
FBI disrupts Chinese hacking infrastructure used to steal data
The U.S. Department of Justice announced on Wednesday that it disrupted two hacking platforms, QScan and QTRouter, used by China-linked actors to target critical infrastructure and other sensitive U.S. networks. FBI Director Kash Patel said the tools had been used to conceal the true origin of attacks by cyber actors from the People’s Republic of China. The activity has been attributed to a Chinese state-sponsored group known as QTFY, which was employed by Nanjing Xinjiuwei Network Technology Company. Damon Rouse, a security researcher at Lumen Black Lotus Labs, said he has tracked the group for more than 18 months and that it has been active since May 2018. Nanjing’s customers reportedly include China’s Ministry of State Security, or MSS, and the People’s Liberation Army, or PLA. Lumen said it began collaborating with the FBI on QTFY about a year ago. Its research found targeting across the Western world and beyond, particularly against academia and research communities. The company said those communities were attractive because advanced science is collaborative. Attacks as recently as June 2026 targeted a U.S. election system. The operation relied on two major tools. QScan scans vulnerable internet of things, or IoT, devices worldwide, automatically infects them, and adds them to the QTRouter network. QTRouter consists of compromised devices, commercial proxy-service devices, and leased virtual private servers, or VPSs. By sending traffic through QTRouter, QTFY and other Chinese cyber actors could conceal the real source of their intrusions. The FBI said QTRouter uses Clash to establish proxy connections and mixes malicious traffic with legitimate traffic on commercial proxy services. That can make activity appear to originate from endpoints outside China, including endpoints that may appear local to the targeted network. The traffic-obfuscation system runs on routers using custom OpenWrt software. It authenticates to administration servers at www.qtproxy[.]xyz and securelink.qtproxy[.]xyz. Because the domains were hard-coded into both products, the court-authorized seizure of the domains caused the platforms to stop operating. QTFY used three main systems to manage its botnets: Proxy Platform Management, Proxy Pool Management System, and QTBotnet. QTBotnet included a main controller server, secondary control servers that maintained communication, and compromised devices. Its control server could run commands on infected nodes and launch distributed denial-of-service, or DDoS, attacks. The FBI described Nanjing as an enabling company with business ties to larger China-based cyber-enabling firms that have expertise in critical-infrastructure security. The agency said the company includes former PLA members and uses their contacts to obtain contracts related to critical-infrastructure targeting. FBI also alleged that QTFY actors participated in China-based freelance brokering networks to acquire and sell exploits, including access to victim networks. Home routers and other IoT devices that are not kept up to date can become part of networks like these. That is relevant to Soomaali users at home and in the diaspora who depend on household, office, and mobile internet: changing default passwords and applying available updates can reduce the chance that their devices are used in attacks elsewhere.
Read our sourcing and corrections policy
This article was prepared by our automated editorial system, which summarized and translated the source above. No human editor reviewed this article individually before publication.



Be the first to comment on this story!