DoJ Revises QTFY Statement on U.S. Agency Cyber Targeting

The U.S. Department of Justice has corrected a press statement about QTFY, a China-linked threat group, clarifying that NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate were among its targets, rather than confirmed victims of intrusion activity.
The amendment follows a review of allegations in an affidavit supporting domain seizures. The Justice Department said edits were made so the release accurately reflected those allegations. Reuters reported the changed wording over the weekend.
A material distinction in the government’s account
The original language described the listed agencies as victims of computer intrusion activity attributed to QTFY, a state-sponsored group affiliated with the People’s Republic of China. The updated release says they were among the targets of QTFY, preserving the allegation of broad targeting while no longer characterising every named organisation as compromised.
That distinction matters for incident response and public risk assessment. Targeting can encompass reconnaissance, attempted exploitation and other preparatory actions, whereas a confirmed compromise indicates that an intrusion succeeded. The amended wording does not remove the reported threat to sensitive and critical networks in the United States and abroad.
QScan, QTRouter and relay infrastructure
The affidavit identifies QTFY, also known as QT AND and QTCYBER, as working for Nanjing Xinjiuwei Network Technology Co. Payments from China’s Ministry of State Security suggest the private company conducts malicious cyber activity on behalf of Beijing, the filing alleges. The group is believed to have been active since 2018.
QTFY is described as a technical quartermaster supplying reconnaissance, proxy management and operational routing for Chinese cyber espionage. Its QScan platform is used for vulnerability scanning and exploitation, while QTRouter is an obfuscation network. In a 2019 case, the group allegedly attempted to access NASA by exploiting CVE-2019-11510, a critical flaw in Pulse Secure VPN.
The FBI has disrupted domains associated with QScan and QTRouter, including qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com. Lumen Black Lotus Labs said the operation industrialised Operational Relay Box networks made up of infected IoT devices and leased virtual private servers.
What defenders should take from the correction
QTFY and its customers can use compromised IoT devices as QTRouter botnet nodes, alongside infrastructure linked to the Chinese commercial proxy service fastlink[.]ws. This architecture supports Fast Labyrinth, an encrypted relay network designed to blend malicious traffic with legitimate activity.
For businesses in sectors named as targets—including healthcare, telecommunications, energy, finance and defence—the correction is a reminder not to equate attempted targeting with a confirmed breach, while still treating it as an operational security signal. Teams should prioritise remediation of exposed remote-access systems and IoT devices, and ensure monitoring can investigate traffic routed through local-looking intermediary hosts.

