Search/qt-proxy.org
IOC

qt-proxy.org

Type
DOMAIN
Source
News extraction
First seen
Aug 26, 2026
Last seen
Aug 31, 2026
Look up on VirusTotal
Connections
3 relationships
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate were some of the victims of "computer intrusion activity" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China (PRC). In the newly updated statement, the aforementioned agencies have been listed as "among the targets of QTFY." The update was reported by Reuters over the weekend. "Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures," the DoJ said in a note. According to the affidavit, QTFY (aka QT AND QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, adding payments from the Ministry of State Security (MSS) suggest that the company conducts malicious cyber activities on behalf of Beijing. The threat actor is believed to have been active since 2018. Infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad. Besides targeting U.S. federal government networks, the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors. Described as a technical quartermaster, QTFY has provided reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage activities. Two of the core products in its arsenal are QScan, a vulnerability scanning and exploitation platform, and QTRouter, which is an obfuscation network. In one case dating back to 2019, the threat actor is said to have attempted to break into the National Aeronautics and Space Administration by exploiting CVE-2019-11510, a critical vulnerability impacting Pulse Secure VPN. The change in wording is significant as it suggests that while the activity may have targeted a broad range of organizations, only some of them were actually compromised. The U.S. Federal Bureau of Investigation (FBI) has since disrupted the domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com), effectively neutralizing the malware's functions. Lumen Black Lotus Labs has revealed that the threat actor has industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operations, creating a decentralized botnet of infected IoT devices and leased VPSs that enables them to obscure the true origins of the malicious activity. QTFY sells access to QScan and QTRouter for other actors to identify and exploit vulnerable IoT devices. This, in turn, allows both QTFY actors and its customers to enlist those devices as botnet nodes in QTRouter. The network also comprises nodes operated by the Chinese commercial proxy service fastlink[.]ws. The entire architecture underpins Fast Labyrinth, an encrypted relay network that blends malicious traffic with legitimate network activity. "By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets," the affidavit alleged.
thehackernews.comAug 31, 2026extracted
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). "Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate," DoJ said. Damon Rouse, a security researcher at Lumen Black Lotus Labs who has been tracking the activity for over the past 18 months, told The Hacker News that the digital quartermaster has been active since May 2018. Nanjing counts both China's Ministry of State Security (MSS) and the People's Liberation Army (PLA) among its customers. Lumen said it began collaborating with the U.S. Federal Bureau of Investigation (FBI) on QTFY about a year ago. "The targeting was throughout the western world and beyond, especially with regard to academia," the company added. "They just love hitting research communities given the collaborative nature of advanced science." "Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure," said FBI Director Kash Patel. "These tools were used by PRC cyber actors to hide the origin of their attacks." Two of the prominent tools are QScan, which scans and automatically infects IoT devices worldwide, and then adds them to the QTRouter network. QTRouter comprises both the compromised devices and commercial proxy service devices and leased virtual private servers (VPSs). QTRouter effectively serves as an obfuscation network that allows QTFY and other Chinese cyber actors to conceal the true origins of their computer intrusion activities, giving the impression that the communications are coming from endpoints that are geolocated outside China and possibly local to the targeted networks. QScan has been associated with a number of domains that host different components of the system - qt-proxy[.]org mq-task.qt-proxy[.]org (previously, mq-task.qt-team[.]com), which provides scanning tasks to a pool of worker nodes primarily housed on leased servers located outside of China mq-result.qt-proxy[.]org (previously, mq-result.qt-team[.]com), which receives completed tasks "QScan is used to exploit vulnerable IoT devices and identify vulnerabilities in victim networks. QTFY uses botnet products to control the compromised IoT devices and include them as QTRouter proxy nodes," the FBI said. "This enables QTFY-affiliated actors to blend in with legitimate users when targeting victim organizations." QTRouter, which functions as a network traffic obfuscation network running on routers with custom OpenWrt software, authenticates to administration servers located at "www.qtproxy[.]xyz" and "securelink.qtproxy[.]xyz." "QTRouter uses Clash to establish proxy connections," the FBI explained. "Its functionality includes viewing available nodes and chaining nodes together to obfuscate the actor behind the malicious activity. Additionally, by mixing the malicious traffic with legitimate traffic on commercial proxy services and using compromised IoT devices to utilize the locations of legitimate users, QTRouter makes it difficult to identify and track the malicious activity." The botnets of hacked devices are commandeered using three major platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, the last of which includes a controller server, secondary-level control servers to maintain communication between the main control server and compromised devices, and compromised devices. The control server is also equipped to launch DDoS attacks and run commands on infected nodes. The entire attack cycle is as follows - Use QScan to conduct reconnaissance against victim networks Exploit zero-day (e.g., CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances) and N-day vulnerabilities (CVE-2018-13379 in Fortinet SSL-VPN, CVE-2019-19781 in Citrix ADC, CVE-2021-26855 in Microsoft Exchange Server, CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP, and CVE-2026-1731 in BeyondTrust Remote Support) to gain initial access to victim networks Establish persistence using remote access trojans (RAT), web shells, and legitimate credentials Use QTRouter to accès the victim network from nearby compromised IoT to fly under the radar The seized domains are said to have been hard-coded into both products, causing them to cease operations following the court-authorized action. The distributed architecture is a set of interconnected components that includes QScan, QTRouter, and two others, per Lumen - Fast Labyrinth, which provides the operational layer by incorporating commercial proxy infrastructure such as Fastlink ("fastlink.ws") into an encrypted relay network along with QTRouter that obfuscates traffic to and from target entities QTProxy, which manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or configure unique paths to target entities The infrastructure has been likened to an operational relay box (ORB), a decentralized mesh that comprises infected IoT devices and leased VPSs and allows malicious traffic to be routed through rotating IPs and evade traditional defenses like IP blocklists and location-based policies. "Since its establishment in 2018, the China-linked hacking group QTFY has developed malicious tooling, traded malware and exploits within freelance hacking networks, established and maintained an obfuscation botnet, and ultimately targeted critical systems in the United States," the FBI said. The agency described Nanjing as an enabling company that has business relationships with larger private China-based cyber-enabling companies with expertise in critical infrastructure security to target victim organizations. It also encompasses former PLA members and takes advantage of their contacts to land contracts related to critical infrastructure targeting. What's more, QTFY actors are alleged to have participated in China-based freelance brokering networks to acquire and sell cyber exploit items, including access to victim networks. Attacks as recent as June 2026 have targeted a U.S. election system. "The operations of this quartermaster demonstrate the high degree of industrialization occurring within China-nexus cyber operations," Lumen said. "By shifting away from fragmented, ad hoc setups and toward shared multi-tenant utility networks, state-sponsored actors can execute complex campaigns with a high degree of anonymity and speed, and at a global scale." "Because these transit loops are procured via legitimate paid subscriptions to commercial proxy services, traditional static blocks are no longer sufficient to stop the threat."
thehackernews.comAug 26, 2026extracted
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. According to the Department of Justice, a threat actor known as QTFY/QT/QTCYBER utilized two "hacking platforms known as 'QScan' and 'QTRouter,'" in attacks targeting U.S. critical infrastructure and other sensitive networks. Among QTFY's targets are NASA, the Federal Reserve, the Departments of Energy, Justice, Health and Human Services, the National Institutes of Health, and the U.S. Senate. The DoJ says that the QTFY group created and operated the QScan and QTRouter frameworks, and is employed by the China-based Nanjing Xinjiuwei Network Technology Company. Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing, and that Nanjing Xinjiuwei received payments from China's Ministry of State Security (MSS), indicating "that the company conducts malicious cyber activities on behalf of the PRC Government." The affidavit supporting the legal action states that QTFY used qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com to operate QScan, described as "a scanning and exploitation platform," and QTRouter, described as "an obfuscation network." All three domains have been seized and are now displaying a law enforcement banner. Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking QTFY's infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure. According to the researchers, the provider offers a reusable service consisting of four distinct operational elements: QScan: a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating system fingerprints, and configuration data Fast Labyrinth: an encrypted relay network that conceals communications to and from victim organizations QTRouter: provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system QTProxy: a management tool that lets users select relays and configure custom routes through Fast Labyrinth The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors. “Lumen Technologies would like to commend the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure,” reads the report. “During our investigation, Black Lotus Labs shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact our nation’s strategic assets.” The researchers also note that they have disrupted the infrastructure by null-routing the traffic to known infrastructure points used by the quartermaster operators. Building an evasive ORB network Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators. ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used for relaying malicious traffic and to obscure its true source. QTFY also sold access to QScan and QTRouter for other actors to scan and exploit vulnerable IoT devices, which the hacker group could add as botnet nodes that would obfuscate the origin of the malicious traffic by routing it through devices of legitimate users. Chinese threat actors have increasingly leveraged ORBs in cyber operations since 2024 and intensified this activity earlier this year. In the case of the “quartermaster,” instead of building a conventional ORB network from thousands of compromised devices, the platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws. These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure. The researchers highlight the overlap between QScan targets and organizations later contacted through Fast Labyrinth as the strongest piece of evidence connecting reconnaissance to follow-up operations. Lumen assesses that the observed bidirectional connections from the proxy network likely represent attempted exploitation, lateral movement, persistent access, or data collection. Although disrupting this provider is significant, Lumen warns that static blocking alone is unlikely to be effective in this case because the quartermaster’s traffic passes through dynamically rotating commercial proxy services. Defenders are recommended to follow CISA and NCSC guidance for mitigating China-nexus threats and to keep routers, firewalls, and IoT devices up to date and securely configured. Update [10:17 EST]: Added information from the DoJ and court documents. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 26, 2026extracted