HackMyIP
← Back to News
2026-08-31 The Hacker News

DoJ: U.S. Agencies Targeted by Chinese QTFY Hackers — Not Confirmed Breached

APTThreat IntelMalware

The U.S. Department of Justice issued a correction to a previous press statement, clarifying that several federal agencies were "targets" — not confirmed "victims" — of intrusions orchestrated by a Chinese state-sponsored threat group known as QTFY (aka QT or QTCYBER). Originally listed as victims in last week's disclosure were the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. "Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures," the DoJ noted. The linguistic shift is significant: being targeted does not equate to being compromised, narrowing the scope of confirmed breaches.

According to the underlying affidavit, QTFY operates on behalf of Nanjing Xinjiuwei Network Technology Co, a private Chinese firm receiving payments from the Ministry of State Security (MSS). Active since 2018, the group functions as a "technical quartermaster," supplying reconnaissance, proxy management, and operational routing services to broader Chinese cyber-espionage operations. Two products anchor its toolkit: QScan, a vulnerability scanning and exploitation platform, and QTRouter, an obfuscation network designed to mask the origin of malicious traffic. In a 2019 campaign, QTFY attempted to breach NASA's perimeter by exploiting CVE-2019-11510, a critical Pulse Secure VPN flaw — one of several CVEs cataloged in its scanner's arsenal.

The FBI has since seized three domains connected to the malware infrastructure — qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com — effectively neutralizing QScan and QTRouter by cutting off their control plane. Investigators at Lumen Black Lotus Labs added further context, revealing that QTFY has industrialized the creation of Operational Relay Box (ORB) networks — decentralized botnets built from infected IoT devices and leased VPSs — which enable Chinese espionage operators to route traffic through thousands of compromised endpoints and obscure attribution. The seizure of these WHOIS records and supporting domains is part of a broader effort to dismantle the upstream tooling used by downstream intrusion crews across hospitals, telecom operators, power companies, financial institutions, and defense contractors.

For organizations assessing exposure, the episode underscores how proxy-layer obfuscation can mask even heavily resourced nation-state operations. Security teams should audit egress traffic against known ORB indicators, scan remote access appliances for legacy Pulse Secure VPN versions, and use a VPN and proxy detection audit to surface unsanctioned tunnels that may be abusing QTRouter-class infrastructure.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →