Full Report
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
Analysis Summary
# Incident Report: Disrupting Chinese State-Sponsored Proxy Networks (QTFY)
## Executive Summary
The U.S. Department of Justice (DOJ) and FBI disrupted a massive hacking infrastructure operated by a Chinese state-sponsored group known as "QTFY." The group utilized hijacked IoT devices and commercial proxy services to mask intrusions into high-value U.S. government agencies and critical infrastructure. The campaign resulted in the compromise of several federal departments, including NASA, the Federal Reserve, and the US Senate.
## Incident Details
- **Discovery Date:** Publicly announced August 2026 (Investigation ongoing for several years)
- **Incident Date:** Active from 2018 to August 2026
- **Affected Organization:** NASA, U.S. Senate, Federal Reserve, Department of Energy, HHS, NIH, and DOJ
- **Sector:** Public Sector / Government / Critical Infrastructure
- **Geography:** United States (Targets) / China (Attribution)
## Timeline of Events
### Initial Access
- **Date/Time:** Commencing as early as 2018.
- **Vector:** Exploitation of Internet-of-Things (IoT) devices and vulnerabilities in edge networking equipment.
- **Details:** The group utilized tools named **QTRouter** and **QScan** to identify vulnerable devices and integrate them into a massive botnet.
### Lateral Movement
- **Details:** Once initial access was gained via proxy nodes, the attackers leveraged these obscured connections to penetrate internal government networks, moving laterally to reach sensitive data repositories.
### Data Exfiltration/Impact
- **Details:** The campaign targeted a "staggering list" of federal agencies. While specific file names were not disclosed, the scope includes sensitive data from the Department of Energy, the Federal Reserve, and the US Senate.
### Detection & Response
- **How it was discovered:** Intelligence gathered by the FBI regarding the Nanjing Xinjiuwei Network Technology Company and its relationship with the MSS and PLA.
- **Response actions taken:** The FBI executed a court-authorized takedown of domains used by the QTRouter and QScan tools, disrupting the botnet's command-and-control (C2) structure.
## Attack Methodology
- **Initial Access:** Exploitation of IoT devices and commercial proxy services.
- **Persistence:** Maintaining a rotating botnet of hacked consumer and enterprise devices.
- **Defense Evasion:** Use of "proxy-as-a-service" to obfuscate the origin of Chinese military/intelligence IP addresses.
- **Discovery:** Utilization of the **QScan** tool for large-scale reconnaissance of U.S. infrastructure.
- **Lateral Movement:** Relaying malicious traffic through legitimate-looking domestic IP addresses.
- **Collection:** Gathering data from high-value federal targets.
- **Impact:** Systemic compromise of government network integrity.
## Impact Assessment
- **Financial:** Costs associated with multi-year federal investigations and remediation of compromised agency networks.
- **Data Breach:** Massive theft of government data; exact volume classified.
- **Operational:** Disruption of proxy tools used by the MSS and PLA for intelligence gathering.
- **Reputational:** High-profile exposure of vulnerabilities in U.S. government IoT and edge security.
## Indicators of Compromise
- **Network Indicators:** Connections to domains associated with **QTRouter** and **QScan** (e.g., [.]qtrdly[.]com - *example of defanged format*).
- **Behavioral Indicators:** Traffic originating from residential or small-business IoT devices attempting to authenticate with government gateways.
## Response Actions
- **Containment:** Domain seizure of infrastructure used by Nanjing Xinjiuwei Network Technology Company.
- **Eradication:** Disruption of the QTRouter malware on infected IoT devices via C2 takedown.
- **Recovery:** Ongoing monitoring of federal networks for residual lateral movement by QTFY.
## Lessons Learned
- **Key Takeaways:** Chinese state actors are increasingly outsourcing infrastructure to "contractor" companies to provide plausible deniability.
- **Gap Analysis:** IoT devices remain a significant blind spot in national cybersecurity, providing an easy entry point for state-sponsored proxy networks.
## Recommendations
- **Device Security:** Implement strict access control and regular patching for all IoT and edge devices (routers, cameras, etc.).
- **Traffic Analysis:** Monitor for unusual traffic patterns originating from residential IP spaces targeting enterprise VPNs or databases.
- **Zero Trust:** Accelerate the adoption of Zero Trust Architecture (ZTA) to limit the effectiveness of lateral movement even when proxy-based obfuscation is used.