The Department of Justice (DOJ) and FBI have seized domains essential to two hacking platforms operated and used by Chinese hackers to target U.S. critical infrastructure and other sensitive networks.
The DOJ said on Aug. 26 that the court-authorized seizures denied malicious cyber actors access to QScan and QTRouter, two platforms created and operated by a Chinese state-sponsored hacking group known as “QTFY.”
Because the seized domains were hard-coded into the malware for essential functions including communications and authentication, the operation made both platforms inoperable, the department said.
The DOJ identified NASA, the Federal Reserve, the Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), the U.S. Senate, and its own department as victims of QTFY computer-intrusion activity.
An FBI affidavit says QTFY infrastructure has been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and around the world, including networks operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
In 2024 alone, QScan processed more than 2 million scanning and exploit tasks. According to the FBI, QTFY successfully exploited a vulnerability in Check Point Quantum Gateway products and stole server-configuration files and user-account details from more than 300 U.S. organizations.
Automated Exploitation at Scale
The court filing describes QScan as a platform built to find vulnerable systems and exploit them.Its capabilities included scraping webpages, collecting digital security certificates, identifying subdomains, and performing penetration-testing tasks.
For penetration testing, QScan contained a database of more than 200 proof-of-concept exploits written in Python, according to the affidavit.
The platform distributed scanning and exploitation tasks through remote worker servers and collected the results through separate infrastructure.
The Check Point intrusion occurred after a vulnerability known as CVE-2024-24919 became public in May 2024.
The affidavit says QTFY successfully exploited the vulnerability several days later and obtained sensitive information from targeted systems, including server configuration files and user-account details.
The September 2024 operation targeted a different vulnerability.
Hiding Attacks Behind Other Devices
QScan worked in conjunction with QTRouter, infrastructure designed to conceal the origin of malicious cyber activity.According to the DOJ, QScan scanned for vulnerable internet-connected devices around the world and automatically infected thousands of them. Those compromised devices were then incorporated into QTRouter.
The network also used commercial proxy services and leased virtual private servers, allowing hackers operating from China to route their communications through devices elsewhere.
The DOJ said the arrangement could make an attack appear to originate outside China—and potentially from a device geographically close to the targeted network.
Private Cybersecurity and the Chinese Regime
The DOJ said QTFY was employed by Nanjing Xinjiuwei Network Technology Company, a Chinese cybersecurity company.According to the department, QTFY offered computer-hacking services to paying customers that included the Chinese regime’s Ministry of State Security and People’s Liberation Army.
The filing says payments from the Ministry of State Security to Nanjing Xinjiuwei indicate that the company conducts malicious cyber activity on behalf of the Chinese regime.
It also says QTFY includes former People’s Liberation Army members who use their relationships with the military to obtain contracts and subcontracts supporting offensive cyber operations.
Domains Seized
The FBI sought warrants for three domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—that investigators said were used to operate QScan and QTRouter.The affidavit called for the relevant domain registries to lock the domains and associate them with servers designated by the FBI.
This follows previous FBI disruptions of infrastructure used by Chinese regime-sponsored hacking groups including Mustang Panda, Flax Typhoon, and Volt Typhoon.
On Aug. 26, the FBI and National Security Agency also published cybersecurity guidance containing indicators of compromise based on their analysis of malicious QTFY activity dating back to at least 2018, according to the DOJ.
