US Seizes Domains Linked to QTFY Group
The United States successfully seized the domains of two prominent hacking platforms. The Department of Justice and the FBI allege the Chinese state-sponsored group QTFY operated these platforms. The group utilized these domains to relentlessly attack critical infrastructure and highly sensitive networks. This targeted operation specifically dismantled the QScan and QTRouter services. American authorities identified numerous high-profile targets. These included NASA, the Federal Reserve, the Department of Energy, and the Department of Justice. The hackers also targeted the Department of Health, the National Institutes of Health, and the US Senate.
The Significance of QScan and QTRouter
This operation represents far more than a routine domain seizure. A joint warning issued by the FBI, NSA, and Cyber National Mission Force detailed the severity of the threat. QScan functioned as a massive, distributed platform specifically designed for vulnerability scanning and executing web application attacks. Conversely, QTRouter meticulously concealed the true origin of malicious traffic. It routed this traffic through compromised routers, commercial proxies, and vulnerable Internet of Things devices. American agencies estimate QScan processed over 2 million tasks on a single day in 2024. These tasks included harvesting TLS certificates, hunting for subdomains, executing web scraping, and launching exploitation attempts.
Specific Attacks Orchestrated by QTFY
American intelligence services provided concrete examples of these aggressive operations. The warning authors claim QTFY operators exploited the CrushFTP CVE-2025-31161 vulnerability in April 2025. They weaponized this flaw against a prominent US biotechnology company. In February 2026, the group deployed QScan to exploit the BeyondTrust Remote Support CVE-2026-1731 vulnerability. They targeted a state government and simultaneously attacked a local water district. By March, QTFY actively scanned the networks of the US Senate and a major hospital system. In June, they aggressively probed election infrastructure for weaknesses. Fortunately, the agencies explicitly confirmed the attackers failed to gain access during these final two incidents.
The Network Behind the Attacks
American intelligence agencies firmly link QTFY to Nanjing Xinjiuwei Network Technology. This company officially registered in Nanjing in 2018. The official document asserts this structure maintained close relationships with the Chinese Ministry of State Security. They also collaborated with various Chinese contractors conducting state-sponsored cyber operations. Furthermore, the group reportedly includes former members of the People’s Liberation Army.
Black Lotus Labs researchers at Lumen provided crucial additional context regarding this threat. They continuously tracked the extensive QTFY infrastructure for approximately a year. They concluded QScan and QTRouter were not merely isolated tools. Instead, they functioned as an integral service layer facilitating broader Chinese cyber espionage. This sophisticated model empowers various operators to efficiently locate targets and optimize routing. It also thoroughly conceals their malicious activities behind a shared infrastructure. Lumen additionally reports QTFY purchased premium subscriptions to the commercial proxy service fastlink.ws. They utilized this service to meticulously blend malicious traffic with legitimate user activity.
A Persistent and Adapting Threat
This recent operation marks at least the third major US strike against Chinese covert networks. These networks typically rely heavily on compromised home and office routers. In January 2024, authorities successfully disabled the notorious KV Botnet, which the US firmly linked to Volt Typhoon. In September 2024, the FBI and DOJ dismantled Raptor Train, a massive botnet containing over 200,000 infected devices.
However, despite these successful operations, the underlying infrastructure rarely disappears completely. Lumen observed the associated ecosystem continuing to expand. Following the KV botnet’s liquidation, the associated JDY botnet actually increased its size from approximately 650 to over 1,500 active nodes. Researchers detailed this troubling expansion in a separate analysis.
The situation surrounding QScan and QTRouter demonstrates the US can temporarily disrupt specific elements of this Chinese espionage infrastructure. However, the overarching operational scheme remains incredibly resilient. According to investigative materials and technical reports, Chinese operators construct their networks utilizing reusable platforms and commercial services. They rely heavily on networks of compromised devices. Therefore, even after a significant disruption, this complex system can rebuild itself relatively quickly.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.