BlackTree Security · Infrastructure · Automation · AI

China’s Cyber Quartermaster Turned 200 Exploits and Millions of Scans Into an Espionage Platform.

A China-linked company built more than a hacking tool. QTFY combined a 200-exploit scanning platform, millions of automated tasks and a distributed proxy network into an operational supply chain for state cyber activity. US authorities have now seized the domains that held it together.

The US Department of Justice and FBI announced court-authorised seizures against three domains embedded in two complementary systems, QScan and QTRouter. Because the domains handled essential communication and authentication functions and were hard-coded into the tools, the government says the action made both platforms inoperable.

That is the disruption headline. The more consequential story is the operating model behind it.

QScan industrialised exploitation

A joint FBI, NSA and US Cyber National Mission Force advisory describes QScan as a distributed system for web scraping, TLS-certificate collection, subdomain enumeration and penetration testing. The platform contained a database of more than 200 proof-of-concept exploits written in Python and distributed tasks to worker nodes hosted primarily on leased servers outside China.

On one day in 2024, QScan processed more than two million scanning and penetration-testing tasks. That figure turns vulnerability research into an operational capacity calculation. The platform could take a newly relevant weakness, place it into a reusable queue and direct a distributed workforce of machines at large target sets.

The advisory traces targeting from at least 2018 across defence, energy, telecommunications, government, healthcare, finance, higher education and election infrastructure. Some entries describe successful compromise or data theft. Others explicitly record unsuccessful scanning or exploitation attempts. Those categories should not be collapsed: appearing in the target history does not mean every organisation was breached.

QTRouter made the activity look local

QTRouter supplied the other half of the service. It combined compromised Internet-of-Things devices, commercial proxy nodes, leased virtual private servers and routers running custom OpenWrt software. Operators could view available nodes, chain them together and send intrusion traffic through infrastructure outside China.

The result was not merely anonymity. A connection could appear to originate from the same country or region as the target, blending with legitimate residential and commercial traffic. That weakens simple location-based detections and makes an intrusion look more like a local user or ordinary service than a state operation crossing an international boundary.

QScan also helped compromise vulnerable IoT devices that could be enrolled into the QTRouter network. The scanner created infrastructure for the proxy layer, and the proxy layer concealed later scanning and intrusion activity. This feedback loop is what made the two systems more consequential together than either product alone.

A cyber quartermaster, not a single intrusion crew

The US advisory attributes QTFY, also known as QT and QTCYBER, to Nanjing Xinjiuwei Network Technology. It describes the company as an enabler for cyber operations linked to the People’s Republic of China, with business relationships across an ecosystem that includes Ministry of State Security units, former People’s Liberation Army personnel and private companies that buy, sell and broker exploits or network access.

According to the Justice Department, QTFY offered hacking services to paying customers that included the Ministry of State Security and the PLA. Lumen Black Lotus Labs frames the group as an infrastructure quartermaster: a provider that turns tools, proxy capacity and access into shared capability for other operators.

This matters strategically. Defenders often organise detections around a named threat actor and its characteristic infrastructure. A supplier model allows multiple customers to draw from the same scanning and obfuscation stack, while one customer may also switch providers or infrastructure. Attribution indicators still help, but the reusable service can outlive a specific campaign.

What the seizures achieved

US authorities seized domains that QScan and QTRouter used for communication, tasking and authentication. The hard-coded dependency created a central point of failure inside systems designed to be distributed. The government says the intervention disabled both platforms.

That is a meaningful operational loss, but it is not the same as erasing every compromised router, deleting every exploit or dismantling the organisation behind the service. Operators can rebuild infrastructure, change software or migrate to other proxy networks. Defenders should treat the seizure as a disruption and intelligence opportunity, not a permanent removal of the threat.

Defensive actions

  • Use the published indicators. The joint advisory provides downloadable file and infrastructure indicators. Search historical as well as current telemetry because QTFY activity dates back years.
  • Patch edge and IoT devices promptly. QTFY used vulnerable routers and other devices as both access opportunities and proxy capacity.
  • Separate critical systems from the edge. A compromised gateway or IoT device should not have an unrestricted path to identity, management or operational networks.
  • Do not trust geography. Residential, commercial and locally located proxy traffic can carry state-sponsored activity. Combine location with identity, device, behaviour and application context.
  • Protect operational information. Internet-facing applications can reveal software, plugins, certificates, naming conventions and other details that improve automated target selection.
  • Investigate failed attempts. Repeated unsuccessful scanning can show that an organisation is on a target list and identify the technology attackers expect to find.

The larger lesson

QTFY illustrates how cyber operations are becoming supply chains. One organisation can acquire exploits, automate discovery, compromise edge devices, package proxy capacity and sell the finished capability to state customers. That model reduces the distance between vulnerability disclosure and operational use while making the source of an attack harder to recognise.

The scanner found the doors. The router network hid who was knocking. The quartermaster made both available as a service.

Sources and publication details

Leave a Reply

Your email address will not be published. Required fields are marked *