Cybersecurity

FBI Disrupts Proxy Network Used in China-Linked Cyberespionage Operations

The U.S. Federal Bureau of Investigation disrupted infrastructure linked to the QTFY group, which provided platforms for reconnaissance, proxy management, and operational routing against government networks and sensitive infrastructure. Court documents indicate links between the group, Nanjing Xinjiuwei Network Technology Company, and China’s Ministry of State Security.

2026-08-26
4 min read
23 views
فريق تحرير certi.news
FBI Disrupts Proxy Network Used in China-Linked Cyberespionage Operations

The U.S. Federal Bureau of Investigation disrupted infrastructure that the Department of Justice said was linked to a technology entity providing reconnaissance, proxy management, and communications-routing services for China-linked cyberespionage operations. The publicly identified targets included networks belonging to U.S. government agencies and sensitive infrastructure, including NASA, the Federal Reserve, the Departments of Energy and Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

The entity is known as QTFY, QT, or QTCYBER, and the case filing says it created and operated the QScan and QTRouter platforms. The documents described QScan as a scanning and exploitation platform, while QTRouter operated as a network for obscuring communications paths. Authorities seized the domains qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, which now display a law-enforcement banner.

A Service Platform, Not a Single Tool

According to research by Black Lotus Labs, the security research arm of Lumen Technologies, the infrastructure provided an interconnected set of services. QScan collected information about high-value targets, such as open ports, application banners, operating-system fingerprints, and configuration data. Fast Labyrinth, meanwhile, was an encrypted relay network designed to conceal communications to and from targeted organizations.

QTRouter provided a preconfigured physical device for accessing the proxy infrastructure and node-management system, while QTProxy enabled users to select relays and create customized paths through Fast Labyrinth. The findings indicate that these elements were designed to reduce the operational effort required to conduct reconnaissance and conceal the source of traffic, rather than relying on a single hacking tool.

Lumen said the infrastructure was used to target military and defense organizations, government networks, universities and research centers, aviation and critical-information companies, the healthcare sector, financial institutions, energy companies and critical infrastructure, as well as enterprise software providers.

What Does the Disruption Reveal?

Black Lotus Labs said it monitored the QTFY infrastructure for a year and shared threat intelligence with U.S. government entities. It also disrupted known nodes by routing traffic directed to them into ineffective paths. Lumen considers the overlap between the targets scanned by QScan and the organizations later contacted by the Fast Labyrinth network to be the strongest indicator that the activity moved from reconnaissance to subsequent operations.

The company estimates that the observed two-way communications may reflect exploitation attempts, lateral movement, access persistence, or data collection. Court documents state that the group included former members of a military wing of the Chinese People’s Liberation Army, and that Nanjing Xinjiuwei Network Technology Company received payments from China’s Ministry of State Security, which the Department of Justice uses as an indicator that malicious activities were carried out on behalf of the Chinese government.

Why Does This Matter to Defenders?

The operation is significant because it targets a commercial model for providing operational infrastructure, not merely a single server. Fast Labyrinth relied on paid nodes from the commercial proxy service fastlink.ws and blended espionage traffic with legitimate user traffic, while rotating the infrastructure from which communications originated. QTFY also sold access to QScan and QTRouter to other entities, allowing them to scan vulnerable Internet of Things devices and add them to relay networks that concealed the source of traffic.

Nevertheless, Lumen warns that static blocking alone will not be sufficient because traffic moves through commercial proxy services that change constantly. The practical findings recommend following CISA and NCSC guidance on China-linked threats and updating routers, firewalls, and Internet of Things devices while securing their configurations. The seizure operation alone does not prove that the threat has ended; the constraints imposed by proxy rotation and the possibility of rebuilding the infrastructure through other services remain open questions for defense teams.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news