Skip to content
Beveiligingsnieuws

FBI disrupts QTFY proxy network targeting US

QTFY-infrastructuur

The U.S. Department of Justice (DoJ) and the FBI have announced a disruption of hacking infrastructure tied to a China-linked activity cluster known as QTFY. The operation focused on two platforms, QScan and QTRouter, which were used to scan for weaknesses, compromise devices, and conceal the true origin of malicious traffic. Together, these tools formed what security researchers describe as a proxy-and-relay system designed to make attribution and tracking much harder.

According to the DoJ, victims of the QTFY intrusion activity included well-known U.S. organizations across multiple sectors. The FBI said the tools were used by China-based actors to hide where attacks actually began, while blending malicious communications into patterns that look similar to legitimate traffic.

Two platforms at the center of the takedown

The DoJ announcement highlights two key components. The first, QScan, is described as a scanning and automated infection mechanism targeting IoT devices. Rather than only searching for exposed systems, it also helps expand the reach of the operation by identifying vulnerable devices and adding them into a broader network.

The second component, QTRouter, acts as the traffic-routing and concealment layer. It is built on compromised devices alongside additional proxy service resources, including leased virtual private servers (VPSs). The result is a distributed setup that can obscure the initial source of activity by making communications appear to originate elsewhere.

Why the QTFY proxy network is hard to trace

In practice, the QTFY proxy network works by combining compromised endpoints with commercial proxy services and network relays. The FBI described QTRouter as an obfuscation network that can make it appear that communications come from endpoints located outside China—potentially closer to the targeted organization.

This design matters because many traditional defenses rely on static indicators, fixed IP blocklists, or location-based policies. When traffic is routed through changing proxies and mixed with lookalike “legitimate” flows, those controls become less effective.

Lumen Black Lotus Labs, which has tracked the activity for roughly 18 months, emphasized the operational maturity of the approach. The company also said that targeting extended beyond isolated technical environments, including academic communities, likely due to the collaborative nature of research efforts.

How QScan and QTRouter work together

Security reporting describes a cycle where reconnaissance comes first and exploitation follows. The FBI outlined an overall workflow where QScan performs scanning against victim environments, then attackers use vulnerabilities to gain initial entry.

After gaining access, the operators establish persistence using techniques such as remote access trojans (RATs), web shells, and legitimate credentials. From there, QTRouter can be used so the attacker’s traffic appears to come from compromised IoT systems in the region or “near” the victim’s network. This reduces the likelihood of being flagged during early investigation.

Compromised devices used as proxy nodes

QScan is associated with multiple domains that host different system components. The reporting mentions domains used for hosting proxy-related services and task distribution, including components for providing scanning tasks to worker nodes and receiving completed results. Those parts support the large-scale harvesting of vulnerable IoT targets.

Once devices are compromised, QTFY uses botnet products to control them and enroll them as proxy nodes inside the QTRouter layer. The FBI stated this helps attackers “blend in” with legitimate users when targeting victim organizations.

Vulnerabilities used to gain initial access

The DoJ and FBI reporting includes examples of both zero-day and previously known vulnerabilities used to break into target networks. The list referenced includes flaws affecting a range of widely deployed enterprise and edge products, such as Ivanti CSA appliances, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, and more.

Some examples highlighted in the reporting include:

  • CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 (Ivanti CSA appliances)
  • CVE-2018-13379 (Fortinet SSL-VPN)
  • CVE-2019-19781 (Citrix ADC)
  • CVE-2021-26855 (Microsoft Exchange Server)
  • CVE-2020-5902 (F5 BIG-IP)
  • CVE-2021-44228 (Apache Log4j)
  • CVE-2023-22515 (Atlassian Confluence)
  • CVE-2020-5902 (F5 BIG-IP)
  • CVE-2024-24919 (Check Point Quantum Gateway)
  • CVE-2025-31161 (CrushFTP)
  • CVE-2026-1731 (BeyondTrust Remote Support)

While the exact implementation details are not fully described in the public announcement, the takeaway is clear: the QTFY proxy network was paired with exploitation of vulnerabilities across multiple technologies, enabling rapid entry into diverse environments.

Targets and alleged victims

The DoJ specifically listed multiple U.S. organizations as victims of QTFY-related intrusion activity. Among those named were the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

These names underline that the activity was not limited to a narrow set of industries. Instead, it appears to have focused on sensitive, high-impact systems and networks that could support longer-term espionage or data theft.

The role of court-authorized disruption

According to the reporting, seized domains were hard-coded into both products. That design choice meant the platforms would stop operating once the court-authorized action took effect. In other words, taking over the infrastructure disrupted both the scanning capability and the routing/obfuscation layer.

FBI Director Kash Patel said the announcement involved the disruption of a global botnet and hacking platform used to target U.S. critical infrastructure. He also noted that the tools helped conceal the origin of attacks carried out by China-linked actors.

An infrastructure described as an operational relay mesh

Lumen described the system as resembling an operational relay box (ORB): a decentralized mesh combining infected IoT devices and leased VPS resources. In such a design, malicious traffic can be routed through rotating IPs, which can help avoid traditional defensive approaches like IP blocklists and location-based restrictions.

The reporting also points to additional operational layers connected to the QTFY ecosystem. Lumen mentioned an operational layer called Fast Labyrinth, which incorporates commercial proxy infrastructure into an encrypted relay network together with the QTRouter approach. Lumen also referenced QTProxy as a management layer that supports operational nodes and allows operators to use preconfigured relays or define paths to target entities.

Why static blocks are no longer enough

The disruption highlights a broader security problem. When transit loops depend on legitimate paid proxy subscriptions, defenders can’t rely solely on static IP blocking. If traffic is routed through credible proxy services and mixed with normal-looking patterns, it becomes easier for attackers to reduce the signal-to-noise ratio during detection.

In that environment, organizations need stronger visibility and validation: monitoring for suspicious scanning patterns, unusual remote access behavior, and proxy-like routing characteristics that don’t match normal operations.

Industrialized capability and broader campaigns

The FBI and Lumen characterize the QTFY activity as part of a more industrialized model of cyber operations. Rather than relying only on ad hoc setups, the approach described in the reporting suggests a utility-like infrastructure where shared components can be scaled across campaigns.

Lumen also said QTFY activity has been active since at least May 2018, and that Nanjing-related entities had ties that include both the Ministry of State Security (MSS) and the People’s Liberation Army (PLA) among its customers. Separately, the FBI reported that the broader group’s activity included developing malicious tooling, trading exploits, maintaining an obfuscation botnet, and targeting critical systems within the United States.

Finally, the reporting notes that more recent activity, including attacks as late as June 2026, had targeted a U.S. election system. While the announcement focuses on the disrupted infrastructure, this detail signals the continuing evolution of the threat activity.

What this means for organizations

The disruption of the QTFY proxy network is a meaningful step, but the tactics described—scanning, exploitation, persistence, and obfuscated routing—will likely remain relevant for other operators using similar concepts. Organizations should treat this as a prompt to harden externally facing services, patch quickly, and audit systems for suspicious remote access and unexpected traffic paths.

If you operate critical infrastructure or support sensitive networks, focus on reducing exposure of IoT and edge devices, improving detection for reconnaissance phases, and strengthening controls around outbound and proxy-like communications.

Conclusion: The DoJ and FBI announced the disruption of QScan and QTRouter, two platforms tied to the QTFY intrusion activity. By combining IoT exploitation with an obfuscation proxy routing layer, the QTFY proxy network helped attackers conceal where their operations originated. While the takedown disrupted parts of the infrastructure, the broader defensive lesson remains: modern campaigns blend malicious activity into legitimate-looking routing paths, so response strategies must go beyond static blocks.

Source: https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html