Product1 distinct publisher3 min readPublished
Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Two products were being sold here, and they are not equally hard to replace. QScan, according to Lumen and the FBI, hunted for vulnerabilities in IoT devices that could be conscripted into proxy botnets [7]. QTRouter managed customers' access to that botnet and to a stable of commercial virtual private servers that could simply be rented [8]. The botnet half runs on other people's unpatched hardware. The VPS half runs on a purchase order. Black Lotus Labs, which worked the takedown with the FBI and DOJ, describes the Nanjing firm as a quartermaster, one of several private contractors now supplying China's state hackers [9].
That distinction decides who carries the risk. The DOJ named seven federal bodies as breached, including NASA, the Senate, the Federal Reserve and the department itself [5][17]. The FBI affidavit separately lists five categories of US infrastructure and industry targeted through the proxies, and declines to say which of those entities were actually breached or how badly [6][18]. A hospital or a power company reading that filing learns it was in the target set and nothing more. It may also have been part of the relay layer, and the filing does not sort the two.
The obfuscation kept improving. Over the past year, researcher Damon Rouse of Black Lotus Labs says, the group moved to hijacking VPN services that Chinese citizens use to get around the Great Firewall, so that state traffic sat inside a large volume of ordinary user traffic [11]. Rouse says that made the state-sponsored traffic hard to pick out [11]. For anyone triaging alerts, that removes a heuristic rather than adding one: a connection from a consumer VPN node stops carrying information.
What was actually seized is the addressing. The FBI and DOJ took key domains hardcoded into QScan and QTRouter, and Lumen null-routed certain domains, including the newer VPN co-opting system [12][13]. Hardcoded domains are the cheapest part of an operation to replace and the most expensive part for a defender to notice changing. The compromised routers and cameras are untouched by a domain seizure, the rented-VPS market is untouched, and the DOJ's announcement did not appear to include charges against any individuals [14]. Attorney General Todd Blanche said state-sponsored hackers preying on critical infrastructure "will be stopped and prosecuted" [14]. Nanjing Xinjiuwei could not be immediately reached for comment [16].
Motive is the other blank. Prosecutors have not established what QTFY or its government clients wanted from the US infrastructure hacking, and Rouse says the campaigns do not appear to overlap with Volt Typhoon [15][19]. Rouse describes the campaign as long-lasting, with the people involved closely tied to the highest levels of the PLA [20]. Read together with the 2018 start date [4], the durable asset was never a tool name. It was a standing inventory of other people's devices, billed to whichever agency wanted a relay that week.
Ranked by verification strength, evidence, and original report placement.
Rouse says "This is a very long-lasting campaign" and that the company and people involved have very close ties to the highest levels of the People's Liberation Army.
Rouse says of the operation, "The scale is really giant."
On Wednesday the Department of Justice announced the takedown of two tools, QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY.
QTFY is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company.
According to prosecutors and an FBI affidavit used to seize domains, the company gave its customers access to botnets of hacked internet-of-things devices and co-opted commercial proxy services.
The company's customers, allegedly including the Ministry of State Security and the People's Liberation Army, used those proxy services as relay points for hacking campaigns stretching back as early as 2018, according to the US government.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary filings, single outlet, unconfirmed extent
The account rests on identifiable primary material — a DOJ announcement, an FBI seizure affidavit and a participating vendor's blog post — which is stronger than anonymous sourcing. But the cluster has exactly one publisher, the accused contractor gave no response, the affidavit explicitly does not confirm which targeted entities were compromised or to what degree, and scale claims are researcher characterisations rather than quantified metrics.
Real disruption executed, remediation absent
Concrete operational actions did occur and are documented: domains hardcoded into both tools were seized, and Lumen null-routed additional domains including the newer hijacked-VPN system. Adoption of the remedy is nonetheless partial — the intervention removed control domains rather than cleaning conscripted IoT devices or VPS proxies, no victim-side remediation or IOC distribution is described, and the participating researcher expects the group to stand up new infrastructure.
Enforcement rhetoric outruns the delivered remedy
The attorney general's promise that such hackers 'will be stopped and prosecuted' sits against an announcement with no individual charges, an affidavit that does not confirm which targets were breached, and the takedown partner's own expectation that the group will pivot and rebuild. The underlying facts are solid, so the overstatement is in framing and finality rather than in fabrication — modestly positive rather than severe.
Enforcement announcement plus vendor co-author
Two interested parties shape the record and both are visible in the text: the DOJ and attorney general are announcing their own enforcement win, and Lumen's Black Lotus Labs is simultaneously a takedown participant, the source of the 'quartermaster' framing, the supplier of the sole named expert voice, and a commercial threat-intelligence and backbone vendor. The reporting discloses these roles rather than hiding them, and includes the countervailing note that the group will likely return.
Solid on actions, thin on effect
Confidence is reasonably high for what was announced and done — the tools, the alleged contractor relationship, the seizures and the null-routing are documented and internally consistent. It is materially lower for consequences: breach depth, device counts, remaining exposure and adversary intent are all either unconfirmed in the affidavit or explicitly described as unclear, and there is no second publisher to test the account.
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
product
After Arup, a face on a video call is not a credential1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026