# Chinese State-Sponsored Hackers Disrupted After Operating Global Botnet to Target U.S. Critical Infrastructure
**WASHINGTON** — Federal authorities have successfully dismantled two hacking platforms linked to a Chinese state-sponsored cyber-espionage group that had been quietly waging a sustained campaign against critical infrastructure networks across the United States and beyond.
## The Operation and the Actors Behind It
The U.S. Department of Justice revealed on Wednesday that it had executed court-authorized actions to seize infrastructure tied to hacking tools called QScan and QTRouter. These platforms were operated by a Chinese state-sponsored group identified as QTFY, which is associated with Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).
The group has been described as functioning as a digital “quartermaster,” providing a suite of cyber tools and services that enable other Chinese actors to conduct intrusions against sensitive targets. Security researchers note that QTFY has been active since May 2018, and the company behind the operation serves a clientele that includes both China’s Ministry of State Security and elements of the People’s Liberation Army.
## Scope of the Victims
The reach of QTFY’s operations has been far-reaching. According to the DoJ, victims of the group’s intrusion activities include some of the most sensitive institutions in the United States:
– National Aeronautics and Space Administration (NASA)
– Federal Reserve
– Department of Energy
– Department of Justice
– Department of Health and Human Services
– National Institutes of Health
– U.S. Senate
The FBI’s investigation, which began approximately a year ago in collaboration with Lumen Technologies’ Black Lotus Labs, uncovered that the targeting extended well beyond these entities. Academic institutions and research communities across the western world were also heavily targeted, with the group showing a particular interest in exploiting the open, collaborative nature of advanced scientific research.
## How the Hacking Platform Worked
### QScan: The Reconnaissance Engine
QScan served as the group’s primary scanning tool, designed to sweep the globe for vulnerable Internet of Things (IoT) devices. Once a device was identified as exploitable, QScan would automatically compromise it and recruit it into a growing network of infected machines known as QTRouter.
The scanning component operated through a network of domains that hosted various parts of the system, including proxy servers, task distribution nodes, and result-collection endpoints. Worker nodes were primarily housed on leased servers located outside of China, allowing the group to mask the geographic origin of their operations.
### QTRouter: The Obfuscation Network
QTRouter functioned as an elaborate traffic-mixing system designed to hide the true origins of cyber attacks. The network ran on compromised routers equipped with custom OpenWrt software, combined with commercial proxy services and leased virtual private servers (VPSs). By chaining together nodes and mixing malicious traffic with legitimate user traffic, QTRouter made it exceptionally difficult for defenders and investigators to trace attacks back to their source.
The system used a tool called Clash to establish proxy connections, allowing operators to view available nodes, chain multiple nodes together, and route malicious communications through rotating IP addresses. This effectively created what investigators described as an operational relay box — a decentralized mesh that could route traffic through compromised IoT devices and leased servers, evading traditional defenses like IP blocklists and location-based filtering.
### The Attack Lifecycle
The entire operation followed a carefully structured sequence:
1. **Reconnaissance** — QScan was deployed to map out target networks and identify vulnerable IoT devices.
2. **Initial Access** — A wide array of zero-day and known vulnerabilities were exploited, including flaws in Ivanti CSA appliances, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, and several other products.
3. **Persistence** — Once inside the network, attackers established footholds using remote access trojans (RATs), web shells, and stolen legitimate credentials.
4. **Obfuscated Access** — QTRouter was then used to access victim networks from nearby compromised IoT devices, making the traffic appear as though it originated from local endpoints rather than from operators based in China.
## Command and Control Infrastructure
The compromised device botnets were managed through three major platforms: a Proxy Platform Management system, a Proxy Pool Management System, and QTBotnet. The QTBotnet component included a central controller server, secondary-level control servers for maintaining communication with compromised devices, and the infected devices themselves. Notably, the control server was also equipped with the capability to launch distributed denial-of-service (DDoS) attacks and execute commands on infected nodes.
## Broader Infrastructure Ecosystem
According to Lumen, the hacking group’s operations extended beyond QScan and QTRouter alone. Two additional components — Fast Labyrinth and QTProxy — formed part of the broader ecosystem:
– **Fast Labyrinth** provided the operational layer by integrating commercial proxy infrastructure into an encrypted relay network alongside QTRouter.
– **QTProxy** managed the operational nodes of Fast Labyrinth, giving operators the ability to use preconfigured relays or create custom routing paths to reach target entities.
The entire distributed architecture was described as an industrialized cyber operation, marking a significant shift from fragmented, ad hoc hacking setups toward shared, multi-tenant utility networks that allow state-sponsored actors to execute complex campaigns at global scale with unprecedented speed and anonymity.
## Enabling Company and Freelance Networks
The FBI characterized Nanjing Xinjiuwei as an “enabling company” that maintained business relationships with larger Chinese-based cyber-enabling organizations possessing expertise in critical infrastructure security. The company reportedly leveraged former PLA members and their professional contacts to secure contracts specifically related to targeting critical infrastructure.
Additionally, QTFY actors were found to have participated in China-based freelance brokering networks, where they acquired and sold cyber exploit items — including unauthorized access to victim networks. The most recent known attack, carried out as recently as June 2026, targeted a U.S. election system, underscoring the ongoing and evolving nature of the threat.
## Impact of the Disruption
The seized domains were hard-coded into both QScan and QTRouter, meaning that the court-authorized action effectively rendered both platforms inoperable. As the FBI noted, the seizure of this infrastructure represents a significant blow to China’s cyber-espionage capabilities targeting the United States.
“These tools were used by PRC cyber actors to hide the origin of their attacks,” said FBI Director Kash Patel. “Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.”
—
## Frequently Asked Questions (FAQ)
**Q1: Who is QTFY?**
A1: QTFY is a Chinese state-sponsored cyber-espionage group that has been operating since 2018. It is linked to Nanjing Xinjiuwei Network Technology Company and is believed to serve clients within China’s Ministry of State Security and the People’s Liberation Army.
**Q2: What were QScan and QTRouter used for?**
A2: QScan was used to scan the internet for vulnerable IoT devices and automatically compromise them, while QTRouter served as a network obfuscation platform that masked the origin of cyber attacks by routing malicious traffic through compromised devices and commercial proxy services.
**Q3: Which organizations were affected by QTFY’s activities?**
A3: Victims included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, the U.S. Senate, and numerous academic and research institutions.
**Q4: How were the hacking platforms taken down?**
A4: The FBI executed a court-authorized operation to seize the domains hard-coded into QScan and QTRouter, which caused both platforms to cease functioning. The infrastructure was disrupted in coordination with Lumen Technologies’ Black Lotus Labs.
**Q5: Why was QTRouter so effective at evading detection?**
A5: QTRouter blended malicious traffic with legitimate user traffic on commercial proxy services and used compromised IoT devices to make communications appear as though they originated from local endpoints or locations outside China, making it extremely difficult for traditional security tools like IP blocklists to detect the activity.
**Q6: What vulnerabilities did QTFY exploit?**
A6: The group exploited a wide range of zero-day and known vulnerabilities affecting products from Ivanti, Fortinet, Citrix, Microsoft, F5, Apache, Atlassian, Check Point, CrushFTP, and BeyondTrust, among others.
**Q7: What makes this operation different from typical cyber attacks?**
A7: Lumen described it as a highly industrialized operation — a shift from fragmented hacking setups to shared, multi-tenant utility networks that enable state-sponsored actors to conduct complex, large-scale campaigns with speed and anonymity.
**Q8: Are the threats fully eliminated?**
A8: While the seized domains have been taken offline and the platforms are no longer operational, the underlying techniques and skills of the threat actors may persist. Organizations are encouraged to remain vigilant, patch known vulnerabilities promptly, and implement robust network monitoring practices.
—
## Conclusion
The disruption of QScan and QTRouter marks a significant milestone in the effort to counter state-sponsored cyber threats targeting the United States. The operation exposed the extent to which cyber-espionage has become a commercialized, industrialized enterprise — one that leverages shared infrastructure, legitimate services, and a vast network of compromised IoT devices to carry out attacks at scale while maintaining a high degree of anonymity.
The targeting of critical institutions, from the nation’s space agency to its financial system and election infrastructure, underscores the severity of the threat posed by groups like QTFY. As the FBI noted, the shift toward shared multi-tenant networks means that traditional static defenses are no longer sufficient, and more dynamic, collaborative approaches to threat detection and disruption are needed.
This operation also highlights the importance of private-sector collaboration with federal law enforcement. Lumen Technologies’ Black Lotus Labs played a pivotal role in tracking the group’s activity for over a year, and their work directly contributed to the success of the takedown.
Going forward, organizations — particularly those in critical infrastructure and research — must remain proactive in securing their networks, patching known vulnerabilities, and monitoring for signs of compromise. The disruption of these platforms is a major win, but the landscape of state-sponsored cyber threats continues to evolve, demanding constant vigilance and innovation in defense.
Thank you for reading



