The FBI "torn down" the huge Chinese espionage network that had targeted NASA and the Senate!

Published Reading time: 5 minutes Cyber ​​Attacks & Data Breaches

The FBI and the US Department of Justice announced that they have taken down two hacking platforms, QScan and QTRouter, linked to the Chinese state-backed group QTFY. The infrastructure was used to attack critical infrastructure and other sensitive networks in the US.

The FBI "broke down" the huge Chinese spy network that had targeted NASA and the Senate! - Image 1

According to the Justice Department, among the organizations targeted were NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate.

The FBI "broke down" the huge Chinese spy network that had targeted NASA and the Senate! - Image 2

QTFY is reportedly operating on behalf of Nanjing Xinjiuwei Network Technology Company, a China-based company. A researcher at Lumen Black Lotus Labs said it has been monitoring the activity for 18 months and that the group has been active since at least May 2018. According to Lumen, Nanjing has clients in both the Chinese Ministry of State Security (MSS) and the People's Liberation Army (PLA).

Lumen has been working with the FBI on the case for about a year. The company said the group targeted organizations across the Western world and other regions, with a particular focus on the academic and research community.

The FBI "broke down" the huge Chinese spy network that had targeted NASA and the Senate! - Image 3

The QScan and QTRouter network

QScan is used to detect vulnerable IoT devices and automatically infect them. Compromised devices are then added to QTRouter, a proxy network that includes both infected devices and commercial proxy service infrastructure and rented VPSs.

This allows attackers to hide the true origin of the attacks. The traffic appears to originate from devices located outside of China or even close to the target organizations’ networks. Leveraging real user devices and mixing malicious traffic with legitimate traffic makes it difficult to detect.

QTRouter runs on routers with modified OpenWrt and uses Clash to create proxy connections. The system allows operators to see available nodes and connect them to each other, creating routes that hide their identity and location.

The FBI reported that the main sectors using the tools were: qt-proxy[.]org, mq-task.qt-proxy[.]org and mq-result.qt-proxy[.]orgThe specific domains were embedded in the tools' code. After the court-approved action, the platforms stopped working.

The FBI "broke down" the huge Chinese spy network that had targeted NASA and the Senate! - Image 4

How were the attacks carried out?

QTFY used the Proxy Platform Management, Proxy Pool Management System, and QTBotnet platforms to control compromised devices. QTBotnet includes a central control server, intermediary communication servers, and the infected devices. The central server could also launch DDoS attacks and execute commands on the botnet nodes.

According to US authorities, the attack began by identifying the victims' networks via QScan. The attackers exploited zero-day and previously known vulnerabilities to gain initial access. Among the vulnerabilities listed are the following:

  • CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 on Ivanti CSA devices
  • CVE-2018-13379 in Fortinet SSL-VPN
  • CVE-2019-19781 in Citrix ADC
  • CVE-2021-26855 in Microsoft Exchange Server
  • CVE-2020-5902 on F5 BIG-IP
  • CVE-2019-10068 in Kentico CMS
  • CVE-2021-44228 in Apache Log4j
  • CVE-2023-22515 in Atlassian Confluence
  • CVE-2024-24919 in Check Point Quantum Gateway
  • CVE-2025-31161 in CrushFTP
  • CVE-2026-1731 in BeyondTrust Remote Support

Once access was gained, the group would install remote access trojans (RATs) and web shells or use legitimate login credentials to maintain their presence on networks. QTRouter allowed operators to connect to targets via compromised IoT devices nearby, making their activity more difficult to detect.

Lumen describes the infrastructure as a decentralized operational relay box (ORB) network. It involved infected IoT devices, rented VPSs, and commercial proxy services. Traffic was routed through different IP addresses, limiting the effectiveness of measures such as static blocklists and geolocation-based rules.

According to Lumen, Fast Labyrinth was the operational layer of the infrastructure. It integrated commercial proxies, such as the Fastlink service, into an encrypted relay network along with QTRouter. QTProxy managed Fast Labyrinth nodes and allowed the use of ready-made relays or the creation of custom routes to targets.

Link to attacks on American systems

The FBI has described Nanjing as a company that facilitates the activities of larger Chinese companies in the cybercrime field. According to the agency, these companies have the expertise needed to breach and target critical infrastructure. The FBI also said that the company employs former PLA members, who use their contacts to secure contracts related to attacks on critical systems.

QTFY members are also said to have participated in Chinese brokering networks between freelance hackers. Through these networks, they bought and sold exploits, as well as access to victim networks. According to authorities, attacks that occurred as early as June 2026 targeted the US election system.

The FBI alleges that, since 2018, QTFY has been developing attack tools, distributing malware and exploits, maintaining botnets to hide the origin of traffic, and targeting critical systems in the United States. Lumen believes that the use of shared proxy infrastructure allows state-sponsored groups to conduct complex operations on a global scale, with greater speed and anonymity.

The company notes that because intermediate routes are purchased through legitimate subscriptions to commercial proxy services, traditional measures based solely on static IP address blocking are no longer sufficient to address such threats.

Hacks.gr on Google Set it as a preferred source for cybersecurity updates.
Preferred source

READ ALSO

Recommended readings from Hacks.gr to continue.

Participate in the discussion

Comments should remain on topic. Your email address will not be published.

0 / 2000

0 / 50

Your comments will not be published if:

  • 1. They cause "DoS" to the community with irrelevant or repetitive comments.
  • 2. They try to "phish" other users' information.
  • 3. They contain "zero-day" insults and slurs.
  • 4. Contain "malware" advertisements for products or services.
  • 5. Your comments should be sweet and friendly, not like malicious cookies trying to mislead us!