The Illusion of Local Traffic: How China Concealed Cyber Attacks on the USA

cryptonews.ruPubblicato 2026-08-27Pubblicato ultima volta 2026-08-27

Introduzione

The U.S. Department of Justice and FBI seized the domains of QScan and QTRouter on August 26, 2026, disabling the infrastructure of the Chinese state-sponsored hacking group QTFY. QScan automated the discovery and infection of vulnerable global IoT devices, which were then funneled into the QTRouter network. This network blended the compromised devices with commercial proxy services to create a distributed obfuscation system, making malicious traffic from China appear as local or non-Chinese. U.S. authorities link QTFY to Nanjing Xinjiuwei Network Technology Co., which has ties to China's Ministry of State Security. The group has targeted U.S. federal agencies, including NASA, the Federal Reserve, and the Department of Justice, as well as critical infrastructure. Private cybersecurity firm Lumen Technologies independently tracked and disrupted parts of QTFY's infrastructure, identifying additional components like Fast Labyrinth and QTProxy. The scheme mirrors the 2024 Flax Typhoon botnet takedown, highlighting an established practice among Chinese state-linked operators. However, QTFY's two-platform architecture makes it more resilient. The low cost of rebuilding such IoT-based networks compared to the high expense of dismantling them raises questions about the long-term effectiveness of domain seizure operations.

On August 26, 2026, the US Department of Justice and the FBI seized the domains of two interconnected platforms—QScan and QTRouter—which together constituted the infrastructure of the QTFY group, sponsored by the People's Republic of China. The significance of the operation does not lie in the domains themselves: their hardcoded presence in the malware meant that without them, both platforms physically could not function—the team deprived the hackers of their communication and authentication channels simultaneously, rather than simply blocking the websites.

The QTFY scheme was built on a division of labor between the two tools. QScan handled reconnaissance—automatically finding and infecting thousands of vulnerable Internet of Things (IoT) devices worldwide. The infected devices were not an end goal but served to expand the QTRouter network, which connected them to commercial proxy services and rented virtual servers. The result was a distributed obfuscation network: attacking traffic from China exited through third-party devices and externally appeared as local to the targeted network or at least as non-Chinese.

Who Stands Behind QTFY and Who the Group Targets

A joint notification from the FBI, the National Security Agency, and the Cyber National Mission Force describes QTFY as a group operating since 2018 and linked to the Chinese company Nanjing Xinjiuwei Network Technology Co. It has recorded business relationships with units of the Chinese Ministry of State Security, and its participants include former People's Liberation Army servicemen. In other words, this is not about private cybercriminals but a commercial contractor serving state clients.

According to the notification, the group's activity affected networks of NASA, the Federal Reserve, the Department of Justice, and other federal structures—ranging from scanning and intrusion attempts to attacks on critical infrastructure targets. In its statement, the Department of Justice also lists these organizations, as well as the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate, among the victims of QTFY's activity.

Independent Confirmation from Lumen Technologies

Parallel to the authorities' actions, Lumen Technologies studied the QTFY infrastructure through its Black Lotus Labs division, which referred to the operator as an "infrastructure quartermaster"—a provider of reconnaissance, proxying, and routing services for other attackers. The company identified two additional components of the scheme not directly mentioned in the Department of Justice's statement:

  • Fast Labyrinth—an encrypted relay network based on commercial proxies
  • QTProxy—a component for managing network nodes

Lumen independently blocked part of the related infrastructure using the null-routing method—meaning that alongside the government's domain seizure, there was another, independent channel of counteraction. Among the domains seized in the operation were qtproxy.xyz, qt-proxy.org, and qt-team.com.

The coincidence of actions by law enforcement and a private company shows that the QTFY infrastructure was sufficiently visible for independent tracking well before the official seizure. At the same time, the architecture itself—using infected IoT devices instead of the group's own servers—is designed so that it can be relatively quickly restored on new domains and nodes.

AI Opinion

From the perspective of machine data analysis, the QTFY scheme replicates a model tested in practice back in 2024: at that time, the FBI announced the dismantling of the Flax Typhoon (Raptor Train) botnet, which combined over 260,000 infected IoT devices to mask Chinese traffic as legitimate. The similarity in architecture—from cameras to storage devices—indicates not a random choice of targets but an established industry practice among operators working for Chinese state structures. The key difference of QTFY is that its infrastructure was built on a combination of two specialized platforms instead of a single botnet, complicating the complete shutdown of the network even after domain seizure.

The economics of such schemes are such that the cost of restoring a network of infected IoT devices is incomparably lower than the expenses incurred by law enforcement to detect and dismantle it. Whether the seizure of QScan and QTRouter domains remains an isolated episode or marks the beginning of a series of similar operations against "infrastructure quartermasters" is a question that will define the next year in cybersecurity.

end-content

Domande pertinenti

QWhat was the main purpose of the operation by the U.S. Department of Justice and FBI against the platforms QScan and QTRouter on August 26, 2026?

AThe operation seized the domains of QScan and QTRouter, which formed the core infrastructure of the QTFY group. The goal was to permanently disable these platforms by cutting off their communication and authentication channels, as the malware was hardcoded to rely on these domains. This was more than just blocking websites; it was a complete takedown of their operational capability.

QHow did the QTFY group's scheme hide the origin of their cyberattacks?

AThe scheme used a two-part infrastructure. QScan automatically found and infected vulnerable IoT devices globally. These devices were then integrated into the QTRouter network, which combined them with commercial proxy services and rented virtual servers. This created a distributed obfuscation network, making attack traffic from China appear to originate locally from the target network or at least not from China.

QWho is allegedly behind the QTFY group according to the U.S. government advisory?

AThe group is linked to the Chinese company Nanjing Xinjiuwei Network Technology Co., which reportedly has business relationships with divisions of China's Ministry of State Security. Some members are former soldiers of the People's Liberation Army. The advisory describes QTFY not as private cybercriminals, but as a commercial contractor working for state-sponsored clients.

QWhat independent action did Lumen Technologies take against the QTFY infrastructure, and what additional components did they identify?

ALumen Technologies, through its Black Lotus Labs division, independently studied and null-routed part of the QTFY infrastructure. They identified two components not directly mentioned in the DOJ statement: 'Fast Labyrinth,' an encrypted relay network based on commercial proxies, and 'QTProxy,' a component for managing network nodes.

QAccording to the article's 'AI Opinion' section, what is a key strategic and economic challenge in combating infrastructures like QTFY?

AThe key challenge is economic asymmetry. The cost for attackers to rebuild an infected IoT device network is far lower than the cost for law enforcement to discover and dismantle it. Furthermore, the architecture of using two specialized platforms (like QScan and QTRouter) instead of a single botnet makes it harder to completely disable the network even after seizing key domains, allowing for quicker recovery.

Letture associate

The Battle for Control of the Tracks Enters the Second Half: Banks vs. Crypto, Who Will Have the Last Laugh?

The competition for control over the tokenization infrastructure, or the "rails," is intensifying, moving beyond initial asset listing to dominance over settlement, custody, and regulatory layers. Recent developments signal a shift in power towards traditional finance. Key evidence includes: the formation of the BankChain Alliance by 39 U.S. state banking associations to launch a banking-owned blockchain network; moves by market infrastructure giants like DTCC, ICE, and Citadel Securities to establish their own institutional-grade on-chain systems; the struggle of crypto-native custodians like ZeroHash (re-applying for a bank charter) and Copper (facing a severe valuation drop), highlighting that regulatory "license moats" are now more critical than technical advantages; and the launch of stablecoin USD1 by licensed trust bank BitGo on the permissioned Canton network, showing convergence of stablecoin issuance towards regulated entities. The analysis concludes this is not a simple "banks vs. crypto" battle but a redefinition of the foundational infrastructure. A clear division of labor is emerging: open public chains for DeFi and innovation, while bank-led consortium chains and licensed entities capture institutional settlement, tokenized deposits, and regulated custody. The defining question is no longer *if* an asset is tokenized, but *on which rails* it runs and *who controls* those rails, with regulation and牌照 providing the ultimate backstop.

marsbit14 min fa

The Battle for Control of the Tracks Enters the Second Half: Banks vs. Crypto, Who Will Have the Last Laugh?

marsbit14 min fa

SEC Submits Proposal to White House for Revising Crypto Asset Custody Rules

The U.S. Securities and Exchange Commission (SEC) has submitted a proposal to the White House for revising rules governing the custody of crypto-assets by investment advisers and funds. Dated August 25, 2026, the proposal—known as Amendments to the Custody Rules (RIN 3235-AN46)—has entered review by the Office of Information and Regulatory Affairs (OIRA). The SEC aims to clarify the regulatory framework for crypto-asset custody and modernize certain requirements it deems outdated in light of market and technological evolution. The proposal, classified as economically significant and deregulatory under Executive Order 14192, seeks to alleviate industry burdens by removing redundant rules rather than imposing new ones. This initiative emerges amid Congressional delays in passing the comprehensive Digital Asset Market Clarity Act (CLARITY). SEC Chair Paul Atkins previously indicated the agency would proceed with its own rules if CLARITY stalled. The SEC plans to publish a Notice of Proposed Rulemaking (NPRM) in October 2026, followed by a standard public comment period. The move marks a shift from the post-2008 Madoff scandal era, which spurred stricter custody rules, toward a more flexible approach for crypto markets. However, unresolved technical questions, such as the regulatory treatment of private key custody, remain. The proposal balances industry adaptability against potential risks, as reduced oversight could delay the detection of custody issues.

cryptonews.ru26 min fa

SEC Submits Proposal to White House for Revising Crypto Asset Custody Rules

cryptonews.ru26 min fa

Trading

Spot
活动图片