~/f4n6 $ grep -r "Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting" ./investigations/ --include="*.md"

Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting

Jeff Davies 03 Sep 2026 8 min read


1. Executive summary

On 27 August 2026 the US Department of Justice announced court-authorised seizure of three domains (qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com), rendering inoperable two PRC-linked cyberespionage platforms operated by the group QTFY: QScan, a distributed vulnerability scanning and IoT infection system, and QTRouter, a covert communications/obfuscation network routing traffic through compromised IoT devices. QTFY works for the private Chinese company Nanjing Xinjiuwei Network Technology and has supported PRC government customers — including the Ministry of State Security and the PLA — since at least 2018; alleged victim categories include financial institutions, hospitals, telecoms and US federal agencies. Attribution of QTFY, Nanjing Xinjiuwei, Flax Typhoon and Qilin is unconfirmed at MITRE ATT&CK level — none has an ATT&CK profile; only Volt Typhoon (G1017) is a tracked actor. This is a law-enforcement disruption, not a new vulnerability: the client-facing risk is that QTFY-style scanning infrastructure has profiled your internet-facing estate for up to a decade, and that sibling infrastructure (e.g. the JDY botnet, which Lumen reports has more than doubled in size since the KV botnet takedown) remains live.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 18: classification of ICT-related incidents and cyber threats The FBI affidavit alleges QTFY's customers targeted financial institutions specifically, and QTFY exploited perimeter VPN/edge CVEs (Pulse Secure CVE-2019-11510, Citrix CVE-2019-19781, Ivanti CSA zero-day) against financial-sector victims — a named cyber threat to this sector. Clients with historically exposed Pulse Secure/Citrix/Ivanti edge devices should classify any historical compromise indicators under this threat as a potential ICT incident and drive the Art. 18 classification decision with that context.
DORA Art. 24: digital operational resilience testing — general requirements QScan is a purpose-built distributed vulnerability scanner whose database holds nearly a decade of internet scan results used to re-target victims when new vulnerabilities emerge. Treat this as external evidence that your internet-facing estate has been continuously scanned by adversary tooling; scope Art. 24 testing to the edge-device classes QTFY demonstrably exploited (VPN/remote-access appliances, IoT).

No NIS2 or UK NIS article is directly engaged by this item beyond generic incident/patching duties that would apply to any advisory.

3. Technical analysis & attack chain

How the operation worked. QTFY ran a two-part service model. QScan was a distributed vulnerability scanning system used to find and scan target networks and identify vulnerable IoT devices for co-option into QTFY's botnets; per the FBI/NSA joint advisory it populates a database containing nearly a decade of internet scanning, used both for victim-specific targeting and to rapidly identify targets when new vulnerabilities are disclosed. QTRouter was a covert communications platform that obfuscated the Chinese origin of traffic by routing it through compromised IoT devices; The Register adds that the QTRouter botnet mixed compromised IoT devices, commercial proxy service devices, and leased VPSes, and was available to paying customers beyond QTFY itself. Both platforms had hard-coded command domains — qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com — which is precisely what made them susceptible to court-authorised seizure: a US federal court granted warrants on Monday 24 August 2026 and the seizures made both services inoperable. For traffic backhaul into China, QTFY purchases "high-tier corporate subscriptions" to the Chinese commercial VPN service Fastlink (per Lumen), apparently because buying relays is cheaper than compromising and managing more devices.

Confirmed exploitation history (from FBI court documents, via The Register)

  1. Aug 2019 — NASA attempted intrusion: QTFY-linked actors attempted to exploit CVE-2019-11510 (critical Ivanti Pulse Secure VPN flaw allowing attackers to read legitimate users' usernames and passwords, granting unauthorised access to protected networks; patched by Ivanti April 2019). The same CVE was separately abused as a zero-day against dozens of defence companies, government agencies and financial organisations in the US and abroad.
  2. 2020 — Ohio medical centre: QTFY exploited the same CVE-2019-11510 during the COVID-19 pandemic.
  3. 2019–2020 — financial and insurance victims: unnamed financial groups in Michigan and South Korea; a Missouri insurance agency compromised via CVE-2019-19781 (critical Citrix VPN flaw permitting arbitrary code execution with no account credentials).
  4. 2024 — DOE National Laboratories, NIH, a US security device manufacturer: victims of a zero-day attack against the Ivanti Cloud Services Appliance.
  5. As recently as 2026 — US Senate compromised via QTFY infrastructure.

Ecosystem context. This is the third PRC state-linked botnet disrupted by the US since December 2023: the KV botnet (active since at least February 2022, used by Volt Typhoon, MITRE G1017, for critical-infrastructure access with potential sabotage intent — disrupted December 2023); Raptor Train (formed May 2020, attributed by DoJ to Flax Typhoon — attribution unconfirmed, no ATT&CK profile — disrupted September 2024); and now QScan/QTRouter. Lumen reports that since the KV disruption, the sister JDY botnet has more than doubled in size — disruption is not degradation of capability at ecosystem level. Raptor Train was likewise attributed to a Chinese technology company, reinforcing the commercial-sector outsourcing model.

Confidence caveats. The QTFY/Nanjing Xinjiuwei attribution, the MSS payment relationship, and the claim that QTFY actors are former PLA members all rest on a single FBI affidavit as reported by one outlet (The Register) — single-sourced; verify against the primary affidavit and FBI/NSA advisory before treating as settled. The FBI declined to answer whether QTFY has ties to any of China's "Typhoon" groups; do not conflate QTFY with Volt Typhoon. The Qilin/ATF claim in the source newsletter is a separate, unconfirmed extortion claim — the ATF has not confirmed the stolen data was genuine, and Qilin has no ATT&CK profile; treat as unconfirmed.

4. Mitigation & containment

This is a disruption of adversary infrastructure, not a patch event. Actions are retrospective exposure review and forward defence against surviving sibling infrastructure.

P1 — within 24h

  • Block and sinkhole-alert on the three seized domains — qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com — at DNS resolver and proxy egress. Seizure makes the services inoperable, but any observed resolution attempts from your estate indicate historical QScan/QTRouter implant or relay activity and must be escalated as a suspected compromise, not merely blocked.
  • Hunt your estate for the edge-device classes QTFY demonstrably exploited: Pulse Secure VPN (CVE-2019-11510), Citrix VPN (CVE-2019-19781), Ivanti Cloud Services Appliance (2024 zero-day). Any of these deployed and internet-exposed between 2019 and 2024 should be treated as presumptively scanned by QScan's database and triaged for historical compromise.

P2 — within 72h

  • Review authentication logs from the affected appliance eras for the specific CVE-2019-11510 failure mode: credential/username disclosure followed by anomalous authentications from residential or IoT-adjacent IP space (consistent with QTRouter's compromised-IoT relay model, which makes traffic appear to originate locally).
  • Inventory IoT and network-periphery devices for unexplained outbound connections; QScan's function was co-opting vulnerable IoT into relay botnets, so unmanaged IoT is both a scanning target and a potential relay.
  • If historical compromise of a financial-sector entity is confirmed, feed the finding into your DORA Art. 18 classification process (see §2).

P3 — within 7 days

  • Reduce the internet-facing attack surface that QScan-style scanning monetises: remove remote-access appliances from direct internet exposure, enforce MFA on all VPN/remote access, and allowlist source IPs for administrative access — the same remedial controls CISA recommended for the water sector apply to any poorly-defended edge.
  • Assume the disruption is temporary: Lumen reports the JDY botnet has more than doubled since the KV takedown. Do not stand down monitoring for compromised-IoD relay traffic patterns after this seizure.

5. Indicators of compromise

Type Value Confidence Source
domain qtproxy[.]xyz High — court-seized, per DoJ The Register / DoJ
domain qt-proxy[.]org High — court-seized, per DoJ The Register / DoJ
domain qt-team[.]com High — court-seized, per DoJ The Register / DoJ
service Fastlink (Chinese commercial VPN, "high-tier corporate subscriptions" used for backhaul) Medium — single vendor (Lumen) assessment Risky Biz / Lumen
domain  qtproxy[.]xyz
domain  qt-proxy[.]org
domain  qt-team[.]com

Note: the source material names no malware file hashes, sample names, or additional C2 infrastructure beyond the three seized domains. The Fastlink VPN relationship is a behavioural/infrastructure observation, not an atomic indicator, and is excluded from the copyable block.

Behavioural indicators

Behaviour Where to observe Confidence
DNS resolution attempts to the three seized QTFY domains DNS resolver logs, proxy logs, EDR network telemetry High — domains confirmed hardcoded in both QScan and QTRouter malware
Intrusion traffic appearing to originate from local/residential IPs (compromised-IoT relay obfuscation) VPN/remote-access authentication logs, geo-vs-ASN mismatch analysis Medium — consistent with QTRouter's documented purpose
Sustained adversary scanning of internet-facing estate feeding a multi-year target database Perimeter IDS/WAF, internet-facing appliance logs High — QScan's core documented function

6. Detection

rule QTFY_QScan_QTRouter_SeizedDomains {
    meta:
        author = "Adverse Trace"
        date = "2026-09-03"
        reference = "https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742"
        description = "Detects QTFY QScan/QTRouter malware by hardcoded C2 domains reported in FBI court documents"
    strings:
        $d1 = "qtproxy.xyz" wide ascii
        $d2 = "qt-proxy.org" wide ascii
        $d3 = "qt-team.com" wide ascii
    condition:
        2 of them
}
title: DNS resolution of seized QTFY QScan/QTRouter domains
id: 7a1c9f3e-2b4d-4e8a-9c5f-1d3b7a6e2f08
status: experimental
description: >
    Detects DNS queries for the three domains hardcoded into QTFY QScan and
    QTRouter malware and seized by court order on 2026-08-24. Any resolution
    attempt indicates likely historical implant or relay activity.
references:

    - https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742
    - https://news.risky.biz/srsly-risky-biz-chinas-private-sector-botnets-are-worth-disrupting/
author: Adverse Trace
date: 2026-09-03
logsource:
    category: dns
detection:
    selection:
        query|endswith:

            - 'qtproxy.xyz'
            - 'qt-proxy.org'
            - 'qt-team.com'
    condition: selection
falsepositives:

    - Post-seizure sinkhole banner pages served on the seized domains
level: high

Threat actor context

Volt Typhoon · G1017 · aka BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. …

No MITRE ATT&CK profile for: QTFY, Flax Typhoon, Qilin, Nanjing Xinjiuwei Network Technology.

7. Sources

  • Risky Business News — Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting — https://news.risky.biz/srsly-risky-biz-chinas-private-sector-botnets-are-worth-disrupting/ — 2026-09-03
  • The Register Security — FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks — https://www.theregister.com/security/2026/08/27/fbi-seizes-hacking-tools-it-says-china-used-to-attack-nasa-doe-us-senate-and-other-critical-networks/5292742 — 2026-08-27

8. Adverse Trace position

This is a strategically significant but operationally partial disruption. The seizure of QScan and QTRouter removes a decade-deep adversary scanning database and a compromised-IoT obfuscation network from PRC state-linked use — but the pattern across KV, Raptor Train and QTFY shows rebuild cycles measured in months, and Lumen's reporting that the JDY botnet has more than doubled since late 2023 indicates the ecosystem is resilient to takedowns. For EMEA financial services the material exposure is retrospective: QTFY demonstrably targeted financial institutions using perimeter-appliance CVEs (Pulse Secure, Citrix, Ivanti CSA), and any client that ran those devices internet-exposed in the 2019–2024 window should now assume their estate was catalogued and hunt accordingly — this is a DORA Art. 18 classification input where compromise evidence emerges. Attribution confidence is moderate: the QTFY/Nanjing Xinjiuwei/MSS relationship is single-sourced from the FBI affidavit as reported by one outlet, and neither QTFY, Nanjing Xinjiuwei, Flax Typhoon nor Qilin has a MITRE ATT&CK profile — only Volt Typhoon (G1017) is a confirmed tracked actor in this story. We will monitor for the primary FBI/NSA joint advisory and Lumen's technical report on the broader QScan/QTRouter system, and will issue updated IOCs and detection content if implant-level artefacts (hashes, sample names, additional C2) are published.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies