The FBI has seized three domains used by a hacking group linked to the Chinese government, disrupting a proxy network that enabled espionage against U.S. critical infrastructure and federal agencies. According to the Department of Justice, the threat actor known as QTFY, also referred to as QT and QTCYBER, operated two hacking platforms called QScan and QTRouter. Targets of these operations included NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the U.S. Senate.

The DoJ stated that QTFY created and ran the QScan and QTRouter frameworks and is employed by Nanjing Xinjiuwei Network Technology Company, a firm based in China. Court documents indicate that the threat group includes former members of the Chinese People's Liberation Army military wing. The documents also show that Nanjing Xinjiuwei received payments from China's Ministry of State Security, which the DoJ says demonstrates that the company conducts malicious cyber activities on behalf of the Chinese government.

The affidavit supporting the legal action says QTFY used the seized domains, qtproxy.xyz, qt-proxy.org, and qt-team.com, to operate QScan, described as a scanning and exploitation platform, and QTRouter, described as an obfuscation network. All three domains now display a law enforcement banner. Black Lotus Labs, the threat research arm of Lumen Technologies, has tracked QTFY's infrastructure for the past year and identified the framework's components in attacks against U.S. critical infrastructure.

Black Lotus Labs reports that the provider offers a reusable service with four distinct operational elements. The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities, research institutions, aerospace and bioinformatics organizations, healthcare firms, financial companies, critical infrastructure and energy providers, and enterprise software vendors. Lumen Technologies commended the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure, noting that Black Lotus Labs shared threat intelligence to warn U.S. government agencies of emerging risks to strategic assets.

The researchers also disrupted the infrastructure by null-routing traffic to known points used by the quartermaster operators. Lumen says this quartermaster industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators. ORBs are decentralized networks of compromised infrastructure, including SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used to relay malicious traffic and obscure its true source.

QTFY also sold access to QScan and QTRouter for other actors to scan and exploit vulnerable IoT devices, which could then be added as botnet nodes. Instead of building a conventional ORB network from thousands of compromised devices, the platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws. These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and rotated its egress infrastructure.

Lumen highlights the overlap between QScan targets and organizations later contacted through Fast Labyrinth as the strongest evidence connecting reconnaissance to follow-up operations. The researchers observed bidirectional connections from the proxy network, likely representing attempted exploitation, lateral movement, persistent access, or data collection. Lumen warns that static blocking alone is unlikely to be effective because the quartermaster's traffic passes through dynamically rotating commercial proxy services, and recommends defenders follow CISA and NCSC guidance for mitigating China-nexus threats and keep routers, firewalls, and IoT devices updated and securely configured.

More cybersecurity news from TechManNews.