U.S. Disrupts QScan and QTRouter Platforms Used by China-Linked Hackers

The U.S. Department of Justice (DoJ) has disrupted two hacking platforms, QScan and QTRouter, allegedly used by a China-linked threat group to target U.S. critical infrastructure and other sensitive networks.

The operation targeted QTFY, a Chinese state-sponsored hacking group associated with Nanjing Xinjiuwei Network Technology Company. According to the DoJ, victims included organizations connected to NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

The FBI said the platforms helped Chinese cyber actors conceal the origins of their attacks by routing malicious traffic through compromised devices and commercial proxy infrastructure.

QScan Used to Find and Compromise Vulnerable Devices

QScan was designed to scan internet-connected systems and identify vulnerable devices, particularly IoT equipment. Once compromised, these devices could be incorporated into the QTRouter network and used as proxy nodes.

According to the FBI, QScan was used to conduct reconnaissance against victim networks and identify vulnerable systems that could provide attackers with an initial foothold.

QTFY allegedly exploited both recently disclosed and older vulnerabilities in widely deployed enterprise products, including Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point gateways, CrushFTP, and BeyondTrust Remote Support.

QTRouter Helped Hide Attack Traffic

QTRouter acted as an obfuscation network. It combined compromised IoT devices, leased virtual private servers (VPSs), and commercial proxy infrastructure to route attacker traffic through systems located outside China.

This allowed malicious connections to appear as though they originated from locations closer to the targeted organization.

The FBI said QTRouter could also chain multiple proxy nodes together, making it more difficult for defenders and investigators to determine the original source of an intrusion.

The system used custom OpenWrt-based router software and relied on proxy technology to establish and manage these connections.

Attackers Used Compromised IoT Devices as Proxies

The infrastructure allowed QTFY-affiliated operators to use compromised devices belonging to legitimate users as network relay points.

This approach can make traditional defenses such as IP blocking and geographic filtering less effective because malicious traffic may originate from residential or commercial networks in the same region as the victim.

The broader infrastructure included several interconnected components, including QScan, QTRouter, Fast Labyrinth, and QTProxy.

Fast Labyrinth provided an operational relay layer using commercial proxy services, while QTProxy helped operators manage relay nodes and construct routes toward targeted organizations.

QTFY Activity Dates Back to 2018

According to Lumen Black Lotus Labs, researchers have tracked QTFY-related activity for more than 18 months, while the group itself has reportedly been active since May 2018.

The company described the operation as an increasingly industrialized model in which hacking infrastructure, compromised devices, commercial proxy services, and exploit capabilities are combined into shared infrastructure.

The group has reportedly targeted organizations across the Western world, including academic and research institutions.

The FBI also alleged that individuals associated with QTFY participated in China-based freelance cybercrime networks involved in acquiring and selling exploits and access to compromised networks.

The Attack Chain

According to the FBI, the activity generally followed this pattern:

  1. Reconnaissance: QScan scanned victim networks and internet-facing systems.
  2. Initial access: Attackers exploited vulnerable services and appliances.
  3. Persistence: RATs, web shells, and stolen legitimate credentials were used to maintain access.
  4. Traffic obfuscation: QTRouter routed communications through compromised IoT devices and proxy infrastructure.
  5. Further operations: Attackers could conduct reconnaissance, move through networks, and perform additional malicious activities while hiding the origin of their traffic.

U.S. Authorities Seized the Infrastructure

The DoJ said the infrastructure was disrupted through court-authorized action against the domains supporting QScan and QTRouter.

Because the seized domains were hard-coded into the platforms, the disruption caused the associated systems to stop functioning.

FBI Director Kash Patel said the platforms had been used by Chinese state-sponsored actors to conceal the origins of cyberattacks against U.S. critical infrastructure.

The operation demonstrates how state-linked cyber groups are increasingly using compromised IoT devices and legitimate commercial proxy networks as disposable infrastructure rather than relying solely on infrastructure directly controlled by the attackers.

Why This Matters

The QScan and QTRouter operation highlights a growing challenge for defenders: malicious traffic can be hidden inside infrastructure that otherwise appears legitimate.

Instead of connecting directly to a victim, attackers can route traffic through compromised routers, residential devices, VPSs, and commercial proxy services. This creates a constantly changing network of source IP addresses and makes simple IP-based blocking significantly less effective.

The case also demonstrates how vulnerability exploitation, botnet infrastructure, and commercial proxy services can be combined into a scalable cyberattack platform.

Key takeaway: Organizations should prioritize patching internet-facing systems, monitoring unusual outbound connections, securing IoT and network devices, and investigating authentication or network activity originating from unexpected residential and proxy networks.