FBI Disrupts China-Linked QTFY Botnet Behind Attacks on NASA, Federal Reserve, and U.S. Senate
The U.S. Department of Justice announced on Wednesday the disruption of two interconnected hacking platforms—QScan and QTRouter—operated by the Chinese state-sponsored threat group known as QTFY. The group, traced to Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), has been active since at least May 2018 and counts both China's Ministry of State Security (MSS) and the People's Liberation Army (PLA) among its customers. Among the confirmed victims of QTFY's computer intrusion campaigns are NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
QScan functions as a scanning engine that identifies and automatically exploits vulnerable IoT devices worldwide, enrolling them into the QTRouter network. QTRouter combines those compromised endpoints with commercial proxy services and leased VPS infrastructure to form a global obfuscation layer that lets QTFY and affiliated actors mask the true geographic origin of their attacks. Domains used to coordinate the platform include qt-proxy[.]org, mq-task.qt-proxy[.]org, and mq-result.qt-proxy[.]org, which distribute scanning tasks to worker nodes primarily hosted on leased servers outside China and collect the results. Lumen Black Lotus Labs, which has tracked the "digital quartermaster" for 18 months, noted that QTFY particularly favors targeting academic and research communities across the Western world given the collaborative nature of advanced science.
"Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," said FBI Director Kash Patel. "These tools were used by PRC cyber actors to hide the origin of their attacks." The takedown reflects more than a year of coordination between Lumen's research team and the FBI. Security teams at affected organizations can validate whether their perimeter devices were enrolled as proxy nodes by running a VPN/proxy detector against outbound traffic, while network defenders should use a port scanner to identify exposed IoT endpoints that may already be compromised. Individuals concerned about credential exposure stemming from these intrusions can verify their accounts with a email breach checker.