FBI Dismantles Chinese Espionage Proxy Network Targeting U.S. Critical Infrastructure
The FBI has successfully disrupted a sophisticated proxy network, dubbed 'QTFY,' which provided critical reconnaissance and operational routing capabilities for Chinese state-sponsored cyber espionage. This network targeted a wide array of sensitive U.S. entities, including government agencies, critical infrastructure, and defense organizations. The operation highlights the ongoing threat of nation-state hacking and the collaborative efforts to counteract it.

The **FBI** and **Department of Justice (DoJ)** have announced the disruption of infrastructure linked to a technical 'quartermaster' known as **QTFY/QT/QTCYBER**. This entity facilitated sophisticated cyber espionage operations on behalf of the Chinese government, providing reconnaissance, proxy management, and operational routing.
### Targeting U.S. Critical Infrastructure
**QTFY** operated two primary hacking platforms: '**QScan**' and '**QTRouter**.' These platforms were instrumental in attacks against critical U.S. infrastructure and other sensitive networks. Notable targets included **NASA**, the **Federal Reserve**, the Departments of **Energy**, **Justice**, and **Health and Human Services**, the **National Institutes of Health**, and the **U.S. Senate**.
The **DoJ** revealed that the **QTFY** group created and operated these frameworks while employed by the China-based **Nanjing Xinjiuwei Network Technology Company**. Court documents further indicate that the group includes former members of the **Chinese People's Liberation Army** military wing, and that **Nanjing Xinjiuwei** received payments from China's **Ministry of State Security (MSS)**, firmly linking the company to malicious cyber activities on behalf of the **PRC Government**.
### Seizure of Malicious Domains
Supporting legal actions led to the seizure of domains associated with **QTFY**'s operations: `qtproxy[.]xyz`, `qt-proxy[.]org`, and `qt-team[.]com`. These domains, used for **QScan** (a scanning and exploitation platform) and **QTRouter** (an obfuscation network), now display law enforcement banners.

### Unpacking the QTFY Framework
**Black Lotus Labs**, the threat research arm of **Lumen Technologies**, had been tracking **QTFY**'s infrastructure for over a year, identifying the framework's components used in attacks against U.S. critical infrastructure. Their analysis revealed a reusable service comprising four distinct operational elements:
* **QScan**: A reconnaissance component for identifying and profiling high-value targets, collecting data like open ports, application banners, OS fingerprints, and configuration data.
* **Fast Labyrinth**: An encrypted relay network designed to conceal communications to and from victim organizations.
* **QTRouter**: A preconfigured physical device providing access to the proxy infrastructure and node management.
* **QTProxy**: A management tool allowing users to select relays and configure custom routes through **Fast Labyrinth**.
This infrastructure was used to profile and exfiltrate data from a broad spectrum of targets, including U.S. military and defense organizations, government networks, universities, research institutions, aerospace, bioinformatics organizations, healthcare entities, financial firms, critical infrastructure, energy companies, and enterprise software vendors.
**Lumen Technologies** commended the **FBI** and **DoJ** for their efforts, stating, βDuring our investigation, **Black Lotus Labs** shared threat intelligence to warn agencies across the U.S. Government of emerging risks that could impact our nationβs strategic assets.β The researchers also noted their efforts to disrupt the infrastructure by null-routing traffic to known operational points.
### Building an Evasive ORB Network
**Lumen**'s research highlights how the 'quartermaster' industrialized the creation of Operational Relay Box (**ORB**) networks for China-linked espionage. **ORBs** are decentralized networks of compromised infrastructureβsuch as SOHO routers, IoT devices, VPS servers, and commercial proxy nodesβused to relay malicious traffic and obscure its true source. Chinese threat actors have increasingly leveraged **ORBs** in cyber operations since 2024, intensifying this activity earlier this year.
Instead of building a conventional **ORB** network from thousands of compromised devices, **QTFY** purchased premium access to select nodes operated by the Chinese commercial proxy service `fastlink.ws`. These nodes formed **Fast Labyrinth**, an **ORB**-style relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure.

The overlap between **QScan** targets and organizations later contacted through **Fast Labyrinth** provides strong evidence connecting reconnaissance to follow-up operations.

**Lumen** assesses that the observed bidirectional connections from the proxy network likely represent attempted exploitation, lateral movement, persistent access, or data collection. While this disruption is significant, **Lumen** warns that static blocking alone may be ineffective due to the quartermaster's use of dynamically rotating commercial proxy services.
Defenders are advised to follow **CISA** and **NCSC** guidance for mitigating China-nexus threats and to ensure routers, firewalls, and IoT devices are kept up-to-date and securely configured.