The U.S. Department of Justice (DoJ) has revised a previously issued statement regarding cyber activity linked to the China affiliated threat group QTFY, clarifying that several U.S. government agencies were among the intended targets rather than confirmed victims of the campaign. The correction follows an earlier announcement that identified organizations including National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate as victims of computer intrusion activity. The updated statement now describes these organizations as being among the targets of QTFY, aligning the public announcement with details contained in the supporting legal affidavit. Reuters reported the revision over the weekend, while DoJ stated that the edits were made to accurately reflect the government’s allegations presented in the domain seizure case.
According to the affidavit, QTFY, also known as QT and QTCYBER, operates on behalf of Nanjing Xinjiuwei Network Technology Co., a private Chinese company that investigators believe has received payments from the Ministry of State Security for conducting cyber operations. Authorities believe the group has been active since 2018 and has targeted critical and sensitive networks in the United States and other countries. Beyond federal government networks, the campaign has focused on hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. Investigators describe QTFY as providing technical support for cyber espionage operations through reconnaissance, proxy management, and operational routing capabilities. Its primary tools include QScan, a platform designed for vulnerability scanning and exploitation, and QTRouter, an obfuscation network used to conceal malicious activity. Court documents also reference an attempted intrusion into National Aeronautics and Space Administration in 2019 through exploitation of the critical Pulse Secure VPN vulnerability tracked as CVE 2019 11510.
The updated wording is significant because it distinguishes between organizations that were selected for targeting and those that may have experienced confirmed network compromise. As part of its response, Federal Bureau of Investigation has disrupted domains associated with QScan and QTRouter, including qtproxy.xyz, qt proxy.org, and qt team.com, limiting the operation of the group’s infrastructure. Additional research from Lumen Black Lotus Labs indicates that QTFY has developed large Operational Relay Box networks to support cyber espionage campaigns. These networks combine compromised Internet of Things devices with leased virtual private servers, allowing operators to route malicious traffic through systems located near intended targets while making activity appear more consistent with legitimate local network traffic.
Investigators further stated that QTFY provides access to QScan and QTRouter to other operators for identifying and exploiting vulnerable Internet of Things devices. Once compromised, these devices become additional nodes within the QTRouter network, expanding its relay infrastructure. Researchers also found that the network includes systems operated through the Chinese commercial proxy service Fastlink and forms part of an encrypted relay architecture known as Fast Labyrinth. According to the affidavit, routing malicious traffic through compromised devices located close to intended targets allows operators to reduce suspicion while conducting reconnaissance and intrusion attempts against critical infrastructure and other sensitive networks. The revised DoJ statement reflects the distinction between organizations identified as intended targets and those where confirmed compromise has been established, while continuing ongoing efforts to disrupt infrastructure associated with the QTFY operation.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.