Security1 distinct publisher2 min readPublished
DOJ seized three domains on 26 August 2026 and disabled the QScan and QTRouter platforms. Both were sold as services to MSS and PLA customers, and the only telemetry that ever saw the traffic sat on the backbone.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Buy a subscription to a commercial proxy service and your egress becomes indistinguishable from the egress of every other customer on the same ranges. That is what QTFY did with its espionage traffic, according to ZeroTrace Lab's reading of the unsealed record [8]. The consequence for defenders is mechanical. An endpoint agent watching an outbound session sees a connection to consumer address space that legitimate users also occupy. There is no malicious-hosting fingerprint to hash, and blocking the range costs you real traffic. ZeroTrace's assessment is that endpoint telemetry saw nothing and backbone telemetry saw the campaign anyway [10].
The procurement detail carries more weight than the platform names. Concealment was bought rather than built through compromise [8], and cover traffic then became a line item, resold alongside reconnaissance and access as reusable services to multiple state customers [18]. ZeroTrace describes the group as an infrastructure quartermaster rather than a conventional intrusion set [18].
Court filings in the Southern District of California name seven U.S. government victims [4][5]. Two of the seven are Health and Human Services and one of its own components, the National Institutes of Health [4], which tells you the filing counts victims by organisation rather than by intrusion.
The lever that ended it was a tradecraft failure. Three domains were compiled into both platforms [11], so a single registry action reached both products at once instead of requiring node-by-node cleanup.
On timing: Black Lotus Labs published a year of tracking on the day of the seizure [2], which puts continuous observation from roughly August 2025 [16]. Nanjing Xinjiuwei was incorporated in 2018 [6], eight years before the takedown [17]. Separate what is on the record from what is analysis. The filings establish the platforms, the paying customers and the victims [3][4]. Joint advisory JCSA-20260826-01 adds the corporate name, the incorporation date, relationships to MSS units, provincial bodies and other China-based security firms [6], and personnel described as former PLA members active in freelance exploit and access brokering [7]. The claim that endpoint programs were structurally blind is ZeroTrace Lab's judgement drawn from that record, not a Justice Department finding [9][15].
One practical caution for anyone mapping indicators: public reporting uses two overlapping vocabularies for the same system [14], so a name collision is likely before a detection gap is. ZeroTrace's closing argument is that advantage in this market is moving from database size toward sensor placement, with infrastructure operators observing threats first-hand and feeding those observations into products built on their own visibility [13]. Note who that argument favours. The parties holding the backbone sensors are the parties selling the reports.
Ranked by verification strength, evidence, and original report placement.
On 26 August 2026 the U.S. Department of Justice and the FBI announced the court-authorised seizure of three domains, qtproxy.xyz, qt-proxy.org and qt-team.com, used to run two linked hacking platforms known as QScan and QTRouter.
On the same day, the FBI, NSA and Cyber National Mission Force published joint advisory JCSA-20260826-01 on the group, and Lumen Technologies' Black Lotus Labs published a year of tracking on the same infrastructure.
Court documents unsealed in the Southern District of California describe QTFY as a People's Republic of China state-sponsored group that developed and operated QScan and QTRouter, selling access to paying customers that included China's Ministry of State Security and the People's Liberation Army.
Named victims in the court record include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.
The joint FBI/NSA/CNMF advisory attributes QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), a company established in 2018, and describes it as an enabling company inside the PRC cyber contractor ecosystem with business relationships to MSS units, provincial bodies and other China-based security firms.
QTFY personnel are described in the advisory as including former PLA members who used those relationships to win contracts and subcontracts, and as active participants in Chinese freelance brokering networks where exploits and network access are bought and sold.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
security
DoJ rewrites its QTFY seizure release to move seven agencies from victims to targets1 distinct publisher
product
DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named primary documents, one reader
Three documents carry everything: the unsealed Southern District of California filings, joint advisory JCSA-20260826-01, and Black Lotus Labs' tracking. All three are public and identified, which is more than most attribution write-ups offer. But ZeroTrace Lab is the only outlet in our coverage reading them, so the victim list, the Nanjing Xinjiuwei link and the proxy-subscription finding all arrive filtered through one set of eyes.
Actions taken, not intentions announced
The strongest material here is the part that already happened: three domains gone at the registry, two platforms dark, seven federal victim organisations on the record, a government advisory and a year of vendor tracking published the same day. Even the adversary's scale is a measured number rather than an estimate — over two million tasks in one day in 2024.
Solid takedown, unmeasured moral
The reporting on the seizure is disciplined and the architecture section resists the usual scanner-hype. The closing argument is a different animal: 'advantage is shifting toward the right sensors in the right places' comes with no market figures, no second operator, and no counterexample. Mild overreach, and it lives almost entirely in the last stretch of the piece.
The moral is also the business case
Follow who gains from the conclusion. A backbone operator's research arm supplied the tracking, and a threat-intelligence shop wrote the argument that backbone-style positioning is what wins from here. That does not make the finding wrong — the endpoint genuinely saw nothing — but the structural claim doubles as its author's pitch. On the other side, DOJ and the advisory agencies have their own reason to present three seized domains as the end of an operation rather than a bad month for a group that rotated address space monthly.
Trust the filings, hold the forecast loosely
Layer by layer: the court-record and advisory facts I would rely on. The inference that concealment was bought as a consumer subscription is plausible and mechanically consistent with the router-plus-proxy-pool design described, but untested by anyone else here. The claim about where intelligence advantage moves next is an opinion wearing a finding's clothes.