TechNewsReel
Live

FBI Seizes PRC-Backed QTFY Infrastructure Targeting US Government

Federal agents neutralized scanning and obfuscation tools used by a Chinese-funded firm to breach NASA, the US Senate, and the Federal Reserve.

TechNewsReel Newsroom · August 27, 2026

The FBI has disrupted a sophisticated botnet and seized two primary hacking platforms used by QTFY, a cyber-espionage group backed by the Chinese government. The operation neutralized the group's ability to conduct wide-scale intrusions into high-profile United States government entities.

Federal agents seized three domains—qtproxy.xyz, qt-proxy.org, and qt-team.com—rendering the group's hacking services inoperable. The disrupted infrastructure consisted of two specialized tools: QScan, used for vulnerability scanning and malware infection, and QTRouter, an obfuscation network composed of commercial proxies, virtual private servers (VPS), and compromised IoT devices. The group is operated by Nanjing Xinjiuwei, a private company in the People's Republic of China (PRC). Court documents indicate that Nanjing Xinjiuwei received payments from the PRC's Ministry of State Security (MSS), confirming the company conducted malicious cyber activities on behalf of the Chinese government.

Strategic Espionage Targets

The scale of the operation reveals a concerted effort to penetrate the highest levels of the US government. Confirmed victims include NASA, the US Senate, the Department of Energy (DOE), the Federal Reserve, the Department of Justice (DOJ), the Department of Health and Human Services (HHS), and the National Institutes of Health (NIH). To gain access, QTFY exploited several critical vulnerabilities, including CVE-2019-11510 in Ivanti Pulse Secure VPN and CVE-2019-19781 in Citrix VPN. The group also utilized a 2024 zero-day vulnerability within the Ivanti Cloud Services Appliance to bypass security perimeters.

Implications for National Security

The QTRouter obfuscation network allowed actors to mask their origin and make intrusions appear as though they originated from local sources. This sophistication underscores the PRC's strategic goal of maintaining long-term, undetected access to critical US networks. By routing traffic through a mesh of compromised devices, the attackers evaded traditional detection systems that flag anomalous foreign traffic, posing a persistent threat to the integrity of federal data and national security infrastructure.

A Persistent Cyber Struggle

This seizure is part of a broader, ongoing effort by US authorities to dismantle PRC-sponsored cyber operations. It follows similar disruptions of other state-linked groups, such as Volt Typhoon and Mustang Panda. However, security experts describe the conflict as a "whac-a-mole" struggle; while the FBI can seize specific domains and servers, Chinese actors frequently revive operations by deploying new botnets or shifting to alternative infrastructure. Future monitoring will focus on whether Nanjing Xinjiuwei or its MSS handlers attempt to rebuild the QScan and QTRouter capabilities under new aliases.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.