The FBI has dismantled a Chinese state-backed hacking operation that targeted NASA, the U.S. Senate, the Energy and Justice departments and other agencies for years, seizing the infrastructure behind it in a court-authorized action announced Aug. 26.
The operation rested on two tools. QScan scanned for and infected internet-of-things devices worldwide, folding them into QTRouter, an obfuscation network that mixed hijacked gadgets with commercial proxies and rented servers. That let hackers route attacks through machines near their victims so traffic looked local. Three domains hardcoded into the malware, qtproxy.xyz, qt-proxy.org and qt-team.com, were seized, rendering both services inoperable, the Justice Department said.
Court documents tie the tools to QTFY, a group linked to the Nanjing company Nanjing Xinjiuwei, with payments from China’s Ministry of State Security and members who formerly served in the People’s Liberation Army. The infrastructure has been in use since at least 2018 and was used to breach the Senate this year.
The campaign touched space agencies directly. In August 2019 the FBI investigated an attempted intrusion at NASA that exploited CVE-2019-11510, a critical Pulse Secure VPN flaw allowing attackers to harvest credentials. QTFY later reused the bug in 2020 against an Ohio medical center during the pandemic and abused CVE-2019-19781, a Citrix flaw, against a Missouri insurer.
The FBI and NSA published an advisory with indicators of compromise, and Lumen’s Black Lotus Labs released its own analysis of the group’s tactics. Officials cast the seizure as one more step against Chinese hacking, following takedowns tied to Mustang Panda, Flax Typhoon and Volt Typhoon in past years.