FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure (opens in a new tab)
Why readDOJ and FBI seized the domains behind QTRouter and QScan, proxy and scanning tools sold by Nanjing Xinjiuwei Network Technology to the MSS and PLA, with the affidavit detailing how deeply the operators reached into US agencies and critical infrastructure.
The takedown targets a Chinese state-sponsored group the DOJ calls QTFY, allegedly operating out of contractor Nanjing Xinjiuwei Network Technology, which supplied customers with botnets of compromised IoT devices and co-opted commercial proxy services to obfuscate operations. The FBI affidavit used to seize the domains sets out the scale of access into American government institutions and critical infrastructure. For defenders, the value is the named tooling and the confirmation that ORB-style proxy infrastructure is being run as a commercial service to Chinese intelligence customers.