Security1 distinct publisher3 min readPublished
The edited release now says NASA, the Federal Reserve and the Senate were among QTFY's targets. That leaves the public record with seven named agencies and no named breach for anyone to brief a board on.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The tradecraft half of the release survived the edit intact. QScan is still described as the vulnerability scanning and exploitation platform, QTRouter as the obfuscation network [8]. The affidavit still puts a 2019 attempt against NASA through CVE-2019-11510 in Pulse Secure VPN [9]. The FBI's disruption of qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com stands [11]. What moved was a single word of victimology, and that word had been carrying more weight than the filing could support.
The first version listed seven federal bodies, including DoJ itself, as "some of the victims" of computer intrusion activity orchestrated by QTFY [2][16]. The revised version lists the same seven as being among the group's targets [1]. The Hacker News reads the change as narrowing broad targeting down to a smaller set of actual compromises [10]. Tally it up and the public record now shows seven organizations QTFY aimed at, and none confirmed as entered [17]. Anyone whose slide said the Federal Reserve or the Senate was breached is now citing a paragraph the government has pulled back, and the stronger version stood for about a week before that happened [18].
The correction itself reached the press through Reuters over the weekend, according to The Hacker News [3]. DoJ's own note claims no more than that the edits bring the release into line with the allegations in the affidavit supporting the domain seizures [4]. No agency has been named as compromised in the correction.
The part that should drive detection work is the routing. Lumen Black Lotus Labs describes QTFY as having industrialized operational relay box networks, a decentralized botnet of compromised IoT devices and leased VPSs that obscures where traffic originates [12]. The affidavit alleges the operators route through IoT devices local to the victim so scanning and attack traffic blends in with legitimate users [15]. Nodes from the Chinese commercial proxy service fastlink[.]ws sit in the same architecture, under an encrypted relay network the filing calls Fast Labyrinth [14]. Geography-based triage does not survive that design. A probe from an address in your own metro is the expected shape, not the exception.
Attribution gets worse from there. QTFY sells access to QScan and QTRouter to other actors, who then enlist the devices they compromise as QTRouter nodes [13]. So an infrastructure hit identifies the toolkit rather than the customer behind it. The affidavit describes the group as a technical quartermaster supplying reconnaissance, proxy management and operational routing to Chinese espionage operations rather than running every intrusion itself [7]. Payments from the Ministry of State Security to Nanjing Xinjiuwei Network Technology Co are the stated basis for tying that company's work to Beijing [5].
QTFY has been running since 2018, against hospitals, telecom operators, power companies, financial institutions and defense contractors alongside federal networks [6]. Most people reading the release will not care which agency the Senate sits next to on a victim list. What they need to know is whether their own perimeter answered a QScan probe from a residential IP down the road.
Ranked by verification strength, evidence, and original report placement.
The U.S. Department of Justice on Friday corrected a previously issued press statement that several agencies were victims of attacks by Chinese threat actors, instead listing them as "among the targets of QTFY."
DoJ said in a note: "Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit in support of the domain seizures."
The Hacker News assesses the change in wording as significant, suggesting that while the activity may have targeted a broad range of organizations, only some of them were actually compromised.
The earlier DoJ statement said NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate were some of the victims of "computer intrusion activity" orchestrated by QTFY, a state-sponsored group affiliated with the People's Republic of China.
The update to the DoJ statement was reported by Reuters over the weekend.
According to the affidavit, QTFY (aka QT and QTCYBER) works for a private Chinese company known as Nanjing Xinjiuwei Network Technology Co, and payments from the Ministry of State Security suggest the company conducts malicious cyber activity on behalf of Beijing.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quoted paperwork, one retelling
The best material here is documentary: the department's own edit note and lines lifted from the seizure affidavit. But it all reaches us through The Hacker News, which shows up twice as the same article under two links, and Reuters — the outlet that noticed the change — is credited rather than read. Nobody in this reporting has put the question to NASA, the Federal Reserve or the Senate, which is precisely the question the edit reopened.
Domains down, effect unmeasured
Real-world action did occur: three domains seized, and Black Lotus Labs' mapping of an ORB network built from IoT devices, leased servers and commercial proxy nodes. That is more than press-release atmosphere. What is absent is the other half of the ledger — no incident counts, no agency remediation, no sign of whether QTFY's tempo dropped after the takedown, and no accounting of how many devices remain enlisted.
A noun change read for more than it says
The department claimed only that its release should match the affidavit. The reporting turns that into a statement about how many agencies were truly breached — plausible, but 'no one named as compromised' is a hole in the record, not a finding. Meanwhile the seven-name list keeps its full rhetorical weight in every headline regardless of which noun follows it, so the walk-back travels lighter than the original claim did.
Prosecutorial caution meets vendor visibility
Two interests shape what is visible. A prosecutor edits toward language defensible in an affidavit, and that direction always shrinks a claim after the news cycle has already banked the bigger version — the timing, a Friday change surfaced over a weekend, does the rest. Separately, the infrastructure detail comes from Lumen's own research arm, a business that benefits from being known as the lab that maps China-linked relay networks.
Firm on the wording, thin past it
What the release now says, and who spotted the change, we can treat as settled. Everything downstream — which networks were entered, when, what the seizures cost QTFY — rests on a single retelling of documents no one in this coverage examined, republished under a second link that adds reach but not verification.