The U.S. Justice Department said the FBI executed seizure warrants on three domains — qtproxy.xyz, qt-proxy.org, and qt-team.com — that were hardcoded into two malware platforms: QScan, a vulnerability scanning and exploitation tool, and QTRouter, an obfuscation network that allowed attackers to hide the origin of their intrusions.
Together, the platforms created a botnet of compromised IoT devices, commercial proxy services, and leased virtual private servers used to attack a wide range of victims. Court documents allege the tools were operated by a Chinese government-backed group known as QTFY, which the FBI says works for a private company called Nanjing Xinjiuwei.
“Payments from the PRC’s Ministry of State Security (MSS) to Nanjing Xinjiuwei … indicate that the company conducts malicious cyber activities on behalf of the PRC Government,” the court documents state. The documents also note that QTFY actors include former members of the People’s Liberation Army.
The hacking campaigns date back to at least 2018. In 2019, QTFY attempted to compromise NASA by exploiting CVE-2019-11510, a critical vulnerability in Ivanti’s Pulse Secure VPN. The same bug was used as a zero-day against dozens of defense and financial organizations, as previously reported. During the COVID-19 pandemic in 2020, the group targeted a medical center in Ohio. Victims also include financial groups in Michigan and South Korea, and a Missouri insurance agency.
More recently, in 2024, QTFY breached three DOE National Laboratories, the National Institutes of Health, and a U.S. security device manufacturer using a zero-day attack against Ivanti Cloud Services Appliance.
The FBI’s operation made both QScan and QTRouter inoperable by seizing the command-and-control domains. The disruption follows a pattern of U.S. court-ordered seizures aimed at Chinese hacking infrastructure, including the 2025 removal of PlugX surveillance malware from thousands of devices.
China has consistently denied state-sponsored hacking allegations. As of press time, the Chinese embassy in Washington had not responded to requests for comment. The FBI declined to provide details on the total number of compromised computers or whether QTFY is linked to other known Chinese cyber groups such as those named after weather phenomena (e.g., Volt Typhoon).