FBI seizes domains used by Chinese state-backed hackers for proxy operations

The FBI seized three domains linked to a Chinese hacking group known as QTFY, which used the QScan and QTRouter platforms for reconnaissance and proxy routing in attacks on US critical infrastructure. The group, allegedly employed by Nanjing Xinjiuwei Network Technology Company, targeted agencies including NASA and the Federal Reserve. The domains now display a law enforcement banner, and the operation was supported by threat research from Lumen's Black Lotus Labs.
The seized domains—qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com—formed the operational backbone for QScan and QTRouter, which combined scanning, exploitation, and encrypted relay capabilities. Black Lotus Labs identified four components: QScan for reconnaissance, Fast Labyrinth for encrypted relays, QTRouter as a physical access device, and QTProxy for route management.
The group's infrastructure enabled profiling of military, government, academic, healthcare, and financial targets. Lumen null-routed traffic to known infrastructure points, complementing the FBI's domain seizures. QTFY reportedly industrialized Operational Relay Box networks, converting compromised routers and IoT devices into anonymizing nodes for espionage traffic.
This disruption could reduce the operational capacity of state-linked espionage groups targeting U.S. infrastructure, though similar frameworks may persist through alternative infrastructure. Organizations previously profiled may face residual risks from stolen data, and the takedown may prompt adversaries to adopt more resilient architectures. The action underscores how private-sector threat research and government enforcement can combine to raise costs for malicious cyber operations.