US government agencies and critical infrastructure have been targeted for years through a web of proxy devices managed by a Chinese contractor, according to an FBI affidavit and court documents reported by WIRED. On Wednesday, the Department of Justice announced the takedown of two tools — QTRouter and QScan — used by a Chinese state-sponsored hacking group identified as QTFY, allegedly part of Nanjing Xinjiuwei Network Technology Company.
A Contractor-Operated Proxy Network
According to prosecutors and the FBI affidavit, Nanjing Xinjiuwei gave its customers access to botnets of hacked internet-of-things (IoT) devices and coopted commercial proxy services. Those customers allegedly included China's Ministry of State Security and the People's Liberation Army, and they used the services as relay points in hacking campaigns dating back as early as 2018, the US government said. Nanjing Xinjiuwei could not be immediately reached for comment, according to WIRED.
Lumen Technologies' Black Lotus Labs, which worked with the FBI and DOJ on the operation, described the Nanjing-based company as a "quartermaster" for China's hacking operations. Damon Rouse, a threat intelligence researcher at Black Lotus Labs, told WIRED:
"The scale is really giant."
Targets: From NASA to the Federal Reserve
The DOJ said the hackers breached NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself. The FBI affidavit also listed types of US infrastructure and industries targeted through the proxy networks, though it does not confirm which of those entities were successfully breached or to what degree.
| Target category | Specific entities / sectors listed |
|---|---|
| US government agencies | NASA, US Senate, Federal Reserve, Department of Energy, Department of Health and Human Services, National Institutes of Health, DOJ |
| Critical infrastructure sectors | Power companies, telecommunications providers, hospitals, financial institutions, defense contractors |
How QScan and QTRouter Worked
QScan, according to Lumen and the FBI, was designed to scan for vulnerabilities in IoT devices that could be hacked and added to botnets of infected devices serving as proxies. QTRouter allegedly managed customers' access to that botnet network, along with a network of commercial proxies known as virtual private servers (VPS) that could be rented and used in hacking campaigns.
Over the last year, Rouse noted, the group had shifted to hijacking virtual private network (VPN) services typically used by Chinese citizens to route around the Great Firewall censorship system. That created a layer of obfuscation mixing malicious state-sponsored traffic with benign Chinese user traffic. "It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were coopting," Rouse told WIRED.
Disruption and Aftermath
The FBI and Justice Department said they disrupted the proxy infrastructure by seizing key domains hardcoded into QScan and QTRouter. Lumen, which serves as an internet backbone provider, said it also "null-routed" certain domains, rendering them inoperable — including the more recent system of coopting censorship-bypassing VPNs.
Rouse called the campaign "a very long lasting campaign" with close ties to the highest levels of the People's Liberation Army, according to WIRED. The US attorney said that "state-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," WIRED reported. The takedown exposes how private contractors underpin Chinese state hacking, and the disclosure of victim agencies underscores the reach of the operation into the highest levels of the US government and the companies that keep its infrastructure running.