DoJ Quietly Walks Back Claim That Major US Agencies Were Hacked by Chinese Group
The Department of Justice has issued a quiet but meaningful correction to a press release about Chinese state-sponsored hacking activity. The original statement described NASA, the Federal Reserve, the Department of Energy, the DoJ itself, Health and Human Services, the NIH, and the US Senate as victims of intrusions carried out by a group called QTFY. The updated version now says those agencies were "among the targets." Small word change. Significant difference.
The correction, flagged by Reuters over the weekend, comes with a note explaining the edit was made to "accurately reflect the government's allegations in the affidavit in support of the domain seizures." Which is polite bureaucratic language for: we overstated things.
So who is QTFY? According to the affidavit, the group operates under a front company called Nanjing Xinjiuwei Network Technology Co, and payments from China's Ministry of State Security suggest the company is effectively a contractor doing Beijing's dirty work. QTFY has been active since at least 2018, and its target list is broad: federal networks, hospitals, telecoms, power companies, banks, and defence contractors in the US and elsewhere.
The group has been described as a "technical quartermaster" for Chinese cyber espionage. Its two main tools are QScan, a vulnerability scanning and exploitation platform, and QTRouter, an obfuscation network. The FBI has since seized the domains tied to both products, including qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, rendering the infrastructure inoperable.
One documented intrusion attempt dates to 2019, when QTFY tried to break into NASA by exploiting CVE-2019-11510, a critical flaw in Pulse Secure VPN. Whether they got in isn't stated, which is sort of the point of the correction.
Researchers at Lumen Black Lotus Labs have dug into the wider architecture and found something worth paying attention to. QTFY has industrialised the creation of what are called Operational Relay Box networks: botnets built from compromised IoT devices and rented virtual private servers, designed specifically to obscure the origin of attacks. QTFY sells access to QScan and QTRouter to other threat actors, who can then use compromised IoT devices as relay nodes inside QTRouter. The whole thing feeds into a larger encrypted relay network called Fast Labyrinth, which blends malicious traffic with normal internet activity.
The practical effect is that attacks appear to originate from local consumer devices near the target, making attribution and detection considerably harder. Routing hostile traffic through a printer or a router down the street from your target is not a new concept, but doing it at industrial scale with a commercial business model behind it is a different proposition entirely.
The DoJ's correction matters because the original framing implied successful breaches across some of the most sensitive parts of the US government. The revised version is more cautious: these organisations were in the crosshairs, but whether the attackers got what they came for is a separate question.