FBI Dismantles China-Backed Proxy Network Targeting US Critical Infrastructure
The FBI, in collaboration with the Department of Justice, has announced the takedown of a sophisticated proxy network, **QTRouter** and **QScan**, allegedly operated by Chinese state-sponsored hackers. This disruption reveals a widespread campaign targeting critical US government institutions and infrastructure, highlighting the extensive reach and reliance on third-party contractors for state-backed cyber espionage.
For years, China's military and intelligence agencies have leveraged vast networks of proxy devices to obfuscate their global hacking campaigns. The recent action by the **FBI** and **Department of Justice (DOJ)** has not only named but also significantly disrupted one such key network, exposing the deep penetration into American government and critical infrastructure.
On Wednesday, the DOJ announced the takedown of two tools, **QTRouter** and **QScan**, utilized by a Chinese state-sponsored hacking group identified as **QTFY**. This group is allegedly part of a Chinese government contractor named **Nanjing Xinjiuwei Network Technology Company**.
According to prosecutors and an **FBI** affidavit, **Nanjing Xinjiuwei Network Technology Company** provided its customersβreportedly including the **Ministry of State Security** and the **People's Liberation Army**βaccess to botnets of hacked Internet of Things (**IoT**) devices and co-opted commercial proxy services. These services served as relay points for hacking campaigns dating back to 2018.
The **DOJ** reports a staggering list of US victim agencies targeted, including attempted hacks of the **US Senate** and the **Department of Health and Human Services**. Successful breaches were recorded against the **Federal Reserve**, the **Department of Energy**, the **National Institute of Health**, and even the **DOJ** itself.
The **FBI** affidavit further details the types of US infrastructure and industries targeted through these proxy networks, encompassing power companies, telecommunications providers, hospitals, financial institutions, and defense contractors. While the affidavit lists targets, it does not confirm the extent of successful breaches for all entities.
"The scale is really giant," commented **Damon Rouse**, a threat intelligence researcher at **Lumen Technology's Black Lotus Labs**, which collaborated with the **FBI** and **DOJ** on the operation. In a blog post, **Black Lotus Labs** described the Nanjing-based company as a "quartermaster" for China's hacking operations, one of several private contractors increasingly supplying critical tools and infrastructure to state-sponsored hackers.
**Rouse** emphasized the longevity and deep ties of the campaign: "This is a very long-lasting campaign, and this company and these people involved in it have very close ties to the highest levels of the **People's Liberation Army**."
**QScan**, as detailed by **Lumen** and the **FBI**, was designed to scan for vulnerabilities in **IoT** devices, enabling their recruitment into botnets that served as proxies. The **QTRouter** service allegedly managed customer access to this botnet network, alongside a network of commercial proxies, including rented virtual private servers, used in hacking campaigns.
Over the past year, **Rouse** noted a shift in tactics, with the group increasingly hijacking **VPN** services typically used by Chinese citizens to bypass China's Great Firewall censorship system. This created a layer of obfuscation, blending malicious traffic with benign user traffic seeking open internet access. "It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user **VPN** traffic in the nodes they were co-opting," **Rouse** explained.
The **FBI** and **Justice Department** have now disrupted this proxy infrastructure by seizing key domains hardcoded into **QScan** and **QTRouter**. **Lumen**, an internet backbone provider, further "null-routed" specific domains, rendering them inoperable, including those involved in the newer **VPN** co-option scheme.
US Attorney General **Todd Blanche** stated, "State-sponsored malicious hackers preying on Americaβs critical infrastructure will be stopped and prosecuted." However, the **DOJ's** announcement did not include charges against any specific individuals at this time.