Skip to content

ProductNot yet confirmed elsewhere1 publisher3 min readPublished

DOJ names China's proxy quartermaster; the seizure took domains, not devices

Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.

The Product Desk

How we use AISend a correction

Photograph accompanying DOJ names China's proxy quartermaster; the seizure took domains, not devices
Photo: fbi.gov

What happened

  • The Justice Department announced the takedown of two tools, QTRouter and QScan, tied to a Chinese state-sponsored group it calls QTFY.
  • Prosecutors say the contractor behind them sold relay access to customers including the Ministry of State Security and the PLA, in campaigns dating to 2018.
  • The FBI affidavit describes the product as botnets of hacked IoT devices plus co-opted commercial proxy services.
  • Named breach victims include NASA, the US Senate, the Federal Reserve, the Department of Energy, HHS, NIH and the DOJ.
  • A Black Lotus Labs researcher who worked the case with the FBI called the scale of the operation giant.

Why it matters

  • exposure Being scanned and enrolled as a relay is a separate exposure from being a target, and the device class involved is the one nobody owns internally: routers, cameras, whatever answered the QScan probe.
  • constraint Hiding state traffic inside consumer VPN nodes takes away a detection shortcut defenders lean on, because the origin of a connection no longer narrows anything down.
  • contradiction The DOJ is confident enough to name breached federal agencies but the affidavit will not say which power, telecom, hospital, finance or defense entities were compromised, so the sectors most cited...
  • precedent A domain seizure with no individuals charged sets the template for handling the contractor market: interrupt the plumbing, leave the firm and its staff in business.

Two products were being sold here, and they are not equally hard to replace. QScan, according to Lumen and the FBI, hunted for vulnerabilities in IoT devices that could be conscripted into proxy botnets [9]. QTRouter managed customers' access to that botnet and to a stable of commercial virtual private servers that could simply be rented [10]. The botnet half runs on other people's unpatched hardware. The VPS half runs on a purchase order. Black Lotus Labs, which worked the takedown with the FBI and DOJ, describes the Nanjing firm as a quartermaster, one of several private contractors now supplying China's state hackers [11].

That distinction decides who carries the risk. The DOJ named seven federal bodies as breached, including NASA, the Senate, the Federal Reserve and the department itself [7][19]. The FBI affidavit separately lists five categories of US infrastructure and industry targeted through the proxies, and declines to say which of those entities were actually breached or how badly [8][20]. A hospital or a power company reading that filing learns it was in the target set and nothing more. It may also have been part of the relay layer, and the filing does not sort the two.

The obfuscation kept improving. Over the past year, researcher Damon Rouse of Black Lotus Labs says, the group moved to hijacking VPN services that Chinese citizens use to get around the Great Firewall, so that state traffic sat inside a large volume of ordinary user traffic [12]. Rouse says that made the state-sponsored traffic hard to pick out [12]. For anyone triaging alerts, that removes a heuristic rather than adding one: a connection from a consumer VPN node stops carrying information.

What was actually seized is the addressing. The FBI and DOJ took key domains hardcoded into QScan and QTRouter, and Lumen null-routed certain domains, including the newer VPN co-opting system [13][14]. Hardcoded domains are the cheapest part of an operation to replace and the most expensive part for a defender to notice changing. The compromised routers and cameras are untouched by a domain seizure, the rented-VPS market is untouched, and the DOJ's announcement did not appear to include charges against any individuals [15]. Attorney General Todd Blanche said state-sponsored hackers preying on critical infrastructure "will be stopped and prosecuted" [15]. Nanjing Xinjiuwei could not be immediately reached for comment [17].

Motive is the other blank. Prosecutors have not established what QTFY or its government clients wanted from the US infrastructure hacking, and Rouse says the campaigns do not appear to overlap with Volt Typhoon [16][18]. Rouse describes the campaign as long-lasting, with the people involved closely tied to the highest levels of the PLA [1]. Read together with the 2018 start date [6], the durable asset was never a tool name. It was a standing inventory of other people's devices, billed to whichever agency wanted a relay that week.

What to watch

  • Whether DOJ follows the domain seizures with named indictments, sanctions, or an entity listing for Nanjing Xinjiuwei.
  • Whether the co-opted VPN and rented VPS relay layer reappears under fresh domains, which would show the seizure hit addressing rather than the operation.
  • Whether the power, telecom, hospital, finance and defense entities described as targeted are told individually whether they were breached.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption47
Hype gap+24
Incentives62
Confidence61
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Rouse says "This is a very long-lasting campaign" and that the company and people involved have very close ties to the highest levels of the People's Liberation Army.

  2. [2]

    Rouse says of the operation, "The scale is really giant."

  3. [3]

    On Wednesday the Department of Justice announced the takedown of two tools, QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. wired.com

    1 article · August 26, 2026

    FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories