Zero Day Room
Live
Vulnerabilities

FBI disrupts China-linked QTFY hacking platforms

The U.S. Department of Justice announced the disruption of QScan and QTRouter, two hacking platforms operated by the Chinese threat group QTFY, linked to Nanjing Xinjiuwei Network Technology Company. The DoJ said the tools targeted critical U.S. infrastructure, including NASA, the Federal Reserve and the Department of Energy.

The U.S. Department of Justice announced the disruption of QScan and QTRouter, two hacking platforms operated by the...

The U.S. Department of Justice announced on Wednesday that it had disrupted two hacking platforms-QScan and QTRouter-used by the Chinese threat group QTFY, which is operated by Nanjing Xinjiuwei Network Technology Company. The action was part of a broader effort to stop the group’s attacks on critical U.S. infrastructure, and the DoJ shared the details on its website, where the seized domains are listed in the stats section.

Victims of the QTFY intrusion campaign include the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate, the DoJ said. The list of affected organizations is available in the agency’s public release and can be cross-referenced in the fixtures database.

Lumen Black Lotus Labs’ security researcher Damon Rouse has been tracking QTFY activity for 18 months, noting that the group has been active since May 2018. Rouse, who is part of Lumen’s squad that collaborates with the FBI, said that Nanjing counts China’s Ministry of State Security and the People’s Liberation Army among its customers.

QScan is a scanning tool that automatically infects IoT devices worldwide and then adds them to the QTRouter network. QTRouter, which runs on routers with custom OpenWrt software, authenticates to administration servers at www.qtproxy.xyz and securelink.qtproxy.xyz and uses Clash to establish proxy connections. The botnet’s architecture includes a Proxy Platform Management system, a Proxy Pool Management System and QTBotnet, which contains a controller server that can launch DDoS attacks and run commands on infected nodes.

The FBI’s statement described the attack cycle: QScan conducts reconnaissance, exploits zero-day and N-day vulnerabilities (such as CVE-2024-8190 in Ivanti CSA appliances and CVE-2021-44228 in Apache Log4j), establishes persistence with remote access trojans and web shells, and then uses QTRouter to access victim networks from nearby compromised IoT devices. The seized domains were hard-coded into both products, causing them to cease operations after the court-authorized action. Attacks as recent as June 2026 targeted a U.S. election system, underscoring the group’s continued threat.

The FBI and Lumen highlighted that QTFY’s infrastructure resembles a decentralized mesh-an operational relay box that routes malicious traffic through rotating IPs and evades traditional defenses such as IP blocklists and location-based policies. The group’s use of legitimate paid subscriptions to commercial proxy services means that static blocks are no longer sufficient to stop the threat. The disruption marks a significant step in countering state-sponsored cyber operations that industrialize malicious tooling and exploit networks on a global scale.

Related coverage

More from Vulnerabilities