VMTech
Discuss a project

FBI dismantles QTFY infrastructure masking attacks on US networks

FBI dismantles QTFY infrastructure masking attacks on US networks

The U.S. Department of Justice and the FBI have disrupted QScan and QTRouter, two hacking platforms attributed to the China-linked QTFY group and used against U.S. critical infrastructure and other sensitive networks. The court-authorized action seized domains hard-coded into the products, which the FBI said caused the tools to cease operating.

The activity is linked to QTFY, a group employed by Nanjing Xinjiuwei Network Technology Company. The Justice Department identified victims including NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the U.S. Senate. Lumen Black Lotus Labs said it had tracked the operation for more than 18 months and began working with the FBI on QTFY about a year ago.

A scanning botnet and an obfuscation layer

QScan was designed to scan for and automatically infect vulnerable IoT devices around the world. Those compromised devices could then be enrolled as nodes in QTRouter, an obfuscation network that also used commercial proxy services and leased virtual private servers. This structure made malicious communications appear to originate outside China and, in some cases, closer to targeted networks.

QTRouter ran on routers using custom OpenWrt software and used Clash to establish proxy connections. The FBI said operators could view available nodes and chain them together, while blending malicious traffic with legitimate proxy traffic. That combination complicates attribution and reduces the usefulness of controls based only on IP blocklists or geographic location.

How the infrastructure supported intrusions

The FBI described an attack cycle in which QScan conducted reconnaissance, followed by exploitation of zero-day and known vulnerabilities to gain initial access. The list included flaws in Ivanti CSA appliances, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, CrushFTP, and BeyondTrust Remote Support.

After gaining access, QTFY actors allegedly established persistence through remote access trojans, web shells and legitimate credentials. They could then use QTRouter to reach victim networks through nearby compromised IoT devices, making the activity resemble traffic from ordinary local endpoints.

A broader relay network

Lumen described the environment as a distributed system that also included Fast Labyrinth and QTProxy. Fast Labyrinth incorporated commercial proxy infrastructure, including Fastlink, into an encrypted relay network alongside QTRouter. QTProxy managed operational nodes and enabled operators to use preconfigured relays or create paths to targets.

The model resembles an operational relay box: a decentralised mesh of infected IoT devices and leased VPSs that routes traffic through rotating IP addresses. The FBI said QTFY has developed tooling, traded malware and exploits through freelance hacking networks, maintained an obfuscation botnet and targeted critical U.S. systems since 2018. Attacks as recently as June 2026 targeted a U.S. election system.

Business implication

Security teams should treat proxy-originated or apparently local traffic as an investigative signal rather than proof of legitimacy. Maintaining an inventory of internet-facing systems and IoT devices, applying patches for exposed products, and monitoring for unusual proxy chains can help organisations reduce the access and concealment opportunities described in this operation.

#cybersecurity#threatintel#iotsecurity#networksecurity
Open analytics
On the site 0 views
min read 4 26.08.2026
Instagram

FBI dismantles QTFY infrastructure masking attacks on US networks

Open the post on Instagram ↗