FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure

FBI and DOJ Seize PRC-Linked QTFY Hacking Platform Used to Target Critical Infrastructure

The FBI and DOJ have disrupted a hacking platform linked to a Chinese state-sponsored threat actor that was used to target critical infrastructure and conduct espionage in a yearlong law enforcement campaign.

The seized domains belonged to a hacking group known as QTFY, QT, or QTCYBER that also operated other platforms, QScan and QTRouter. QTFY has targeted U.S. critical infrastructure since 2018.

Hacking platform targeted over 300 organizations worldwide

The Chinese state-sponsored APT used the seized hacking platform to target numerous government entities, including the DOJ, the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and the U.S. Senate. Other targets included telecom firms, hospitals, defense contractors, power companies, and financial institutions.

The unsealed documents show that QTFY used the hacking platform to target more than 300 organizations worldwide by exploiting software vulnerabilities in Check Point (CVE-2024-24919), Ivanti (CVE-2024-8190 and CVE-2024-8963), CrushFTP (CVE-2025-31161), and BeyondTrust (CVE-2026-1731).

The hacking group also operated QScan to scan and compromise Internet of Things (IoT) devices globally. It routed the malicious traffic through QTRouter, which leveraged legitimate commercial proxy servers and virtual private servers operated by other actors to cover its tracks and conceal its Chinese origin.

After the FBI and DOJ seized the hacking platform, QScan and QTRouter became inoperable as the malicious domains, qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, were hard-coded in the malware.

Other tools deployed by the state-sponsored hacking group include Fast Labyrinth, an encrypted communication network for communication between compromised organizations and the threat actor’s C2 servers, and QTProxy, a management tool used to configure custom routes.

Evidence of the Chinese government’s involvement

According to the DOJ, the seized hacking platform was registered by a Chinese technology firm, Nanjing Xinjuwei Network Technology Company. The company provided services to PRC-linked entities, including the People’s Liberation Army (PLA) and China’s Ministry of State Security (MSS). It also received payments from China’s Ministry of State Security, suggesting that it conducted the malicious cyber activities “on behalf of” the People’s Republic of China.

Additionally, QTFY included former PLA employees who leveraged their political connections to obtain contracts, receive payments, and support offensive operations.

“QTFY is a useful case study in how state-linked contracting networks actually operate,” said Josh Picolet, VP of Detection & Analysis, Team Cymru. “The detail worth noting is what QScan was built to do. It scanned the internet, likely in a very targeted manner, for vulnerable IoT/SOHO devices and enrolled them into QTRouter, the layer that hid the actual operations behind a mesh of compromised hardware.”

Meanwhile, the DOJ has vowed to continue targeting hacking infrastructure linked to the People’s Republic of China.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” said US Attorney General Todd Blanche in a statement. “Federal law enforcement investigated and disabled malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

U.S. authorities have previously seized Chinese-linked hacking platforms. In 2025, the FBI removed surveillance malware PlugX from over 4,000 U.S. computers. The malware was associated with a Chinese state-sponsored group, Mustang Panda. In 2024, the FBI had taken down a botnet linked to another PRC-linked group, Flax Typhoon.

In 2023, the FBI took down another botnet linked to the Chinese hacking group Volt Typhoon, which targets U.S. critical infrastructure. In March 2024, the Cybersecurity and Infrastructure Security Agency warned that Volt Typhoon had been pre-positioning itself within US critical infrastructure as early as 2019 to disrupt essential services in the event of a geopolitical conflict.