FBI interrompe QScan e QTRouter, la rete cinese che nascondeva gli attacchi alle infrastrutture Usa
APT

Illustrative image generated with AI

FBI Disrupts QScan and QTRouter, the Chinese Network That Hid Attacks on US Infrastructure

FBI disrupts Chinese hacking platforms QScan and QTRouter used to attack US critical infrastructure, including NASA and Federal Reserve.

Text generated by artificial intelligence, published without human review. AI transparency

The US Department of Justice announced on Wednesday the disruption of two hacking platforms operated by Chinese threat actors. The platforms, QScan and QTRouter, were used to target critical infrastructure and sensitive networks in the United States. The judicial action seized the domains embedded in the two products, causing their operations to cease.

Who Is Behind It: QTFY and the Nanjing Front Company

The activity is attributed to QTFY, a Chinese state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company. According to Damon Rouse, a researcher at Lumen Black Lotus Labs, QTFY has been active since May 2018. Lumen has tracked it for more than 18 months and began working with the FBI about a year ago.

The Nanjing-based company counts China’s Ministry of State Security and the People’s Liberation Army among its clients. It includes former PLA members and leverages their contacts to obtain contracts related to targeting critical infrastructure. QTFY has also taken part in Chinese freelance brokering networks to acquire and sell exploits and access to victim networks.

FBI Director Kash Patel stated that the tools were used by cyber actors from the People’s Republic of China to hide the origin of attacks. Lumen reports that targeting extended across the Western world and beyond, with particular interest in academia and research.

The Victims: NASA, Federal Reserve, Senate, and an Election System

Victims of the intrusive activity include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. Recent attacks, through June 2026, have also targeted a US election system.

The infrastructure allowed operators to hide the origin of intrusions by mixing malicious traffic with legitimate traffic from commercial proxies and compromised IoT devices. This made it difficult for defenders to identify and trace the activity.

The Technical Architecture: QScan, QTRouter, and the “Operational Relay Box”

QScan performs automated scanning and infection of IoT devices worldwide, adding them to the QTRouter network. The seized domains were hard-coded into both products. These include qt-proxy[.]org, mq-task.qt-proxy[.]org, and mq-result.qt-proxy[.]org. The first two provided scanning tasks to worker nodes hosted on leased servers outside China; the third received completed tasks.

QTRouter is a traffic obfuscation network running on routers with customized OpenWrt software. It authenticates to the management servers www.qtproxy[.]xyz and securelink.qtproxy[.]xyz and uses Clash to establish proxy connections. The network includes compromised devices, commercial proxy services, and leased virtual private servers. It allows operators to chain nodes and mix malicious traffic with legitimate traffic.

Botnets of compromised devices are controlled through three platforms: Proxy Platform Management, Proxy Pool Management System, and QTBotnet. QTBotnet includes a command-and-control server, second-level control servers, and compromised devices. The control server can launch DDoS attacks and execute commands on infected nodes.

The distributed architecture also includes Fast Labyrinth, an operational layer that integrates commercial proxy infrastructure such as Fastlink (fastlink.ws) into an encrypted relay network together with QTRouter. QTProxy manages Fast Labyrinth operational nodes and allows operators to use preconfigured relays or unique paths to target entities.

Lumen compares the whole to an “operational relay box”: a decentralized mesh of infected IoT devices and leased VPS that routes malicious traffic through rotating IPs. This evades blocklists and geolocation-based policies. Because transit circuits are procured through legitimate subscriptions to commercial proxy services, traditional static blocks are no longer sufficient.

The Attack Cycle and Exploited Vulnerabilities

According to the FBI, the attack cycle proceeds in four phases. First, QScan performs reconnaissance against victim networks. Then zero-day and N-day vulnerabilities are exploited to obtain initial access. Persistence follows through remote access trojans, web shells, and legitimate credentials. Finally, QTRouter allows access to the victim network from nearby compromised IoT devices, staying under the radar.

The cited zero-day vulnerabilities are three, all in Ivanti CSA appliances:

  • CVE-2024-8190 – OS command injection in Ivanti Cloud Services Appliance 4.6 Patch 518 and earlier. CVSS 7.2. Requires admin privileges for remote code execution.
  • CVE-2024-8963 – path traversal in Ivanti CSA before Patch 519 of 4.6. CVSS 9.4. An unauthenticated remote attacker can access restricted functionality.
  • CVE-2024-9380 – OS command injection in the Ivanti CSA admin web console before 5.0.2. CVSS 7.2. Requires admin privileges for remote code execution.

The exploited N-days include:

  • CVE-2018-13379 in Fortinet SSL-VPN (FortiOS 6.0.0–6.0.4, 5.6.3–5.6.7, 5.4.6–5.4.12 and FortiProxy 2.0.0, 1.2.0–1.2.8, 1.1.0–1.1.6, 1.0.0–1.0.7). An unauthenticated attacker can download system files via HTTP requests to the SSL VPN portal.
  • CVE-2019-19781 in Citrix ADC and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Directory traversal.
  • CVE-2021-26855 in Microsoft Exchange Server 2013. Remote code execution.
  • CVE-2020-5902 in F5 BIG-IP, CVE-2019-10068 in Kentico CMS, CVE-2021-44228 in Apache Log4j, CVE-2023-22515 in Atlassian Confluence, CVE-2024-24919 in Check Point Quantum Gateway, CVE-2025-31161 in CrushFTP and CVE-2026-1731 in BeyondTrust Remote Support.

For the CVEs listed beyond the first three, exact versions were not communicated by the FBI. All detailed CVEs have CVSS v3 scores ranging from 7.2 to 9.8; several are critical and allow remote code execution, path traversal, or unauthorized access.

Vulnerabilities in the KEV Catalog: Deadlines and Actions

Many of the cited CVEs are in CISA’s Known Exploited Vulnerabilities catalog. The dates added and remediation deadlines for US federal agencies are:

  • CVE-2018-13379, CVE-2019-19781, and CVE-2021-26855: in the KEV since November 3, 2021, due May 3, 2022. All are known to be used in ransomware campaigns.
  • CVE-2019-10068: in the KEV since March 25, 2022, due April 15, 2022.
  • CVE-2020-5902: in the KEV since November 3, 2021, due May 3, 2022. Known to be used in ransomware campaigns.
  • CVE-2024-8190: in the KEV since September 13, 2024, due October 4, 2024.
  • CVE-2024-8963: in the KEV since September 19, 2024, due October 10, 2024.
  • CVE-2024-9380: in the KEV since October 9, 2024, due October 30, 2024.

For the three Ivanti CSA vulnerabilities, CISA specifies a required action: because Ivanti CSA 4.6.x has reached End-of-Life status, users must remove CSA 4.6.x from service or move to the supported 5.0.x line. Future vulnerabilities in 4.6.x are unlikely to receive security updates.

The first three CVEs are known to be used in ransomware campaigns. Remediating them is therefore a priority even outside the federal perimeter.

What Organizations Should Do

Immediate actions depend on the exposed products. For CVEs in the KEV catalog, the general guidance is to apply vendor updates. For Ivanti CSA 4.6.x, the required mitigation is removal from service or upgrading to the 5.0.x line. Federal deadlines have already passed, but private organizations should treat them as a priority reference.

The FBI disrupted the main domains, but defenders must not lower their guard. QTFY’s distributed infrastructure can be rebuilt on new domains. Lumen emphasizes the high industrialization of Chinese cyber operations: the shift from fragmented configurations to shared multi-tenant networks enables complex campaigns with strong anonymity, speed, and global scale.

This is not an isolated case. In the last 90 days, CVE-2026-10520 has also been added to the KEV catalog, involving the same vendors present in this campaign: Ivanti, Kentico, and Citrix. The sequence indicates constant pressure on edge appliances and remote access solutions. Those who manage these products must verify versions, apply patches, and remove out-of-support systems.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsFBIQScanQTRouterChinese cyber threatsUS infrastructure securitycyberattack prevention
Back to home