On August 26, 2026, the US Department of Justice and the FBI seized the domains of two interconnected platforms—QScan and QTRouter—which together constituted the infrastructure of the QTFY group, sponsored by the People's Republic of China. The significance of the operation does not lie in the domains themselves: their hardcoded presence in the malware meant that without them, both platforms physically could not function—the team deprived the hackers of their communication and authentication channels simultaneously, rather than simply blocking the websites.
The QTFY scheme was built on a division of labor between the two tools. QScan handled reconnaissance—automatically finding and infecting thousands of vulnerable Internet of Things (IoT) devices worldwide. The infected devices were not an end goal but served to expand the QTRouter network, which connected them to commercial proxy services and rented virtual servers. The result was a distributed obfuscation network: attacking traffic from China exited through third-party devices and externally appeared as local to the targeted network or at least as non-Chinese.
Who Stands Behind QTFY and Who the Group Targets
A joint notification from the FBI, the National Security Agency, and the Cyber National Mission Force describes QTFY as a group operating since 2018 and linked to the Chinese company Nanjing Xinjiuwei Network Technology Co. It has recorded business relationships with units of the Chinese Ministry of State Security, and its participants include former People's Liberation Army servicemen. In other words, this is not about private cybercriminals but a commercial contractor serving state clients.
According to the notification, the group's activity affected networks of NASA, the Federal Reserve, the Department of Justice, and other federal structures—ranging from scanning and intrusion attempts to attacks on critical infrastructure targets. In its statement, the Department of Justice also lists these organizations, as well as the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the US Senate, among the victims of QTFY's activity.
Independent Confirmation from Lumen Technologies
Parallel to the authorities' actions, Lumen Technologies studied the QTFY infrastructure through its Black Lotus Labs division, which referred to the operator as an "infrastructure quartermaster"—a provider of reconnaissance, proxying, and routing services for other attackers. The company identified two additional components of the scheme not directly mentioned in the Department of Justice's statement:
- Fast Labyrinth—an encrypted relay network based on commercial proxies
- QTProxy—a component for managing network nodes
Lumen independently blocked part of the related infrastructure using the null-routing method—meaning that alongside the government's domain seizure, there was another, independent channel of counteraction. Among the domains seized in the operation were qtproxy.xyz, qt-proxy.org, and qt-team.com.
The coincidence of actions by law enforcement and a private company shows that the QTFY infrastructure was sufficiently visible for independent tracking well before the official seizure. At the same time, the architecture itself—using infected IoT devices instead of the group's own servers—is designed so that it can be relatively quickly restored on new domains and nodes.
AI Opinion
From the perspective of machine data analysis, the QTFY scheme replicates a model tested in practice back in 2024: at that time, the FBI announced the dismantling of the Flax Typhoon (Raptor Train) botnet, which combined over 260,000 infected IoT devices to mask Chinese traffic as legitimate. The similarity in architecture—from cameras to storage devices—indicates not a random choice of targets but an established industry practice among operators working for Chinese state structures. The key difference of QTFY is that its infrastructure was built on a combination of two specialized platforms instead of a single botnet, complicating the complete shutdown of the network even after domain seizure.
The economics of such schemes are such that the cost of restoring a network of infected IoT devices is incomparably lower than the expenses incurred by law enforcement to detect and dismantle it. Whether the seizure of QScan and QTRouter domains remains an isolated episode or marks the beginning of a series of similar operations against "infrastructure quartermasters" is a question that will define the next year in cybersecurity.
end-content




