Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks. A People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by a corporation called China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter. Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and US Senate. The law enforcement agencies said QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. The hacking services include QScan and QTRouter, with QScan scanning and automatically infecting thousands of internet-of-things (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. “For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against US government agencies, power companies, telcos, and major hospital systems,” FBI cyber assistant director Brett Leatherman said. “QTFY operates within a complex network of hackers-for-hire and government clients in the People’s Republic of China.” The FBI has a long track record of taking down hacking activities of the PRC. Previous actions include removing PlugX surveillance malware from over 4,000 US computers after they had been infected by the PRC-sponsored hacking group Mustang Panda. In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government. In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of US and foreign critical infrastructure. What distinguishes QTFY is the breadth of the shared service it allegedly provided, combining reconnaissance, exploitation capabilities, routing, and obfuscation infrastructure for multiple offensive teams. “It’s an effective tool to impact multiple offensive hacking teams at one time because they’re using this service,” Dakota Cary, a China-focused consultant at SentinelOne, tells CSO. “It’s kind of like a choke point, where you have a bunch of teams using the same network to carry out offensive operations,” he says. “If you take down that network, they all have to go find new infrastructure to obfuscate their activity.” The quartermaster model of hacking For a year prior to the takedown, Lumen’s Black Lotus Labs tracked QTFY as it functioned as a “quartermaster,” integrating reconnaissance, proxy orchestration, and operational routing into “a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.” “We were able to see the direct targeting of certain things,” Damon Rouse, senior lead information security engineer at Black Lotus Labs, tells CSO. “And then from that, we were able to find their scanning framework, their application called QScan. And then we were starting to really do some correlation between QScan activity and then follow-on activity from the proxy network called Fast Labyrinth.” Rouse likened Nanjing Xinjiuwei’s role to that of a defense contractor. “There’s a ton of these companies in China that are usually started directly after people leave the PLA,” he says. “Because of their connections to the PLA, they have a specialized status to do certain things for the PRC government. And it gives the government plausible deniability because it’s not actually coming from their units.” China has marketized state hacking Nanjing Xinjiuwei’s private-contractor role illustrates how Beijing draws operational capacity from a broader commercial ecosystem. “The company knows that they’re facilitating offensive operations for hackers,” SentinelOne’s Cary says. “This business exists because the hacking teams have a need for this type of infrastructure, and China has been really good at using capitalism to create a lot of its infrastructure for cyber operations.” The FBI in its investigations was able to track the flow of this marketized state hacking system. “The FBI is amazing at following the money and creating very elaborate maps of customers and payments and all kinds of good stuff,” Lumen’s Rouse says. “That’s how they were able to out a lot of these very high-end clients of this company, including PLA units, MSS units and other very, very well-connected Chinese companies that are in the infosec hacking space.” In short, China has cultivated a market of private contractors supplying specialized capabilities to state hacking teams. “They’ve been very effective at using
How China industrialized the infrastructure behind state hacking
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks. A People’s Repub
Source: CSO Online