Back to Feed
Nation-stateAug 26, 2026

FBI disrupts proxy network enabling Chinese espionage operations

FBI disrupts Chinese espionage network providing proxy services for cyber attacks.

Summary

The FBI has dismantled a sophisticated proxy network used by a Chinese threat actor, QTFY, to conduct cyber espionage operations against U.S. critical infrastructure and sensitive government networks. QTFY, linked to the China-based Nanjing Xinjiuwei Network Technology Company and former Chinese military personnel, provided reconnaissance and proxy management capabilities through platforms like 'QScan' and 'QTRouter'. The operation involved seizing domains and disrupting infrastructure that facilitated data theft from various U.S. sectors.

Full text

FBI disrupts proxy network enabling Chinese espionage operations By Bill Toulas August 26, 2026 10:17 AM 0 The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. According to the Department of Justice, a threat actor known as QTFY/QT/QTCYBER utilized two "hacking platforms known as 'QScan' and 'QTRouter,'" in attacks targeting U.S. critical infrastructure and other sensitive networks. Among QTFY's targets are NASA, the Federal Reserve, the Departments of Energy, Justice, Health and Human Services, the National Institutes of Health, and the U.S. Senate. The DoJ says that the QTFY group created and operated the QScan and QTRouter frameworks, and is employed by the China-based Nanjing Xinjiuwei Network Technology Company. Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing, and that Nanjing Xinjiuwei received payments from China's Ministry of State Security (MSS), indicating "that the company conducts malicious cyber activities on behalf of the PRC Government." The affidavit supporting the legal action states that QTFY used qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com to operate QScan, described as "a scanning and exploitation platform," and QTRouter, described as "an obfuscation network." All three domains have been seized and are now displaying a law enforcement banner. QTFY domain seized by the FBI source: BleepingComputer Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking QTFY's infrastructure for the past year and discovered the components of the framework used in attacks against U.S. critical infrastructure. According to the researchers, the provider offers a reusable service consisting of four distinct operational elements: QScan: a reconnaissance component that identifies and profiles high-value targets, collecting open ports, application banners, operating system fingerprints, and configuration data Fast Labyrinth: an encrypted relay network that conceals communications to and from victim organizations QTRouter: provides a preconfigured physical device that handles access to the proxy infrastructure and the node management system QTProxy: a management tool that lets users select relays and configure custom routes through Fast Labyrinth Overview of the quartermaster infrastructureSource: Black Lotus Labs The infrastructure was used to profile and steal data from U.S. military and defense organizations, government networks, universities and research institutions, aerospace and bioinformatics organizations, healthcare orgs, financial firms, critical infrastructure and energy companies, and enterprise software vendors. “Lumen Technologies would like to commend the FBI and DOJ for their efforts to counter Chinese cyber activity targeting U.S. critical infrastructure,” reads the report. “During our investigation, Black Lotus Labs shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact our nation’s strategic assets.” The researchers also note that they have disrupted the infrastructure by null-routing the traffic to known infrastructure points used by the quartermaster operators. Building an evasive ORB network Lumen says the “quartermaster” industrialized the creation of Operational Relay Box (ORB) networks for China-linked espionage operators. ORBs are decentralized networks of compromised infrastructure, such as SOHO routers, IoT devices, VPS servers, and commercial proxy nodes, used for relaying malicious traffic and to obscure its true source. QTFY also sold access to QScan and QTRouter for other actors to scan and exploit vulnerable IoT devices, which the hacker group could add as botnet nodes that would obfuscate the origin of the malicious traffic by routing it through devices of legitimate users. Chinese threat actors have increasingly leveraged ORBs in cyber operations since 2024 and intensified this activity earlier this year. In the case of the “quartermaster,” instead of building a conventional ORB network from thousands of compromised devices, the platform purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws. Fastlink nodesSource: Lumen These nodes formed Fast Labyrinth, an ORB-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure. The researchers highlight the overlap between QScan targets and organizations later contacted through Fast Labyrinth as the strongest piece of evidence connecting reconnaissance to follow-up operations. QScan information pipelineSource: Lumen Lumen assesses that the observed bidirectional connections from the proxy network likely represent attempted exploitation, lateral movement, persistent access, or data collection. Although disrupting this provider is significant, Lumen warns that static blocking alone is unlikely to be effective in this case because the quartermaster’s traffic passes through dynamically rotating commercial proxy services. Defenders are recommended to follow CISA and NCSC guidance for mitigating China-nexus threats and to keep routers, firewalls, and IoT devices up to date and securely configured. Update [10:17 EST]: Added information from the DoJ and court documents. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: New Dysphoria DDoS botnet spreads to 200k devices worldwideHackers infect Android car head units with proxy botnet malwareCISA: Medusa ransomware hit over 500 critical infrastructure orgsNew Evooo1Bot Linux botnet turns routers into traffic relay nodesHundreds of fake Chrome VPN extensions route traffic through a proxy

Indicators of Compromise

  • domain — qtproxy[.]xyz
  • domain — qt-proxy[.]org
  • domain — qt-team[.]com

Entities

QTFY (threat_actor)QT (threat_actor)QTCYBER (threat_actor)QScan (product)QTRouter (product)Nanjing Xinjiuwei Network Technology Company (vendor)