FBI Takes Down QTFY Proxy Network Used in China-Linked Intrusions
The U.S. Department of Justice and the FBI have disrupted infrastructure that Chinese state-linked operators allegedly used to compromise organizations and conceal their activity. The operation target...
The U.S. Department of Justice and the FBI have disrupted infrastructure that Chinese state-linked operators allegedly used to compromise organizations and conceal their activity. The operation targeted two related platforms, QScan and QTRouter, attributed to a group known as QTFY and linked to Nanjing Xinjiuwei Network Technology Company.
According to the Justice Department, victims included organizations connected to NASA, the Federal Reserve, the departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the U.S. Senate. Security researchers also said the activity affected targets across Western countries, with academic and research institutions receiving particular attention.
Scanning and proxy capabilities
QScan allegedly scanned internet-connected devices and victim networks, then exploited vulnerable systems or identified devices suitable for incorporation into the QTRouter network. QTRouter combined compromised routers and other IoT equipment with leased servers and commercial proxy services. This arrangement allowed operators to route traffic through changing locations, making malicious connections appear to originate from legitimate users or networks closer to the intended targets.
Investigators said the system used customized OpenWrt-based software and the Clash proxy framework to chain multiple relay nodes. Additional management platforms controlled the proxy pool and infected devices, while the QTBotnet infrastructure could issue commands and, in some cases, support distributed denial-of-service attacks.
Exploited vulnerabilities
The reported intrusion sequence involved reconnaissance, exploitation, persistence, and concealed access. Authorities and researchers linked the activity to exploitation of both recently disclosed and older vulnerabilities, including flaws in Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point gateways, CrushFTP, and BeyondTrust Remote Support. Attackers reportedly used web shells, remote-access malware, and stolen credentials after gaining entry.
The seized domains were embedded in the affected tools, according to the authorities, causing the platforms to stop functioning after the court-authorized disruption. Lumen Black Lotus Labs said it had tracked QTFY for more than 18 months and began cooperating with the FBI approximately a year ago.
The case highlights the growing use of shared relay and proxy networks by state-sponsored groups. Such infrastructure can make attribution and blocking more difficult by blending hostile traffic with ordinary internet activity. Organizations should prioritize timely patching of perimeter appliances, review unexpected remote access, rotate exposed credentials, and monitor IoT devices for unusual outbound connections.
