Ethical Hacking News
The FBI has disrupted a sophisticated proxy network used by a Chinese state-sponsored hacking group known as QTFY, which has been used to breach numerous US government agencies and critical infrastructure. The disruption marks a significant setback for the hacking group and some embarrassment and customer relations problems for the Nanjing Xinjiuwei Network Technology Company. However, it is likely that the QTFY hacking group will adapt and return, as they have done in the past, and the US government and its allies will need to remain vigilant and proactive in their efforts to counter this threat.
The Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) have disrupted a sophisticated proxy network used by a Chinese state-sponsored hacking group known as QTFY. The QTFY proxy network was used to target numerous US government agencies and critical infrastructure, including NASA, the US Senate, and the Federal Reserve. The hacking group, allegedly linked to the Ministry of State Security and the People's Liberation Army, had been using the proxy network to breach US victim agencies since at least 2018. The disruption of the proxy network marks a significant setback for the hacking group and some embarrassment for the Nanjing Xinjiuwei Network Technology Company, which developed the network. The QTFY hacking group is likely to adapt and return, as they have done in the past, posing a continued threat to US critical infrastructure and government agencies.
The recent announcement by the Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) has sent shockwaves through the cybersecurity community, as it revealed the disruption of a sophisticated proxy network used by a Chinese state-sponsored hacking group known as QTFY. The QTFY proxy network, which was allegedly used by the Ministry of State Security and the People's Liberation Army, has been at the center of a massive hacking campaign targeting numerous US government agencies and critical infrastructure.
According to the DOJ, the QTFY hacking group had been using a vast web of proxy devices to enable and obfuscate their targeting. The FBI has now named and disrupted one key network of those proxies, revealing just how extensively the hackers who used it reached into American government institutions and US critical infrastructure. The QTFY proxy network, which was designed to scan for vulnerabilities in IoT devices that could be hacked and added to botnets of infected devices that served as proxies, was allegedly used by the QTFY hacking group to breach a staggering list of US victim agencies, including NASA, the US Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the DOJ itself.
The QTFY proxy network, which was developed by the Nanjing Xinjiuwei Network Technology Company, was a key component of the hacking group's operations. The company, which is allegedly part of a Chinese government contractor, provided its customers with access to botnets of hacked IoT devices and co-opted commercial proxy services. The customers, who were allegedly included in the Ministry of State Security and the People's Liberation Army, then used those proxy services as relay points to carry out hacking campaigns stretching back as early as 2018.
The FBI's affidavit, which was used to seize domains that the QTFY proxy network relied on, revealed that the hacking group had been using a variety of tactics to evade detection. The group had transitioned to hijacking virtual private network (VPN) services typically used by Chinese citizens to route around China's Great Firewall censorship system. By proxying their malicious traffic through these VPNs, the QTFY hacking group was able to create a layer of obfuscation that mixed malicious traffic with the benign traffic of Chinese users seeking to access the open internet.
The disruption of the QTFY proxy network by the FBI and the DOJ marks a significant setback for the hacking group and some embarrassment and customer relations problems for the Nanjing Xinjiuwei Network Technology Company. According to Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, which worked with the FBI and DOJ on the takedown operation, the disruption of the QTFY proxy network will create a direct effect on the company and its perception in China. Rouse notes that the Nanjing-based company is a kind of "quartermaster" for China's hacking operations, one of several private contractors that increasingly provide key tools and infrastructure to China's state-sponsored hackers.
However, Rouse also cautions that the QTFY hacking group will likely adapt and return, as they have done in the past. The group's flexibility in shifting their methods over the years to find new ways to relay and disguise malicious traffic means that they will continue to be a threat to US critical infrastructure and government agencies. As Rouse notes, the QTFY hacking group's operations are "pretty much as broad as you can get, mapping back to what Chinese cyber operations are tasked with in terms of information collection."
The disruption of the QTFY proxy network is a significant development in the ongoing battle between US law enforcement agencies and Chinese state-sponsored hackers. As the US government continues to work to disrupt and dismantle these hacking groups, it is clear that the war between cyber espionage and cybersecurity will only continue to intensify. With the QTFY hacking group's sophisticated proxy network now exposed, the US government and its allies will need to remain vigilant and proactive in their efforts to counter this threat.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Unveiling-of-QTFY-Chinas-Sophisticated-Proxy-Network-Exposed-by-the-FBI-ehn.shtml
https://www.wired.com/story/fbi-disrupts-chinese-proxy-tools-used-in-mass-hacking-of-us-agencies-and-infrastructure/
https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
Published: Wed Aug 26 16:23:51 2026 by llama3.2 3B Q4_K_M