US seizes Chinese state hacking infrastructure
FBI and DOJ dismantle QTFY's shared hacking platforms, exposing China's marketized cyber operations.
The U.S. Justice Department and FBI last week took control of domains tied to two complementary hacking platforms, QScan and QTRouter, which Chinese state-sponsored hackers used to target U.S. critical infrastructure and other sensitive networks. The action marks a rare, direct hit on the commercial scaffolding that Beijing has built to support its offensive cyber operations.
QTFY: A private contractor for state hacking
The platforms were created and operated by a People's Republic of China (PRC) state-sponsored group known as QTFY, which is employed by China-based Nanjing Xinjiuwei Network Technology Company. QTFY offers hacking services to paying customers, including the PRC's Ministry of State Security and the People's Liberation Army, according to the law enforcement agencies.
QScan automatically scans and infects thousands of internet-of-things (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. This shared infrastructure served as a choke point, according to experts, allowing multiple offensive teams to route their traffic through compromised everyday devices.
Targets span government and critical sectors
Among the targets attributed to QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. The FBI's assistant cyber director, Brett Leatherman, said that QTFY has been active for nearly a decade.
“For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against US government agencies, power companies, telcos, and major hospital systems,”
— Brett Leatherman, FBI cyber assistant director
Leatherman added that QTFY operates within a complex network of hackers-for-hire and government clients in the PRC. The FBI has a history of disrupting PRC-backed operations, including removing PlugX surveillance malware from over 4,000 U.S. computers after infections by Mustang Panda, disabling a botnet of hundreds of thousands of IoT devices used by Flax Typhoon in 2024, and disrupting a Volt Typhoon botnet in 2023.
A shared service model
What sets QTFY apart is the breadth of its shared service, which combined reconnaissance, exploitation, routing, and obfuscation for multiple offensive teams. Dakota Cary, a China-focused consultant at SentinelOne, described the service as a choke point: “It’s kind of like a choke point, where you have a bunch of teams using the same network to carry out offensive operations,” he said. “If you take down that network, they all have to go find new infrastructure to obfuscate their activity.”
For a year before the takedown, Lumen's Black Lotus Labs tracked QTFY's operations, observing how it functioned as a “quartermaster,” integrating reconnaissance, proxy orchestration, and routing into a reusable service layer. Damon Rouse, senior lead information security engineer at Black Lotus Labs, noted that the team saw direct targeting and correlated QScan activity with follow-on operations from the proxy network called Fast Labyrinth.
China’s marketized hacking ecosystem
Nanjing Xinjiuwei's role resembles that of a defense contractor, according to Rouse. “There’s a ton of these companies in China that are usually started directly after people leave the PLA,” he said. “Because of their connections to the PLA, they have a specialized status to do certain things for the PRC government. And it gives the government plausible deniability because it’s not actually coming from their units.”
The FBI's investigations tracked financial flows to expose high-end clients, including PLA and MSS units. “The FBI is amazing at following the money and creating very elaborate maps of customers and payments and all kinds of good stuff,” Rouse said. This enabled them to identify private contractors supplying specialized capabilities to state hacking teams, illustrating how Beijing uses market incentives to build operational capacity.
Efficiency creates a vulnerability
This market-like efficiency gives China scale, speed, and plausible deniability, but it also concentrates risk. Taking down a shared service forces every team relying on it to scramble for new infrastructure. However, experts caution that the operation is not a permanent solution. Rouse warned, “It would be naive to say that there’s not going to be another company or another 10 companies that are doing something very similar to this to either pick up their slack or to replace them.”
Some companies persist despite indictments. Chengdu 404, a Chinese cybersecurity firm indicted as a front for APT41, remains in business. Cary noted, “Chengdu 404 is a really good example. They got indicted, and it was very clear the DOJ and FBI were like, ‘We know who you are. We know where you work. We know where you live.’ Chengdu 404 is still in business. They still operate out of the same address. They don’t care.”
Others may shut down entirely, as i-Soon did after leaks in February of ’24. Cary said, “On the other end of the spectrum is i-Soon, where i-Soon had those leaks in February of ’24, and they completely shut down. I mean, they closed all their offices. They were done, done, done.”
Implications for defenders
The operation highlights that geography- and reputation-based IP blocking are increasingly inadequate. QTFY's infrastructure routed traffic through small office routers and IoT devices, commercial proxies, and leased virtual private servers, with dynamically rotating IP addresses. As Leatherman stated, “Instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries — potentially through systems just down the street from the victim’s own network.”
Rouse warned that malicious traffic could appear “like it’s traffic originating from the United States from, for example, Charter Communications.” Experts advise moving beyond IP-based defenses and focusing on behavioral visibility and tighter edge security. Cary emphasized, “Even if the device or the IP address doesn’t resolve to an ASN in China, that doesn’t mean it’s not malicious.”
Closing the gap
For CISOs, the actionable steps are clear: patch perimeter devices promptly, shorten patching life cycles, and maintain robust logging to establish a baseline of normal traffic. Rouse advised, “Make sure [perimeter devices are] patched; make sure your patching life cycles are shortened to as short of time as possible.” He added, “Make sure you have adequate logging around your firewalls, your perimeter, and look for traffic from residential things. If you have that kind of baseline, you have an understanding of what the traffic should look like, and you can really do a better job at looking at the anomalies.”
The takedown may disrupt QTFY's operations temporarily, but the market-driven model that produced it remains resilient. As long as China's state hacking relies on commercial contractors, new choke points will emerge—and defenders must adapt to a threat that hides behind ordinary internet traffic.
Sources
- CSO Online Original source
Continue Reading
Freelancer phishing campaign nets 80,000 infections
US indicts Russian national accused of using phishing emails to spread TVRAT and DarkVNC malware to freelancers.
Two-Decade Botnet Finally Falls
Global joint operation seizes Sality infrastructure, dismantling a botnet active since 2003.
Excel Malware Extraditee Faces Fresh Charges
Russian national Searzhudin Aktulaev faces U.S. charges over Excel malware that infected thousands via a freelance platform.