- Infrastructure Disruption: The U.S. Justice Department and FBI seized three primary domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—effectively neutralizing the QScan and QTRouter platforms.
- State-Sponsored Activity: The botnet was operated by the Chinese group QTFY, which serves clients including China’s Ministry of State Security and the People’s Liberation Army.
Dismantling the QTFY Hacking Infrastructure
The U.S. Justice Department and FBI recently neutralized a significant cyber threat by taking control of infrastructure used for international espionage. This operation occurred as the US seizes domains of Chinese botnet used by a state-sponsored group known as QTFY. The specific domains identified in court filings include qtproxy.xyz, qt-proxy.org, and qt-team.com. These web addresses served as the backbone for the group’s malicious activities, which have been active since at least 2018.
Investigations revealed that QTFY is employed by the China-based firm Nanjing Xinjiuwei Network Technology Company. The group utilized two primary tools: the QScan and QTRouter hacking platforms. QScan was engineered to scan the internet and automatically infect Internet of Things (IoT) devices, such as security cameras and home routers, to build an expansive botnet. Meanwhile, QTRouter functioned as an obfuscation network, routing malicious traffic through these compromised devices to mask the attackers’ geographic location and identity. Because these domains were hardcoded into the malware for authentication and communication, the seizure has rendered the entire botnet inoperable.
High-Profile Targets and Security Breaches
The reach of this Chinese hacker group extended into the highest levels of the American government and critical infrastructure. Confirmed victims of the QTFY intrusions include the Federal Reserve, the Department of Justice, and the National Institutes of Health. U.S. authorities also confirmed that the group successfully compromised NASA and the U.S. Senate during their operations. Other targeted entities included the Department of Health and Human Services (HHS) and the Department of Energy.
In September 2024, the group successfully breached an HHS agency and three laboratories belonging to the Department of Energy. However, not every attempt was successful; a 2019 effort to penetrate NASA’s network failed because the agency had already patched the specific VPN vulnerability the group intended to exploit. These persistent threats highlight why organizations must understand how to tell if your AI account is hacked and maintain rigorous patching schedules. Beyond U.S. borders, the group also targeted telecommunications providers, defense contractors, and hospitals worldwide.
U.S. Strategic Response and China’s Denial
FBI Director Kash Patel categorized this domain seizure as part of a larger technical surge aimed at dismantling hacking infrastructure sponsored by the People’s Republic of China. This action follows previous efforts to disrupt similar Chinese-linked botnets, such as Volt Typhoon in 2023 and Flax Typhoon in 2024. Despite the evidence linking the group to the Ministry of State Security and the People’s Liberation Army, the Chinese Embassy in Washington has denied the allegations. Chinese officials urged the U.S. to stop what they described as “smearing” and maintained that Beijing actively combats all forms of cyberattacks.
