ProductNot yet confirmed elsewhere1 publisher3 min readPublished
DOJ names China's proxy quartermaster; the seizure took domains, not devices
Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.
The Product Desk
What happened
- The Justice Department announced the takedown of two tools, QTRouter and QScan, tied to a Chinese state-sponsored group it calls QTFY.
- Prosecutors say the contractor behind them sold relay access to customers including the Ministry of State Security and the PLA, in campaigns dating to 2018.
- The FBI affidavit describes the product as botnets of hacked IoT devices plus co-opted commercial proxy services.
- Named breach victims include NASA, the US Senate, the Federal Reserve, the Department of Energy, HHS, NIH and the DOJ.
- A Black Lotus Labs researcher who worked the case with the FBI called the scale of the operation giant.
Why it matters
- exposure Being scanned and enrolled as a relay is a separate exposure from being a target, and the device class involved is the one nobody owns internally: routers, cameras, whatever answered the QScan probe.
- constraint Hiding state traffic inside consumer VPN nodes takes away a detection shortcut defenders lean on, because the origin of a connection no longer narrows anything down.
- contradiction The DOJ is confident enough to name breached federal agencies but the affidavit will not say which power, telecom, hospital, finance or defense entities were compromised, so the sectors most cited...
- precedent A domain seizure with no individuals charged sets the template for handling the contractor market: interrupt the plumbing, leave the firm and its staff in business.
Two products were being sold here, and they are not equally hard to replace. QScan, according to Lumen and the FBI, hunted for vulnerabilities in IoT devices that could be conscripted into proxy botnets [9]. QTRouter managed customers' access to that botnet and to a stable of commercial virtual private servers that could simply be rented [10]. The botnet half runs on other people's unpatched hardware. The VPS half runs on a purchase order. Black Lotus Labs, which worked the takedown with the FBI and DOJ, describes the Nanjing firm as a quartermaster, one of several private contractors now supplying China's state hackers [11].
That distinction decides who carries the risk. The DOJ named seven federal bodies as breached, including NASA, the Senate, the Federal Reserve and the department itself [7][19]. The FBI affidavit separately lists five categories of US infrastructure and industry targeted through the proxies, and declines to say which of those entities were actually breached or how badly [8][20]. A hospital or a power company reading that filing learns it was in the target set and nothing more. It may also have been part of the relay layer, and the filing does not sort the two.
The obfuscation kept improving. Over the past year, researcher Damon Rouse of Black Lotus Labs says, the group moved to hijacking VPN services that Chinese citizens use to get around the Great Firewall, so that state traffic sat inside a large volume of ordinary user traffic [12]. Rouse says that made the state-sponsored traffic hard to pick out [12]. For anyone triaging alerts, that removes a heuristic rather than adding one: a connection from a consumer VPN node stops carrying information.
What was actually seized is the addressing. The FBI and DOJ took key domains hardcoded into QScan and QTRouter, and Lumen null-routed certain domains, including the newer VPN co-opting system [13][14]. Hardcoded domains are the cheapest part of an operation to replace and the most expensive part for a defender to notice changing. The compromised routers and cameras are untouched by a domain seizure, the rented-VPS market is untouched, and the DOJ's announcement did not appear to include charges against any individuals [15]. Attorney General Todd Blanche said state-sponsored hackers preying on critical infrastructure "will be stopped and prosecuted" [15]. Nanjing Xinjiuwei could not be immediately reached for comment [17].
Motive is the other blank. Prosecutors have not established what QTFY or its government clients wanted from the US infrastructure hacking, and Rouse says the campaigns do not appear to overlap with Volt Typhoon [16][18]. Rouse describes the campaign as long-lasting, with the people involved closely tied to the highest levels of the PLA [1]. Read together with the 2018 start date [6], the durable asset was never a tool name. It was a standing inventory of other people's devices, billed to whichever agency wanted a relay that week.
What to watch
- Whether DOJ follows the domain seizures with named indictments, sanctions, or an entity listing for Nanjing Xinjiuwei.
- Whether the co-opted VPN and rented VPS relay layer reappears under fresh domains, which would show the seizure hit addressing rather than the operation.
- Whether the power, telecom, hospital, finance and defense entities described as targeted are told individually whether they were breached.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption47
- Hype gap+24
- Incentives62
- Confidence61
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Rouse says "This is a very long-lasting campaign" and that the company and people involved have very close ties to the highest levels of the People's Liberation Army.
- [2]
Rouse says of the operation, "The scale is really giant."
- [3]
On Wednesday the Department of Justice announced the takedown of two tools, QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY.
- [4]
QTFY is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company.
- [5]
According to prosecutors and an FBI affidavit used to seize domains, the company gave its customers access to botnets of hacked internet-of-things devices and co-opted commercial proxy services.
- [6]
The company's customers, allegedly including the Ministry of State Security and the People's Liberation Army, used those proxy services as relay points for hacking campaigns stretching back as early as 2018, according to the US government.
- [7]
The DOJ says the hackers breached US victim agencies including NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself.
- [8]
The FBI affidavit lists types of US infrastructure and industries targeted via the proxy networks, including power companies, telecommunications providers, hospitals, financial institutions and defense contractors, but does not confirm which of the targeted entities were successfully breached or to what degree.
- [9]
QScan, according to Lumen and the FBI, was designed to scan for vulnerabilities in IoT devices that could be hacked and added to botnets of infected devices serving as proxies.
- [10]
The QTRouter service allegedly managed customers' access to the botnet network as well as a network of commercial proxies known as virtual private servers that could simply be rented and used in hacking campaigns.
- [11]
Lumen Technology's Black Lotus Labs, which worked with the FBI and DOJ on the takedown, describes the Nanjing-based company as a kind of quartermaster for China's hacking operations, one of several private contractors that increasingly provide tools and infrastructure to China's state-sponsored hackers.
- [12]
Damon Rouse of Black Lotus Labs says that over the past year the group transitioned to hijacking VPN services typically used by Chinese citizens to route around the Great Firewall, mixing malicious traffic with benign user traffic; "It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were co-opting."
- [13]
The FBI and Justice Department say they disrupted the group's proxy infrastructure by seizing key domains hardcoded into QScan and QTRouter.
- [14]
Lumen, an internet backbone provider, says it also null-routed certain domains, rendering them inoperable, including the more recent system of co-opting censorship-bypassing VPNs.
- [15]
US attorney general Todd Blanche said in a statement that "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," though the DOJ's announcement did not appear to include charges against any individuals.
- [16]
Rouse says the hacking campaigns do not appear to overlap with China's Volt Typhoon hacking campaign.
- [17]
Nanjing Xinjiuwei Network Technology Company could not be immediately reached for comment.
- [18]
Exactly what the QTFY hackers or the group's clients within the Chinese government sought to accomplish with the US infrastructure hacking is far from clear.
- [19]
The DOJ named seven federal victim organisations as breached.
- [20]
The FBI affidavit names five categories of US infrastructure and industry as targeted through the proxy networks.
Sources
1 independent publisher whose own reporting we read for this story.
- wired.comFBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- IoT and Embedded Device SecurityFollow
- China State-Sponsored HackingFollow
- Proxy and Botnet InfrastructureFollow
- Critical infrastructure securityFollow
- Hack-for-Hire Contractor EcosystemFollow
- Law Enforcement TakedownsFollow
Entities
- U.S. Department of JusticeFollow
- Federal Bureau of InvestigationFollow
- QTFYFollow
- Nanjing Xinjiuwei Network Technology CompanyFollow
- QTRouterFollow
- QScanFollow
- Lumen TechnologiesFollow
- Black Lotus LabsFollow
- Damon RouseFollow
- Todd BlancheFollow
- Ministry of State SecurityFollow
- People's Liberation ArmyFollow
- Volt TyphoonFollow