QTRouter, dismantling obfuscation infrastructure that China-linked group QTFY used to hide intrusions into NASA, the Federal Reserve, and other U.S. organizations since 2018.
What happens next
What to do






