"Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures," the DoJ said in a note.
DoJ changes wording: from "victims" to "among the targets"
The U.S. Department of Justice quietly corrected a prior press statement after initially listing several U.S. institutions as victims of a China-linked hacking group. Agencies named last week — the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate — were moved in the updated release to being "among the targets of QTFY," Reuters reported.
The edit matters because it distinguishes organizations that were targeted for activity allegedly conducted by QTFY from those the government says were actually compromised. The DoJ framed the revision as an alignment of its public statement with the allegations laid out in the affidavit supporting domain seizures.
QTFY (aka QT AND QTCYBER): the accused actor and its alleged patron
The affidavit identifies the threat actor QTFY — also referred to as QT AND QTCYBER — and connects it to a private Chinese company, Nanjing Xinjiuwei Network Technology Co. It further notes that payments from the Ministry of State Security (MSS) "suggest that the company conducts malicious cyber activities on behalf of Beijing," according to the affidavit.
The group is described as a "technical quartermaster" that has been active since 2018, providing reconnaissance, proxy management, and operational routing to facilitate espionage. The affidavit says infrastructure linked to the adversary has been used to compromise critical and sensitive networks in the U.S. and abroad and that the group has singled out hospitals, telecom operators, power companies, financial institutions, and defense contractors in addition to U.S. federal government networks.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadQScan, QTRouter and an attempted Pulse Secure exploit at NASA
Two products are central to the affidavit's account: QScan, characterized as a vulnerability scanning and exploitation platform, and QTRouter, described as an obfuscation network. The court filing recounts a 2019 incident in which the actor attempted to exploit CVE-2019-11510, a critical Pulse Secure VPN vulnerability, in an effort to break into the National Aeronautics and Space Administration.
According to the affidavit, QTFY sells access to QScan and QTRouter to other actors, enabling both QTFY and its customers to identify and exploit vulnerable Internet of Things (IoT) devices and enlist them as botnet nodes in QTRouter.
Fast Labyrinth, ORB networks and the FBI disruption of domains
Technical reporting cited in the affidavit — including work by Lumen Black Lotus Labs — describes an industrialized approach to building Operational Relay Box (ORB) networks: a decentralized botnet of compromised IoT devices and leased virtual private servers that obscures the origin of malicious traffic. Nodes in the network also include machines operated by a Chinese commercial proxy service at fastlink[.]ws, the affidavit says.
The architecture underpins what the affidavit calls Fast Labyrinth, "an encrypted relay network that blends malicious traffic with legitimate network activity." The filing further alleges: "By routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets."
Operationally, the U.S. Federal Bureau of Investigation has disrupted domains connected to QScan and QTRouter — qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com — actions the DoJ says effectively neutralized the malware's functions.
What this means for NASA, the Federal Reserve, DOE, DoJ, HHS, NIH, hospitals and critical operators
- Named federal agencies (NASA, Federal Reserve, Department of Energy, Department of Justice, HHS, NIH, and the U.S. Senate): the change from "victims" to "among the targets" carries operational and reputational implications for how these agencies report intrusions and disclose remediation. The affidavit’s underlying allegations tie some activity to the same scanning and routing toolset that QTFY offered.
- Hospitals, telecom operators, power companies, financial institutions and defense contractors: these sectors were specifically singled out by the affidavit as targets of infrastructure linked to QTFY, and the filing highlights reconnaissance and proxy-routing as core capabilities used against such organizations.
- Security teams and incident responders: the affidavit and the FBI domain disruptions focus attention on IoT compromise and the specific toolset QScan/QTRouter used to enlist devices as relay nodes, and on CVE-2019-11510 as an example exploited against a U.S. agency in 2019.
The DoJ’s wording correction narrows a public claim into closer alignment with the affidavit’s allegations: it moves some institutions from an asserted status of having been "victims" to the more circumscribed designation "among the targets." At the same time, the affidavit sketches a sophisticated supply-and-service model — a private company allegedly receiving MSS payments, a commercialized toolkit sold to customers, and an ORB network that blends malicious traffic with legitimate flows — that the FBI sought to disrupt by taking down key domains. The legal and operational consequences of the affidavit’s claims will play out as courts, defenders and the named organizations parse where targeting became compromise and what follow‑on activity, if any, must be addressed.
Original reporting: https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html




