Security1 distinct publisher2 min readPublished
QTYF built and ran the scanning and routing frameworks other Chinese teams pointed at U.S. critical infrastructure. That means the proxy addresses and scan fingerprints in your logs point to the supplier; the intruder behind them stays unnamed.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A quartermaster model splits the labor. One party writes the tooling, runs it, and sells access; other parties pick the targets. Both halves appear in the Bureau's description of this case: reconnaissance, proxy management and operational routing sold as capabilities, plus two frameworks the same group built and operated itself [1][2]. The framework names look like a straight map onto those functions, a scanner and a routing layer, though the material does not say that outright.
The consequence lands where analysts cluster activity. When a proxy address or a scan fingerprint belongs to a service, finding it in two unrelated intrusions establishes that two operators bought from the same shop, and nothing more. Infrastructure overlap has been doing heavy lifting in attribution for years. Against a shared supplier it degrades to a vendor match. Detection content keyed to QScan behaviour will fire for every customer of the service, which is useful for coverage and worthless for naming who is on the other end.
The seller is also a company with employees, and that is a different legal object than a persona [3]. Payroll, invoices, a customer list, an address in Nanjing.
Worth being plain about the evidence. The account here is a single weekly-recap item, published twice under the same headline, with no seizure date, no count of servers or domains taken offline, no sector breakdown for the critical infrastructure targets and no charged individuals [4]. Everything beyond the framework names is the FBI's characterization as relayed by one publisher [1].
The same roundup carries a firmware finding that the source does not connect to QTYF in any way [10]. Analysts pulled apart ZBT's Deep Orange LTE router and found SPEAKINGSTONE and DARKLANTERN, both rated 9.3, both predating the ENDLESSDOORS implant already documented in at least 21 of the vendor's firmware images [5][6][7]. That makes three separate backdoors at CVSS 9.3 in one vendor's code [9]. ENDLESSDOORS starts automatically and beacons as often as every 35 seconds, so one implanted router places 86,400 / 35, or about 2,468 outbound connections in a day [6][8]. At that cadence the traffic looks like vendor telemetry, because in one direction it is: SPEAKINGSTONE phones home to ZBT's own cloud infrastructure [7].
QScan and QTRouter are code. Code outlives a hosting seizure. What the disruption buys is the time the customers need to re-provision. Anyone holding scan traffic from that service in their logs is holding a targeting record; the case behind it stays open.
Ranked by verification strength, evidence, and original report placement.
The U.S. Federal Bureau of Investigation disrupted infrastructure associated with a technical quartermaster who sold reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities.
The QTYF group is said to have created and operated the QScan and QTRouter frameworks, which have been used to target U.S. critical infrastructure networks.
QTYF is employed by the China-based Nanjing Xinjiuwei Network Technology Company.
The supplied material on the QTYF disruption consists of one weekly-recap item from thehackernews.com, appearing twice under the same headline, and it states no seizure date, no count of seized servers or domains, no sector breakdown of the critical infrastructure targets and no charged individuals.
Firmware analysis of the ZBT Deep Orange 3G/4G/LTE router uncovered two new backdoors, SPEAKINGSTONE (CVE-2026-74233, CVSS 9.3) and DARKLANTERN (CVE-2026-74232, CVSS 9.3).
At least 21 firmware images from ZBT were found to contain a backdoor called ENDLESSDOORS (CVE-2026-66747, CVSS 9.3), designed to start automatically and attempt to beacon to Chinese command-and-control infrastructure as often as every 35 seconds.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
ZBT router firmware ships two factory implants that beacon out on UDP/100001 distinct publisher
product
Two Nim implants shipped inside a US-branded router VulnCheck bought on Amazon1 distinct publisher
build
An all-zero MAC address bypasses the root command check in ZBT-derived white-label routers2 distinct publishers
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One roundup, two very different footings
The quartermaster case rests entirely on three hedged sentences in a Hacker News weekly recap — no FBI statement, no affidavit, no indictment, and 'is said to have' doing the load of an attribution. The router half is far sturdier: VulnCheck is named and quoted, three CVE identifiers are on the record, and the detail goes down to the launching binary. Averaged across what the story asserts, that is thin support for the headline and solid support for the sidebar.
Countable on the hardware side, uncounted on the espionage side
Real-world footprint exists in exactly one direction. At least 21 firmware images and three assigned CVEs give the ZBT problem a measurable perimeter, and a 35-second beacon is something a defender can look for tonight. The QScan and QTRouter side has no counted servers, no named victims, no sectors and no indicators, so its reach in U.S. critical infrastructure remains an assertion rather than an observation.
Our framing runs ahead of the paragraph it rests on
Our own headline states flatly that a Nanjing contractor sold QScan and QTRouter to espionage operators, and our summary tells defenders the proxy addresses and scan fingerprints in their logs point at the supplier. The reporting supports neither confidence level: it hedges the framework attribution, says only that the quartermaster is employed by that company, and publishes not a single address or fingerprint to match. The router findings, meanwhile, are the reverse case — an unauthenticated WAN backdoor in shipped consumer hardware is undersold as the fourth bullet of a weekly digest.
A takedown announcement and a vendor teardown, side by side
Both threads originate with parties who gain from them being read a particular way. Law enforcement publicising a disruption has every reason to present it as a blow to Chinese espionage, and disruption claims are hard to falsify from outside. VulnCheck's firmware work is genuine research that also markets vulnerability intelligence. Add the paid AI-spend placement sitting between the two, and this is a digest where interest and information travel together — not disqualifying, but worth reading with.
Confident about the routers, provisional about the contractor
We would stand behind the CVE numbers, the 9.3 ratings and the beacon interval, all of which are independently checkable. We would not yet stand behind the shape of the QTYF case: one publisher, one hedged paragraph, republished once, and every question an analyst would ask next — when, how much, against whom, charged or not — still open.