← BACK TO FEED
Chinacyber espionageDoJQTFYbotnets

DoJ Quietly Walks Back Claim That Major US Agencies Were Hacked by Chinese Group

The U.S. Department of Justice corrected a press statement to clarify that several federal agencies, including NASA, the Federal Reserve, and the DoJ itself, were *targeted* by Chinese state-linked hacking group QTFY rather than confirmed *victims*, a distinction suggesting not all targeted organisations were successfully compromised. QTFY, operating through a private Chinese company with ties to the Ministry of State Security, has been active since 2018 and provides cyber espionage tools — including a vulnerability scanning platform and an obfuscation network — used to attack critical infrastructure in the U.S. and abroad. The FBI has since seized domains linked to the group's key tools, while investigators revealed QTFY also operates a botnet of compromised IoT devices to mask the origins of its malicious traffic.

The Department of Justice has issued a quiet but meaningful correction to a press release about Chinese state-sponsored hacking activity. The original statement described NASA, the Federal Reserve, the Department of Energy, the DoJ itself, Health and Human Services, the NIH, and the US Senate as victims of intrusions carried out by a group called QTFY. The updated version now says those agencies were "among the targets." Small word change. Significant difference.

The correction, flagged by Reuters over the weekend, comes with a note explaining the edit was made to "accurately reflect the government's allegations in the affidavit in support of the domain seizures." Which is polite bureaucratic language for: we overstated things.

So who is QTFY? According to the affidavit, the group operates under a front company called Nanjing Xinjiuwei Network Technology Co, and payments from China's Ministry of State Security suggest the company is effectively a contractor doing Beijing's dirty work. QTFY has been active since at least 2018, and its target list is broad: federal networks, hospitals, telecoms, power companies, banks, and defence contractors in the US and elsewhere.

The group has been described as a "technical quartermaster" for Chinese cyber espionage. Its two main tools are QScan, a vulnerability scanning and exploitation platform, and QTRouter, an obfuscation network. The FBI has since seized the domains tied to both products, including qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, rendering the infrastructure inoperable.

One documented intrusion attempt dates to 2019, when QTFY tried to break into NASA by exploiting CVE-2019-11510, a critical flaw in Pulse Secure VPN. Whether they got in isn't stated, which is sort of the point of the correction.

Researchers at Lumen Black Lotus Labs have dug into the wider architecture and found something worth paying attention to. QTFY has industrialised the creation of what are called Operational Relay Box networks: botnets built from compromised IoT devices and rented virtual private servers, designed specifically to obscure the origin of attacks. QTFY sells access to QScan and QTRouter to other threat actors, who can then use compromised IoT devices as relay nodes inside QTRouter. The whole thing feeds into a larger encrypted relay network called Fast Labyrinth, which blends malicious traffic with normal internet activity.

The practical effect is that attacks appear to originate from local consumer devices near the target, making attribution and detection considerably harder. Routing hostile traffic through a printer or a router down the street from your target is not a new concept, but doing it at industrial scale with a commercial business model behind it is a different proposition entirely.

The DoJ's correction matters because the original framing implied successful breaches across some of the most sensitive parts of the US government. The revised version is more cautious: these organisations were in the crosshairs, but whether the attackers got what they came for is a separate question.

READ NEXT
FBI Takes Down Chinese State Hacking Tools Used Against NASA, Senate, and DOENine Charged in Taiwan Over Smuggled AI Servers Destined for China, Nvidia and Super Micro Staff Among AccusedQUICAgent Backdoor Targets Myanmar Government in Multi-Stage Espionage Campaign