QTRouter is a China-linked cyber-operations platform that functions as an obfuscation and traffic-relaying network. It has been attributed by U.S. authorities to QTFY, a state-sponsored group alleged to operate through Nanjing Xinjiuwei Network Technology Company and to provide hacking services to customers including China’s Ministry of State Security and the People’s Liberation Army. The network combines compromised internet-of-things devices with commercial proxy infrastructure and leased virtual private servers to relay intrusion traffic, conceal operators’ geographic origin, and make malicious activity appear to originate from third-party or geographically local systems. QScan, a complementary QTFY tool, performs large-scale scanning and automated compromise of vulnerable IoT devices, which are then incorporated into QTRouter. QTRouter has supported activity targeting U.S. government entities, critical infrastructure, healthcare, telecommunications, financial services, power organizations, and defense contractors. U.S. law-enforcement action against infrastructure required for QTRouter communications and authentication disrupted the platform’s operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an 'obfuscation network.'
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers.”
QTRouter served as an obfuscation network that allowed malicious actors to conceal the origin of their attacks by making it appear that actions came from any of the infected devices.
QTRouter routed traffic through “hijacked routers and other internet-connected devices, commercial proxy services and rented servers.”
“QTRouter then serves as an ‘obfuscation network’ – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers... outside of the PRC.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An attacker traffic-routing and origin-obfuscation tool that relayed operations through hijacked devices, proxy services, and rented servers to conceal the China-based origin of attacks.
A traffic-relaying and concealment tool attributed to QTFY that routes operator traffic through compromised edge devices, proxy services, and rented servers to obscure its Chinese origin and blend malicious activity with legitimate user traffic.
An obfuscation and routing platform that uses compromised devices as proxies to hide attackers' true origin and falsely attribute activity to other countries or local actors.
A QTFY-operated obfuscation and proxy network composed of compromised IoT devices, commercial proxy devices, and leased VPS infrastructure; it conceals operators' locations and activities during attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.