The FBI and the Department of Justice have seized domains linked to a yearslong effort by China-nexus hackers to target U.S. critical infrastructure providers and government agencies for espionage and other activity.
Authorities said a state-backed group known as QTFY operated hacking platforms known as QScan and QTRouter in an operation that went after various industries and government sites in the U.S.
Among the government agencies in the crosshairs were the DOJ, the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate.
In addition to the federal agencies, the QTFY hackers also targeted critical infrastructure providers in the U.S., including telecom firms, hospitals, defense contractors, power companies and financial institutions, according to court records.
PLA hacking ties
A company called the Nanjing Xinjuwei Network Technology Company employed hackers in the state-sponsored threat group, which provided services to paying customers, including the People’s Liberation Army and China’s Ministry of State Security.
QTFY used QScan to infect thousands of internet of things devices around the globe and dispatched them to the QTRouter network, which also included commercial proxy servers and virtual private servers leased by the threat actors.
The origins of the malicious hacking program were hidden for years and previously could not be directly traced back to China.
The National Security Agency and FBI said the QTFY hackers identified zero-day and N-day vulnerabilities to gain initial access to victim networks and then stole legitimate credentials to maintain persistence, according to an advisory released Wednesday.
The hackers exploited critical vulnerabilities in a number of technology products to gain access to specific targets.
- QScan was used to scan power and telecommunications firms in 2024, leveraging a Check Point Quantum Gateway vulnerability, tracked as CVE-2024-24919. Data was stolen from more than 300 organizations globally, including financial services firms, universities and defense contractors.
- Zero-day vulnerabilities in Ivanti Cloud Services Appliance, including CVE-2024-8190, CVE-2024-8963 and CVE-2024-9380, were used to target labs at the Department of Energy, HHS, the National Institutes of Health and a security device maker in the U.S.
- An authentication bypass flaw in CrushFTP, tracked as CVE-2025-31161, was exploited to target a U.S. biotechnology firm.
- A BeyondTrust flaw, tracked as CVE-2026-1731, was used in an attack on a U.S. state government. A water district was also targeted.
NSA officials said organizations should apply the latest firmware updates to their IoT and network devices, isolate critical systems from edge devices and audit webpages and internet-facing applications for suspicious activity.
Researchers at Black Lotus Labs described the China-backed operation as the “quartermaster model”: the integration of reconnaissance, proxy orchestration and operational routing to shield the true nature of the cyberattack campaign.
“From what we saw, this was a classic espionage campaign focused on reconnaissance, exploitation, and information collection,” Damon Rouse, senior information security engineer at Black Lotus Labs, told Cybersecurity Dive. “We did not observe any information influence operations or destructive components.”
The components worked together to “identify targets, route traffic and obscure operator activity,” according to a blog post by Black Lotus Labs, which is part of Lumen Technologies. Black Lotus has been tracking the group’s activity for many years and provided information to law enforcement for its takedown effort.