In a statement released Wednesday, the Justice Department said that the QTFY group — working on behalf of the PRC's Ministry of State Security — used two custom malware tools, QTRouter and QScan, to build and operate a botnet targeting U.S. government and critical infrastructure networks. QScan is described as malware that "scans and automatically infects thousands of IoT devices worldwide," with those devices then funneled into a proxy network obscuring the source of malicious traffic.
According to the FBI affidavit, the group has been active since at least 2018. The investigation began in 2019 after a system intrusion at NASA was traced to the now-patched CVE-2019-11510 vulnerability. Investigators linked the activity to two Gmail accounts and a Chinese (+86) phone number. The group allegedly rented infrastructure from hosting provider Hostwinds, leading to multiple abuse complaints, and registered the three seized domains — qtproxy.xyz, qt-proxy.org, and qt-team.com — through Namecheap, paying via PayPal between 2022 and 2024.
The affected agencies include the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, NASA, and the U.S. Senate. The DOJ stated that QTFY is employed by the Nanjing Xinjiuwei Network Technology Company, though little public information exists on that entity. All three domains now display a federal seizure notice.
While Beijing routinely denies involvement in hacking campaigns, a Wall Street Journal report from late last year revealed that Chinese officials had privately acknowledged responsibility for a series of attacks on U.S. infrastructure during a secret meeting. In 2024, it was reported that Chinese attackers had compromised wiretap systems deployed by the U.S. government in telecom networks — systems that had been in place for over 30 years.