FBI Seizes Proxy Infrastructure Powering Chinese Cyber Espionage Campaign

The FBI disrupts a proxy network operated by a threat actor known as QTFY, which provides reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations. According to the Department of Justice, the group uses two hacking platforms called QScan and QTRouter in attacks against U.S. critical infrastructure and sensitive networks. Targets include NASA, the Federal Reserve, multiple cabinet departments, the National Institutes of Health, and the U.S. Senate.

Court documents reveal that QTFY operates on behalf of Nanjing Xinjiuwei Network Technology Company, a China-based firm that receives payments from China's Ministry of State Security. The group includes former members of the Chinese People's Liberation Army, indicating the company conducts malicious cyber activities on behalf of the PRC government. The FBI seizes three domains used to operate the platforms — qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com — which now display law enforcement banners.

Black Lotus Labs, the threat research arm of Lumen Technologies, tracks QTFY's infrastructure for the past year and identifies four distinct operational elements. QScan profiles high-value targets by collecting open ports, application banners, and operating system fingerprints. Fast Labyrinth serves as an encrypted relay network concealing communications, QTRouter provides preconfigured physical devices for proxy access, and QTProxy acts as a management tool for selecting relays and configuring custom routes through the network.

Read More at the original source →