The images in this article were generated with artificial intelligence. How we publish
The U.S. Department of Justice announced the judicial interruption of an attack infrastructure made up of the platforms known as QScan and QTRouter, used by a group linked to the Chinese State identified as QTFY and allegedly operated by Nanjing Xinjiuwei Network Technology Company. According to official communication and research shared with partners in the sector, this infrastructure was used to compromise IoT devices and routing them into a proxy mesh that concealed the real origin of intrusions directed at sensitive networks of the US. United States, including federal agencies and critical sector entities.
In technical terms, the authorities' confirmation describes a modular set: QScan acts as an automatic scanner and operator of vulnerable devices on the Internet - mainly cameras, routers and other embedded equipment - and incorporates them into a botnet. QTRouter is the obfuscation layer: OpenWrt-based software that converts compromised routers (and combinations of compromised devices with VPS and commercial proxy services) into transit nodes. The platform uses the Clash tool to chain nodes and mix malicious traffic with legitimate traffic, complicating attribution by geolocation of PIs. The authorities further indicated that some key domains were encoded in the binaries and that judicial action on those domains led to the paralyzation of the affected platforms.

The FBI and cyber-security companies investigation - in particular Lumen Black Lotus Labs, who has tracked the activity since 2018 and collaborated with the FBI - attributed QTFY attacks to multiple organizations, including NASA, the Federal Reserve, the Energy and Justice Departments, HHS, NIH and the U.S. Senate. United States. These victims were listed by the Department of Justice as the objectives of the campaign. Lumen also noted that QTFY showed a sustained pattern of targeting on academic communities and research centres for its collaborative value in advanced science.
Chain of attack and exploited vulnerabilities. The authorities detailed the operating cycle: QScan makes recognition and operation of failures (both zero-day and N-day), attackers establish persistence through RATs, web shells or legitimate credentials, and then use QTRouter to pivote from IoT devices close to the victims and so "fly under the radar." The vulnerabilities mentioned in public reports include recent and old CVE covering Ivanti, Fortinet, Citrix, Microsoft Exchange, F5, Apache Log4j and others. These references are consistent with known tactics: to exploit public entry doors in applications and then to use transit infrastructure to hide malicious activity.
What is confirmed and what remains uncertain. It is confirmed by the Department of Justice that a judicial action was carried out against domains that were part of the botnet control and that, as a result, these tools ceased to operate as they had done so far. The operational attribution to QTFY and the link to Nanjing's company as facilitator according to the allegations are also confirmed. What remains uncertain at the public level are the total scope of data theft (exactly what information was exfiltered, if the exfiltration was massive or selective), the precise number of devices committed globally and the degree of direct involvement of State entities beyond the commercial and operational relations affirmed in the allegations. Several statements about participation in the networks of the brokering of exploits and contracts related to ex-PLA members come from FBI investigations and Lumen analysis; these links have been presented as part of the indictment but some operational details have not been independently verified by third parties.
A practical consequence highlighted by researchers is the "industrialization" of this type of tools: instead of ad hoc campaigns, there is a multi-tenant architecture that offers State and non-State actors a shared utility in carrying out operations quickly and anonymously. That changes the defense: static IP blockages or geographical black lists are insufficient when the malicious traffic broken through commercial proxies and legitimate devices located outside the attacker's country.

For organizations and managers, the concrete and verifiable measures to be taken are clear and urgent. First, audit the inventory of connected devices and apply patches to exposed applications and services; many of the exploited routes are parcheable failures that continue to be exploited by sophisticated actors. Second, to segment networks: separate IoT and embedded equipment from user networks and critical systems; limit remote management access to controlled and MFA bastions. Third, strengthen the detection of exfiltration and proxys: monitor unusual outbound traffic patterns, chain connections or use of commercial proxy services and analyze TLS and SNI headers to identify tunnels. Fourth, review credentials and active sessions, rotate keys and passwords, and search web shells and RATs using EDR / anti- malware and forensic analysis. These recommendations are in line with guides published by agencies and institutions that study IoT risk and cyberdefence; practical material can be found on the portals of the Department of Justice and in the technical reports of security companies such as Lumen Black Lotus Labs to implement specific controls ( https: / / www.justice.gov / opa, https: / / www.lumen.com / en-us / security / black-lotus-labs.html). It is also prudent to review good practice guides on connected devices and segmentation of networks published by agencies such as NIST and CISA.
For domestic users and SMEs, practical actions include changing default passwords in routers and cameras, disabling UPnP when not necessary, updating device firmware and, if possible, isolating cameras and domotics in a separate VLAN. For organizations with responsibility for critical infrastructure, it is essential to coordinate with security authorities and providers in order to conduct a complete forensic analysis and, if a commitment is detected, to carry out containment mitigation, including the cleaning of nodes and the revocation of committed credentials.
Finally, although judicial intervention has interrupted key components, the described architecture - an operational relay box composed of compromised devices, leased VPS and commercial proxy services - can be recreated by actors with similar resources. The lesson is that the defense must evolve towards dynamic output controls, enriched telemetry and strict segmentation, because modern ofuscation techniques reduce the effectiveness of reactive responses based only on IP blocking or black lists.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...