Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.
Perspective Coverage
7 publishers
- Builder
- Builder 32%
- Operator
- Operator 54%
- Investor
- Investor 14%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence64
QTYF built and ran the scanning and routing frameworks other Chinese teams pointed at U.S. critical infrastructure. That means the proxy addresses and scan fingerprints in your logs point to the supplier; the intruder behind them stays unnamed.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 58%
- Investor
- Investor 19%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
The DOJ and FBI pulled down two platforms a commentary attributes to Chinese state-sponsored operators. The same piece argues the routers and gateways recruited into those relays are still deployed and still weakly governed.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence55
Three seized domains and a roughly 390-item indicator list arrive with no named bank victim, so any institution running the listed products has to answer a multi-year exposure question out of whatever logs it happened to keep.
Reality
- Evidence66
- Adoption34
- Hype gap+18
- Incentives45
- Confidence62
DOJ seized three domains on 26 August 2026 and disabled the QScan and QTRouter platforms. Both were sold as services to MSS and PLA customers, and the only telemetry that ever saw the traffic sat on the backbone.
Publishers:zerotracelab.com
Reality
- Evidence74
- Adoption71
- Hype gap+12
- Incentives62
- Confidence63
The edited release now says NASA, the Federal Reserve and the Senate were among QTFY's targets. That leaves the public record with seven named agencies and no named breach for anyone to brief a board on.
Reality
- Evidence47
- Adoption38
- Hype gap+14
- Incentives61
- Confidence51
Black Lotus Labs spent a year mapping a service layer that hands reconnaissance, encrypted relays and routing to several Chinese state operators at the same time. IP-overlap attribution assumes that cannot happen.
Publishers:lumen.com
Reality
- Evidence45
- Adoption35
- Hype gap+28
- Incentives75
- Confidence45
The August 26 advisory, written with the NSA and Cyber National Mission Force, describes QTFY running its own scanning, proxying and botnet platforms since 2018. Commodity indicator feeds will not find it.
Reality
- Evidence63
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence58
A court order killed two Chinese contractor hacking platforms because their command domains were hard-coded into the malware. The pivot hardware they infected is still nobody's asset.
Reality
- Evidence68
- Adoption71
- Hype gap+14
- Incentives62
- Confidence60
Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.
Reality
- Evidence58
- Adoption47
- Hype gap+24
- Incentives62
- Confidence61
Lumen's Black Lotus Labs spent a year mapping a four-part framework sold to Chinese espionage operators. Its indicators belong to a supplier, so hunt the service rather than one group's habits.
Reality
- Evidence52
- Adoption58
- Hype gap+18
- Incentives66
- Confidence48