The U.S. Department of Justice has demolished two major hacking platforms tied to China’s state-sponsored group QTFY, tools that were used to harvest data from critical infrastructure and sensitive networks across America. The operations involved platforms called QScan and QTRouter, run by Nanjing Xinjiuwei Network Technology Company. Several agencies, including NASA, the Federal Reserve, and the Department of Energy, were among the victims.
Both QScan and QTRouter serve distinct but interconnected roles in QTFY’s surveillance and espionage campaigns. Active since at least May 2018, QTFY has built a sprawling botnet and obfuscation framework designed to silence attribution and broaden access to U.S. systems. The DOJ action was announced on August 26, 2026. Key federal targets included Justice, Health and Human Services, NIH, and Congress. QTFY’s network is supported by Nanjing Xinjiuwei, which allegedly maintains ties with China’s Ministry of State Security and the People’s Liberation Army.
How QScan and QTRouter Work Together
QScan searches for vulnerable IoT devices globally, scanning for known flaws and enrolling compromised devices to become part of QTRouter. QTRouter then acts as a proxy fabric—routing malicious traffic through a mix of these hacked IoT units, commercial proxy services, and leased virtual private servers. Its purpose is to disguise the origin of attacks, hiding them from defenders and law enforcement.
Specific domains, such as qt-proxy.org, and others under the qt-proxy[.]org umbrella, were identified as critical to these operations. Components called Fast Labyrinth and QTProxy further enable the malicious infrastructure. Fast Labyrinth relays traffic using both the compromised IoT network and commercial proxy services, while QTProxy manages the relay nodes. The full setup achieves what amount to ORBs—operational relay boxes—that channel malicious activity through multiple, shifting endpoints so as to evade detection, blocklisting, and location-based defenses.
Attack Cycle & Notable Exploits
The operation workflow begins with reconnaissance via QScan, then moves through a blend of zero-day and “N-day” vulnerabilities. Some of the patched flaws exploited include CVE-2024-8190, CVE-2024-8963, CVE-2024-9380 (affecting Ivanti CSA appliances), and older vulnerabilities in Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Kentico CMS, Apache Log4j, and others. Once inside a network, QTFY actors leveraged remote access trojans, web shells, or valid credentials to maintain persistence.
Recent activity included interference with a U.S. election system as recently as June 2026. According to cybersecurity researchers who tracked QTFY for over 18 months, the group has increasingly depended on research institutions, universities, and critical infrastructure—not just traditional governmental targets—for espionage and intrusion operations.
The disruption included legal action that enabled the seizure of domains hard-coded into QScan and QTRouter, rendering them non-operational. These domains acted as control or command towers, tasked with coordinating infected IoT devices, generating scanning tasks, or delivering payloads.
Authorities describe QTFY as a “digital quartermaster,” a state actor that operates with precision and industrial efficiency. This is no longer a collection of small operators, but a complex system that sells exploit services, manages massive infrastructure, and blends malicious communications with normal network traffic to blur lines of attribution.
For organizations on the receiving end, traditional defenses—static IP blocks, geolocation filters, simple signature-based detection—are now inadequate. QTFY’s use of commercial proxy networks and compromised endpoints in legitimate user locations means defenders must rethink detection strategies.
The DOJ’s operation represents a major win, but the broader threat remains. As QTFY and similar groups continue to industrialize their operations—mixing leased infrastructure, malware, and commodity proxy services—cyber defenses must keep pace.
What this means: attribution gets harder. The blurred lines make legal and technical responses more challenging, especially when state-affiliated groups mask their tracks so effectively. Enhanced collaboration among intelligence agencies, private cybersecurity firms, and global infrastructure providers will be key to staying ahead. Watch closely for new policies around IoT device security, ransomware-style ecosystems of attack, and for defenders to double down on behavior-based network monitoring over simple signature matchups.