FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI disrupts QTFY hacking platforms used by Chinese threat actors to target U.S. critical infrastructure and sensitive networks.
Intelligence analysis by Qwen 2.5 (3B)

U.S. Department of Justice announces disruption of QScan and QTRouter hacking platforms used by Chinese state-sponsored hackers to steal data from U.S. organizations.
The FBI stopped two hacking tools used by Chinese hackers to steal information from important American computer systems. They used fake addresses to hide their true location.
Analysis
{"
QTFY Activity Overview":"The QTFY hacking group has been active since May 2018, targeting organizations worldwide, especially in academia.","
QScan and QTRouter Functionality":"QScan is used to scan and infect IoT devices, while QTRouter acts as an obfuscation network to hide the true origin of attacks.","
QTRouter Architecture":"QTRouter uses OpenWrt software and the Clash proxy to obfuscate traffic and blend in with legitimate users.","
Botnet Command and Control":"The botnet is managed through Proxy Platform Management, Proxy Pool Management System, and QTBotnet, including a controller server and compromised devices.","
Impact and Mitigation":"The disruption of QScan and QTRouter has halted the operation of the hacking platforms, preventing further data theft from U.S. organizations."}
Key points
- FBI disrupts QScan and QTRouter hacking platforms used by Chinese threat actors
- QTFY group has been active since May 2018, targeting U.S. organizations
- QTRouter acts as an obfuscation network to hide the true origin of attacks
- The disruption of QScan and QTRouter has halted the operation of the hacking platforms
- The infrastructure has been likened to an operational relay box (ORB)
This disruption may reduce the risk of future cyber attacks on U.S. critical infrastructure.
Chinese hackers might develop new tools to continue their attacks, and the disruption could lead to more collateral damage.



