Who QTFY and Nanjing Xinjiuwei are, per U.S. authorities
The Department of Justice (DoJ) announced a court-authorized disruption of two interconnected platforms—QScan and QTRouter—used by a China-linked hacking group the DoJ attributed to QTFY, operated by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). The DoJ statement names QTFY as "Chinese state-sponsored" and ties the company to customers including China's Ministry of State Security (MSS) and the People's Liberation Army (PLA), according to reporting that cites Lumen Black Lotus Labs.
Lumen identified Damon Rouse as a researcher who has tracked the activity for "over the past 18 months" and said the "digital quartermaster" has been active since May 2018. The FBI described Nanjing as an enabling company with business relationships with larger China-based cyber-enabling firms and said it employs former PLA members to win contracts related to critical infrastructure targeting.
QScan and QTRouter: the mechanics of the platforms
Two tools were central to the disruption. QScan scans and automatically infects Internet-of-Things (IoT) devices worldwide, adding them to the QTRouter network. QTRouter operates as an obfuscation or proxy network composed of compromised IoT devices, commercial proxy service devices, and leased virtual private servers (VPSs).
The FBI explained that QTRouter runs custom OpenWrt software on routers and uses Clash to establish proxy connections. QTRouter authenticates to administration servers at "www.qtproxy[.]xyz" and "securelink.qtproxy[.]xyz" and is designed to view available nodes and chain them together so actors can "mix the malicious traffic with legitimate traffic on commercial proxy services" and exploit the locations of legitimate users to evade detection.
The platforms included hard-coded domains that the court-authorized action seized; the DoJ said those hard-coded domains caused the products to cease operations after the seizure. Examples of domains associated with QScan include qt-proxy[.]org, mq-task.qt-proxy[.]org (previously mq-task.qt-team[.]com), and mq-result.qt-proxy[.]org (previously mq-result.qt-team[.]com).

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildExploits, the attack cycle, and tooling
The DoJ and FBI laid out an attack cycle that starts with QScan reconnaissance and proceeds through exploitation, persistence, and access using QTRouter. Exploits used for initial access have included both zero-day and N-day vulnerabilities. The announcement lists zero-days such as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 in Ivanti CSA appliances and a wide range of N-days spanning multiple products: CVE-2018-13379 (Fortinet SSL-VPN), CVE-2019-19781 (Citrix ADC), CVE-2021-26855 (Microsoft Exchange Server), CVE-2020-5902 (F5 BIG-IP), CVE-2019-10068 (Kentico CMS), CVE-2021-44228 (Apache Log4j), CVE-2023-22515 (Atlassian Confluence), CVE-2024-24919 (Check Point Quantum Gateway), CVE-2025-31161 (CrushFTP), and CVE-2026-1731 (BeyondTrust Remote Support).
After exploitation, QTFY actors reportedly established persistence with remote access trojans (RATs), web shells, and legitimate credentials. The botnets were managed through three major platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet, which includes controller servers, secondary-level control servers, and compromised devices. The control server can also launch distributed denial-of-service (DDoS) attacks and execute commands on infected hosts.
Targets named by the DoJ and Lumen’s characterization of operations
The DoJ listed a range of high-profile victims of QTFY intrusion activity, including the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. Lumen told reporters that targeting was "throughout the western world and beyond, especially with regard to academia" and that QTFY "just love hitting research communities given the collaborative nature of advanced science."
According to the reporting, QTFY has traded malware and exploits within China-based freelance brokering networks and sold access to victim networks; attacks as recent as June 2026 were said to have targeted a U.S. election system.
Fast Labyrinth and QTProxy: the operational relay box
Lumen described additional layers in the architecture. Fast Labyrinth provides an operational layer that incorporates commercial proxy infrastructure such as Fastlink ("fastlink.ws") into an encrypted relay network with QTRouter to obfuscate traffic. QTProxy manages Fast Labyrinth operational nodes and lets operators choose preconfigured relays or set unique paths to target entities.
The combined components form what Lumen likened to an operational relay box (ORB): a decentralized mesh of infected IoT devices and leased VPSs that routes malicious traffic through rotating IPs and frustrates traditional defenses like IP blocklists and location-based policies. Lumen summed up the shift as a move from "fragmented, ad hoc setups" toward "shared multi-tenant utility networks" that give state-sponsored actors "a high degree of anonymity and speed, and at a global scale."
What this means for technologists, policymakers, and affected agencies
- Technologists and security teams: Expect efforts to detect chained-proxy traffic to be more challenging when botnet-linked IoT devices and paid commercial proxies are mixed together; the FBI noted QTRouter's explicit design to blend malicious traffic with legitimate proxy usage.
- Policymakers and procurement leaders: The DoJ flagged Nanjing Xinjiuwei's business relationships with other China-based cyber firms and former PLA members as an enabling factor; acquisition oversight and scrutiny of third-party relationships were highlighted in the agency's description.
- Affected federal agencies and research institutions: The DoJ listed specific federal victims, and Lumen emphasized that research and academic communities remain attractive targets because of their collaborative networks and shared data.
The disruption of hard-coded domains has halted the seized tooling, but the DoJ and Lumen describe a resilient, multi-tenant relay model that mixes legitimate commercial proxy services, leased servers, and compromised consumer devices—an architecture designed to be reusable by multiple operators. Whether that model can be dismantled more broadly, or will simply reconstitute under different management, is the salient question left in the wake of this court-authorized action.




