For several years, Chinese military and intelligence agencies have utilized an extensive network of proxy devices to facilitate and obscure their hacking operations globally. Recently, the FBI has focused on dismantling one of these critical proxy networks, highlighting the vast extent of hacking that has infiltrated U.S. government bodies and critical infrastructure.
On a recent Wednesday, the Department of Justice (DOJ) announced the takedown of two specific tools, QTRouter and QScan. These tools were employed by a Chinese state-sponsored hacking group known as QTFY, linked to Nanjing Xinjiuwei Network Technology Company. Authorities assert that this company provided access to botnets formed from hacked Internet of Things (IoT) devices coupled with commercial proxy services. Notably, customers of this company reportedly included China’s Ministry of State Security and the People’s Liberation Army, utilizing these proxies to conduct hacking operations since 2018.
The DOJ reported that the hacking activities targeted numerous U.S. agencies, including NASA, the Federal Reserve, and the Department of Energy, among others.
Despite attempts to reach Nanjing Xinjiuwei for comments, there was no immediate response. The FBI’s filings detailed numerous U.S. sectors affected by these proxy networks, encompassing power companies, telecommunications, healthcare, financial institutions, and defense contractors. However, it remains unclear which entities faced successful breaches.
Damon Rouse, a researcher at Lumen Technology’s Black Lotus Labs, which collaborated with the FBI and DOJ on this operation, emphasized the operation’s monumental scale and its connections to the highest ranks of the People’s Liberation Army.
QScan was reportedly created to identify weaknesses in IoT devices, integrating them into the botnet for use as proxies. The QTRouter service purportedly managed access for customers to both this botnet and a network of virtual proxies available for rent for hacking endeavors.
Over the last year, the group has begun hijacking virtual private networks (VPNs) to further obscure their actions, blending malicious traffic with legitimate user data to complicate detection efforts by security analysts.
Following the seizure of key domains integral to QScan and QTRouter, the FBI and DOJ have effectively disrupted the hackers’ infrastructure. Lumen mentioned taking additional measures to nullify certain domains, including those utilized for the newly introduced VPN hijacking scheme.
U.S. Attorney General Todd Blanche stated that state-sponsored attacks on critical infrastructure would face rigorous prosecution, although no individuals were charged in this specific announcement. The intent behind these hacking efforts remains somewhat ambiguous, with indications that they focus on traditional espionage rather than disruptive attacks like those of the Volt Typhoon campaigns.
While this disruption represents a setback in QTFY’s operations and could affect Nanjing Xinjiuwei’s reputation in China, analysts suggest that the group will likely adapt and reestablish its operations in new forms. Rouse noted that this incident could indeed be a "moment of embarrassment" for the company, yet it is assumed they will quickly pivot to create new infrastructure for their hacking strategies.