The FBI and Department of Justice seized domains supporting the China-linked QTFY espionage group's QScan and QTRouter platforms after the infrastructure was linked to intrusions at NASA, the Federal Reserve, the Departments of Justice and Energy, and the U.S. Senate. Officials said the platforms supported follow-on attacks against sensitive networks and U.S. critical infrastructure, though they did not disclose the extent of access or data compromise at each victim.
QTFY's technical infrastructure included the QScan reconnaissance and IoT-compromise tool, QTRouter hardware, QTProxy route management, and the Fast Labyrinth encrypted relay network. The operators combined compromised IoT devices, leased VPS systems, and premium nodes from the Chinese commercial proxy service fastlink.ws to rotate malicious traffic through consumer-proxy infrastructure and conceal its origin. Defenders should prioritize edge-device hardening and apply CISA and NCSC guidance on China-linked threats, as static IP or domain blocking alone is unlikely to stop the dynamically changing relay network.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
The FBI stated that attacks attributed to the China-linked QTFY group targeted a U.S. election system as recently as June 2026.
In March 2026, QTFY scanned for vulnerabilities and unsuccessfully attempted to access the networks of the U.S. Senate and a U.S. hospital.
QTFY exploited CrushFTP vulnerability CVE-2025-31161 against a U.S. biotechnology company.
In May 2024, QTFY allegedly rapidly exploited a publicly disclosed vulnerability in Check Point security equipment. The activity reportedly stole server configuration settings and user-account information from more than 300 U.S. organizations.
Several months after its May 2024 Check Point activity, QTFY allegedly exploited a previously unknown Ivanti vulnerability. The exploitation provided access to three national laboratories, the National Institutes of Health, another HHS agency, and a U.S. security-device manufacturer.
According to Lumen, Chinese threat actors have increasingly used Operational Relay Box (ORB) networks in cyber operations since 2024 to relay and obscure malicious traffic.
The FBI investigated an attempted intrusion against NASA in August 2019 that sought to exploit CVE-2019-11510, a critical Ivanti Pulse Secure VPN vulnerability. The flaw could expose user credentials and permit unauthorized network access.
The FBI and NSA published a cybersecurity advisory containing indicators of compromise for QTFY. Their analysis associated QTFY malicious cyber activity with operations dating back to at least 2018.
The DOJ alleged that China-based Nanjing Xinjiuwei Network Technology Company operated the QScan and QTRouter platforms used by QTFY. The FBI said the company sold stolen data and hacking services to Chinese military and intelligence agencies.
The FBI and Department of Justice disrupted the China-linked infrastructure and seized domains hard-coded into QScan and QTRouter malware. The platforms used compromised IoT devices, commercial proxy nodes, and leased VPS infrastructure to conceal follow-on attacks and their origin.
After tracking the infrastructure for approximately a year, Lumen's Black Lotus Labs identified QScan, Fast Labyrinth, QTRouter, and QTProxy as components supporting reconnaissance, routing, and data theft against U.S. organizations. Lumen shared intelligence with U.S. government agencies and null-routed known infrastructure points.
U.S. officials said the Chinese state-sponsored QTFY group breached NASA, the Federal Reserve, the Department of Energy, the U.S. Senate, and the Department of Justice while targeting critical infrastructure and sensitive networks. Officials did not disclose the scope or nature of the compromises.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 444 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
25 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcecommunity.gurucul.com
Open sourcesecurityonline.info
Open sourceinfosecurity-magazine.com
Open sourcejustice.gov
Open sourcelumen.com
Open sourceic3.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.