FBI disrupts proxy network enabling Chinese espionage operations

Federal authorities have disrupted a sophisticated proxy network used by Chinese cyber operatives to carry out espionage operations against high-stakes targets in the US. The FBI’s operation has dealt a significant blow to the group, known as QTFY/QT/QTCYBER, which employed advanced tools and infrastructure to evade detection.

QTFY, backed by the China-based Nanjing Xinjiuwei Network Technology Company, had created and operated two key hacking platforms: “QScan” and “QTRouter”. These frameworks were used in attacks on critical US infrastructure, including NASA, the Federal Reserve, and several government departments. The group’s targets also included major research institutions, defense contractors, and financial firms.

The QTFY operation is believed to have been carried out on behalf of China’s Ministry of State Security (MSS), with court documents revealing that former members of the Chinese People’s Liberation Army military wing were involved in the group. This raises concerns about the level of coordination between Chinese state actors and commercial entities involved in cyber espionage.

The FBI’s disruption of QTFY’s infrastructure has resulted in the seizure of several key domains, including qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com. These domains had been used to operate QScan, a scanning and exploitation platform that identified high-value targets and collected sensitive data from compromised networks.

Black Lotus Labs, the threat research arm of Lumen Technologies, has been tracking QTFY’s infrastructure for over a year and discovered that the group offered a reusable service consisting of four distinct operational elements. These included QScan for reconnaissance, Fast Labyrinth for encrypted relay networks, QTRouter for access to proxy infrastructure, and QTProxy for management of custom routes.

The disruption of QTFY’s operation highlights the growing use of Operational Relay Box (ORB) networks by Chinese threat actors. ORBs are decentralized networks of compromised infrastructure that obscure the origin of malicious traffic by routing it through legitimate devices. This tactic has become increasingly common in recent years, with researchers noting a significant increase in ORB-based attacks since 2024.

The FBI’s action is seen as a major victory in the ongoing battle against Chinese cyber espionage operations. It serves as a reminder that sophisticated proxy networks can be identified and disrupted with coordinated efforts between law enforcement agencies and threat intelligence groups. As we continue to navigate the complex landscape of cyber threats, it’s essential for organizations to remain vigilant and adopt robust security measures to protect themselves against advanced attacks.

For individuals and organizations looking to stay ahead of emerging threats, it’s crucial to implement robust security protocols and stay informed about the latest developments in the cybersecurity world. This includes monitoring for suspicious activity, keeping software up-to-date, and being cautious when interacting with unfamiliar networks or devices. By staying proactive and informed, we can better protect ourselves against the evolving threat landscape.


Source: Bleeping Computer — 2026-08-26