FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
The FBI and Department of Justice have disrupted a vast network of proxy tools, QTRouter and QScan, used by a Chinese state-sponsored hacking group, QTFY, to target numerous US government agencies and critical infrastructure since 2018.
Intelligence analysis by Gemini 2.5 Flash

A Chinese government contractor, Nanjing Xinjiuwei Network Technology Company, allegedly provided these tools and botnets of compromised IoT devices and commercial proxies to clients, including China's Ministry of State Security and the People's Liberation Army. The operation exposed extensive breaches into US institutions like NASA, the US Senate, and the Federal Reserve, alongside c…
Imagine there's a secret club of spies who want to peek into important places in the US, like NASA or hospitals, without being seen. They used special tools, like secret tunnels and disguises, to hide where they were really coming from. The FBI found these secret tunnels and tools, called QTRouter and QScan, and shut them down, making it much harder for the spies to sneak around. It's like catching a sneaky fox by blocking its favorite escape routes.
Analysis
The recent FBI and Department of Justice operation against the Chinese state-sponsored hacking group QTFY represents a significant, albeit temporary, setback for Beijing's cyber espionage capabilities. The takedown of QTRouter and QScan, tools allegedly developed by Nanjing Xinjiuwei Network Technology Company, reveals the intricate web of proxy infrastructure used to obfuscate malicious activities targeting a broad spectrum of American institutions. This action not only disrupts current operations but also provides valuable intelligence into the methodologies and supply chains supporting state-backed hacking.
QTFY
QTFY, identified by the DOJ as a Chinese state-sponsored hacking group, has been active since at least 2018, engaging in extensive cyber espionage against the United States. The group's operations, as observed by threat intelligence researchers, were remarkably broad, focusing on information collection rather than destructive attacks, distinguishing them from campaigns like Volt Typhoon. This suggests a strategic imperative to gather intelligence across various sectors, from government and defense to finance and healthcare, indicating a comprehensive approach to data exfiltration and strategic reconnaissance. The group's close ties to the People's Liberation Army underscore the military-intelligence nexus driving these persistent threats.
The group's reliance on sophisticated proxy networks allowed them to mask their origins, making attribution and defense significantly more challenging. By leveraging compromised IoT devices and co-opted commercial VPN services, QTFY effectively blended malicious traffic with legitimate user activity, creating a formidable layer of obfuscation. This tactic highlights a common challenge in cybersecurity: distinguishing between benign and malicious network flows, especially when adversaries exploit widely used services. The FBI's disruption, therefore, required not only identifying the tools but also dismantling the underlying infrastructure that enabled this stealth.
Nanjing Xinjiuwei Network Technology Company
Nanjing Xinjiuwei Network Technology Company is alleged to be a key contractor for the Chinese government, providing the technical infrastructure and tools necessary for QTFY's hacking campaigns. This revelation sheds light on the increasing trend of state-sponsored actors outsourcing or relying on private companies for specialized cyber capabilities. Such a model allows nation-states to maintain plausible deniability while accessing advanced tools and a broader pool of technical talent. The company acted as a 'quartermaster,' supplying botnets and proxy services to clients like the Ministry of State Security and the People's Liberation Army.
The company's role as a provider of hacking infrastructure underscores the commercialization of cyber warfare tools and services. This ecosystem complicates international efforts to curb state-sponsored hacking, as it involves targeting private entities that may operate under the guise of legitimate technology firms. The disruption of Nanjing Xinjiuwei's operations, therefore, serves as a direct blow to this supply chain, potentially causing significant operational and reputational damage within China's cyber espionage community. It also sends a clear message about the US government's intent to pursue not just the hackers but also their enablers.
QTRouter and QScan
QTRouter and QScan were the primary tools used by QTFY to manage and deploy their proxy networks. QScan was specifically designed to identify vulnerabilities in IoT devices, which were then exploited to build botnets of infected devices. These botnets served as crucial relay points, allowing the hackers to route their malicious traffic through a distributed network of compromised systems, further obscuring their true origin. The ability to continuously scan for and enlist new devices into their botnet highlights the dynamic and adaptive nature of their operations.
QTRouter, on the other hand, managed customer access to these botnets and also facilitated the use of commercial virtual private servers (VPNs) as proxies. The group's recent pivot to hijacking VPN services used by Chinese citizens to bypass the Great Firewall added another layer of complexity, making it even harder for defenders to differentiate between legitimate and malicious traffic. The FBI and Lumen Technology's Black Lotus Labs successfully disrupted this infrastructure by seizing key domains hardcoded into these tools and null-routing others, effectively rendering them inoperable. While this creates a significant hurdle for QTFY, the adaptability demonstrated by the group in the past suggests they will likely seek new methods and infrastructure to continue their operations.
Key points
- The FBI and DOJ disrupted QTRouter and QScan, proxy tools used by Chinese state-sponsored hacking group QTFY.
- QTFY, allegedly linked to Nanjing Xinjiuwei Network Technology Company, targeted numerous US government agencies and critical infrastructure since 2018.
- Victims included NASA, the US Senate, Federal Reserve, Department of Energy, and various industries like power and telecommunications.
- The tools leveraged botnets of hacked IoT devices and co-opted commercial proxy services, including VPNs used by Chinese citizens.
- The hacking campaigns primarily focused on traditional espionage and information collection, not disruptive attacks like Volt Typhoon.
- While a significant setback, experts anticipate the adaptable hackers will develop new infrastructure and methods.
The disruption of the QTFY proxy network will significantly impede Chinese state-sponsored hacking operations, forcing them to rebuild infrastructure and potentially delaying future espionage campaigns. This action demonstrates the effectiveness of collaborative efforts between government agencies and private cybersecurity firms in countering sophisticated cyber threats.
Despite this disruption, the article notes that the hackers are highly adaptable and will likely pivot to new methods and infrastructure, suggesting that this takedown is a temporary setback rather than a permanent solution. The underlying threat of state-sponsored espionage against US critical infrastructure remains persistent and will require continuous vigilance and evolving defense strategies.



