Illustrative image generated with AI
FBI Disrupts QScan and QTRouter, the Chinese Network That Hid Attacks on US Infrastructure
FBI disrupts Chinese hacking platforms QScan and QTRouter used to attack US critical infrastructure, including NASA and Federal Reserve.
Text generated by artificial intelligence, published without human review. AI transparency
The US Department of Justice announced on Wednesday the disruption of two hacking platforms operated by Chinese threat actors. The platforms, QScan and QTRouter, were used to target critical infrastructure and sensitive networks in the United States. The judicial action seized the domains embedded in the two products, causing their operations to cease.
Who Is Behind It: QTFY and the Nanjing Front Company
The activity is attributed to QTFY, a Chinese state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company. According to Damon Rouse, a researcher at Lumen Black Lotus Labs, QTFY has been active since May 2018. Lumen has tracked it for more than 18 months and began working with the FBI about a year ago.
The Nanjing-based company counts China’s Ministry of State Security and the People’s Liberation Army among its clients. It includes former PLA members and leverages their contacts to obtain contracts related to targeting critical infrastructure. QTFY has also taken part in Chinese freelance brokering networks to acquire and sell exploits and access to victim networks.
FBI Director Kash Patel stated that the tools were used by cyber actors from the People’s Republic of China to hide the origin of attacks. Lumen reports that targeting extended across the Western world and beyond, with particular interest in academia and research.
The Victims: NASA, Federal Reserve, Senate, and an Election System
Victims of the intrusive activity include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. Recent attacks, through June 2026, have also targeted a US election system.
The infrastructure allowed operators to hide the origin of intrusions by mixing malicious traffic with legitimate traffic from commercial proxies and compromised IoT devices. This made it difficult for defenders to identify and trace the activity.
The Technical Architecture: QScan, QTRouter, and the “Operational Relay Box”
QScan performs automated scanning and infection of IoT devices worldwide, adding them to the QTRouter network. The seized domains were hard-coded into both products. These include qt-proxy[.]org, mq-task.qt-proxy[.]org, and mq-result.qt-proxy[.]org. The first two provided scanning tasks to worker nodes hosted on leased servers outside China; the third received completed tasks.
QTRouter is a traffic obfuscation network running on routers with customized OpenWrt software. It authenticates to the management servers www.qtproxy[.]xyz and securelink.qtproxy[.]xyz and uses Clash to establish proxy connections. The network includes compromised devices, commercial proxy services, and leased virtual private servers. It allows operators to chain nodes and mix malicious traffic with legitimate traffic.
Botnets of compromised devices are controlled through three platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet. QTBotnet includes a command-and-control server, second-level control servers, and compromised devices. The control server can launch DDoS attacks and execute commands on infected nodes.
The distributed architecture also includes Fast Labyrinth, an operational layer that integrates commercial proxy infrastructure such as Fastlink (fastlink.ws) into an encrypted relay network together with QTRouter. QTProxy manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or unique paths to target entities.
Lumen compares the whole to an “operational relay box”: a decentralized mesh of infected IoT devices and leased VPS that routes malicious traffic through rotating IPs. This evades blocklists and geolocation-based policies. Because transit circuits are procured through legitimate subscriptions to commercial proxy services, traditional static blocks are no longer sufficient.
The Attack Cycle and Exploited Vulnerabilities
According to the FBI, the attack cycle proceeds in four phases. First, QScan performs reconnaissance against victim networks. Then zero-day and N-day vulnerabilities are exploited to obtain initial access. Persistence follows through remote access trojans, web shells, and legitimate credentials. Finally, QTRouter allows access to the victim network from nearby compromised IoT devices, staying under the radar.
The cited zero-day vulnerabilities are three, all in Ivanti CSA appliances:
- CVE-2024-8190 – OS command injection in Ivanti Cloud Services Appliance 4.6 Patch 518 and earlier. CVSS 7.2. Requires admin privileges for remote code execution.
- CVE-2024-8963 – path traversal in Ivanti CSA before Patch 519 of 4.6. CVSS 9.4. An unauthenticated remote attacker can access restricted functionality.
- CVE-2024-9380 – OS command injection in the Ivanti CSA admin web console before 5.0.2. CVSS 7.2. Requires admin privileges for remote code execution.
The exploited N-days include:
- CVE-2018-13379 in Fortinet SSL-VPN (FortiOS 6.0.0–6.0.4, 5.6.3–5.6.7, 5.4.6–5.4.12 and FortiProxy 2.0.0, 1.2.0–1.2.8, 1.1.0–1.1.6, 1.0.0–1.0.7). An unauthenticated attacker can download system files via HTTP requests to the SSL VPN portal.
- CVE-2019-19781 in Citrix ADC and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Directory traversal.
- CVE-2021-26855 in Microsoft Exchange Server 2013. Remote code execution.
- CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP and CVE-2026-1731 in BeyondTrust Remote Support.
For the CVEs listed beyond the first three, exact versions were not communicated by the FBI. All detailed CVEs have CVSS v3 scores ranging from 7.2 to 9.8; several are critical and allow remote code execution, path traversal, or unauthorized access.
Vulnerabilities in the KEV Catalog: Deadlines and Actions
Many of the cited CVEs are in CISA’s Known Exploited Vulnerabilities catalog. The dates added and remediation deadlines for US federal agencies are:
- CVE-2018-13379, CVE-2019-19781, and CVE-2021-26855: in the KEV since November 3, 2021, due May 3, 2022. All are known to be used in ransomware campaigns.
- CVE-2019-10068: in the KEV since March 25, 2022, due April 15, 2022.
- CVE-2020-5902: in the KEV since November 3, 2021, due May 3, 2022. Known to be used in ransomware campaigns.
- CVE-2024-8190: in the KEV since September 13, 2024, due October 4, 2024.
- CVE-2024-8963: in the KEV since September 19, 2024, due October 10, 2024.
- CVE-2024-9380: in the KEV since October 9, 2024, due October 30, 2024.
For the three Ivanti CSA vulnerabilities, CISA specifies a required action: because Ivanti CSA 4.6.x has reached End-of-Life status, users must remove CSA 4.6.x from service or move to the supported 5.0.x line. Future vulnerabilities in 4.6.x are unlikely to receive security updates.
The first three CVEs are known to be used in ransomware campaigns. Remediating them is therefore a priority even outside the federal perimeter.
What Organizations Should Do
Immediate actions depend on the exposed products. For CVEs in the KEV catalog, the general guidance is to apply vendor updates. For Ivanti CSA 4.6.x, the required mitigation is removal from service or upgrading to the 5.0.x line. Federal deadlines have already passed, but private organizations should treat them as a priority reference.
The FBI disrupted the main domains, but defenders must not lower their guard. QTFY’s distributed infrastructure can be rebuilt on new domains. Lumen emphasizes the high industrialization of Chinese cyber operations: the shift from fragmented configurations to shared multi-tenant networks enables complex campaigns with strong anonymity, speed, and global scale.
This is not an isolated case. In the last 90 days, CVE-2026-10520 has also been added to the KEV catalog, involving the same vendors present in this campaign: Ivanti, Kentico, and Citrix. The sequence indicates constant pressure on edge appliances and remote access solutions. Those who manage these products must verify versions, apply patches, and remove out-of-support systems.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-10520CRITICAL10.0An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
- CVE-2021-44228CRITICAL10.0Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message p
- CVE-2026-1731CRITICAL9.8BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the co
- CVE-2025-31161CRITICAL9.8CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible
- CVE-2023-22515CRITICAL9.8Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluenc
- CVE-2019-10068CRITICAL9.8An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserial
- CVE-2019-19781CRITICAL9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
- CVE-2020-5902CRITICAL9.8In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
- CVE-2024-8963CRITICAL9.4Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
- CVE-2018-13379CRITICAL9.1An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system
- CVE-2021-26855CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2024-24919HIGH8.6Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
- CVE-2024-9380HIGH7.2An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
- CVE-2024-8190HIGH7.2An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
