The QTFY Hunt: How Chinese Hackers Were Tracked and How the Internet Became the Sensor

theclu5ter
theclu5ter@theclu5ter
August 29, 2026 · 13 min read
TL;DR

QTFY worked as an infrastructure quartermaster for MSS and PLA customers, selling reconnaissance, access and cover traffic as reusable services. Its egress blended into a commercial Chinese proxy service, so endpoint telemetry saw nothing. Backbone telemetry saw the campaign anyway. What ended it was positional visibility, tradecraft failure, and three domains compiled into both platforms that could be seized at the registry level.

Key judgements

  • QTFY is better understood as an infrastructure quartermaster than a conventional hacking group: its role appears to be providing reconnaissance, access and obfuscation capabilities as reusable services to multiple state customers.
  • Much of its concealment capability appears to have been procured rather than built through compromise. Espionage traffic was routed through subscriptions to a commercial Chinese proxy service, allowing it to blend into ordinary consumer traffic rather than relying on obviously malicious infrastructure.
  • That model exposes the limits of static blocking and endpoint telemetry. The activity was difficult to distinguish from legitimate traffic. What ultimately made it visible was positional visibility: the ability to spot a small, targeted campaign within a much larger volume of legitimate background activity.
  • The broader implication is a changing threat-intelligence market. Advantage is shifting away from simply having the largest database and toward having the right sensors in the right places. Infrastructure operators are increasingly in a position to observe threats first-hand and then feed those observations back into the intelligence products built around their own visibility.

On 26 August 2026 the U.S. Department of Justice and the FBI seized three domains and disabled two hacking platforms built by a Chinese state-sponsored group. The operational story is straightforward. The structural story, how a distributed, deliberately non-attributable network was tracked at all, is the one worth reading.

Sourced from DOJ court filings, the FBI/NSA/CNMF joint advisory JCSA-20260826-01, and Black Lotus Labs research.

The takedown, in brief

On 26 August 2026 the U.S. Department of Justice and the FBI announced the court-authorised seizure of three domains qtproxy.xyz, qt-proxy.org and qt-team.com which was used to run two linked hacking platforms known as QScan and QTRouter.

The same day, the FBI, NSA and Cyber National Mission Force published a joint advisory on the group behind them, while Lumen Technologies Black Lotus Labs published a year of tracking on the same infrastructure.

QTFY built its system around a simple objective: make its traffic appear to come from somewhere other than China. For years, it largely worked.

But there was one thing it could not hide: the traffic itself.

That distinction between concealing where an operation originates and concealing the fact that the operation exists at all is increasingly where modern threat intelligence gets its advantage. Attribution may remain difficult, but visibility is often enough to expose the operation.

What the record establishes

Court documents unsealed in the Southern District of California describe QTFY as a People's Republic of China state-sponsored group that developed and operated QScan and QTRouter, selling access to paying customers that included China’s Ministry of State Security (MSS) and the People's Liberation Army (PLA).

Its named victims include NASA, The Federal Reserve, The Department of Energy, The Department of Justice, The Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

The joint FBI/NSA/CNMF advisory provides a more detailed picture. It attributes QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), a company established in 2018, and describes it as an enabling company inside the People's Republic of China's cyber contractor ecosystem with business relationships to MSS units, provincial bodies and other China-based security firms.

QTFY personnel are described as including former PLA members who used those relationships to win contracts and subcontracts, and as active participants in Chinese freelance brokering networks where exploits and network access are bought and sold.

That is the headline finding: QTFY was not simply deploying malware. It was operating within a supply chain.

The architecture

Public reporting uses two overlapping vocabularies for the same system. Separating them matters, because they describe different layers.

Diagram of the QTFY operating model. A reconnaissance layer shows QScan built from a RabbitMQ task broker, a distributed scanner fleet rotating /24 blocks every 30 days, a Redis result backend and a target library of 200 plus Python exploits. An access and control layer shows customers such as MSS units and PLA linked entities connecting through QTRouter devices to the QTProxy admin plane. An obfuscated transit layer shows the Fast Labyrinth relay mesh combining a co-opted commercial proxy, compromised IoT devices and leased VPS addresses leading to victim networks.
Fig 1: The QTFY operating model. Reconnaissance, access control and obfuscated transit sold as a service layer.

  • QScan was the scout a distributed scanning and exploitation platform running task queues over RabbitMQ with results collected into Redis, worker nodes on leased servers outside China rotating across /24 blocks every thirty days. Its queues covered webpage scraping, TLS certificate collection, subdomain enumeration and penetration testing, backed by a library of more than 200 Python proof-of-concept exploits. On one day in 2024 it processed over two million scanning and exploitation tasks. Calling it a scanner undersells it considerably.
  • QTRouter was the access layer: physical router devices issued to customers, through which they authenticated and chained proxy nodes together. The management plane, hosted at qtproxy.xyz and branded internally as a Proxy Node Management System, authenticated those devices and served them node lists. Underneath sat a separate Proxy Pool Management System that aggregated compromised IoT devices and held both an exploit database and a database of server fingerprints, used to find new devices to compromise whenever fresh proxy capacity was needed.

The surprising part

The single most interesting technical finding in this case is not a piece of malware. It is a procurement decision.

In mainland China, an “Airport” (机场) commonly refers to a commercial tiered subscription based proxy service, often sold to consumers seeking to circumvent the Great Firewall. These are not shady operations. They are professionally run, high-bandwidth international transit services with large legitimate user bases, managed through clients like Clash or Shadowrocket.

Rather than relying exclusively on compromised devices to assemble a relay mesh, the QTFY operation appears to have procured the high-tier commercial proxy service fastlink.ws and selectively co-opted specific egress nodes, identifiable by their flanycast and flnode subdomains on yotocloud.com. Operational traffic could therefore blend into infrastructure carrying a large volume of legitimate consumer traffic.

I would treat a claim like that carefully if it came from one source, but it does not. Black Lotus Labs identified the co-opted nodes from backbone telemetry, while the FBI affidavit independently placed Fastlink among the observed QTRouter node types, with the government's own network diagram labelling one of three node classes “airport (机场) commercial proxy” alongside VPS and compromised IoT.

The two records point to the same underlying phenomenon from different vantage points.

So how was it seen at all?

This is where the vantage point does the work that no product could.

The vast majority of traffic on that relay network looked exactly like an ordinary consumer VPN user, because most of it was one. Separating that high volume background out is what left something worth looking at: a narrow, patient profiling campaign aimed at research universities working in advanced physics, bioinformatics, aerospace and satellite systems, at defence and public-sector networks, and at exposed development perimeters and unpatched cloud storage.

Two distinct behaviours were visible in it. Against hardened federal and military ranges, the operators ran broad perimeter sweeps that mostly hit rigid filtering and returned very little, but which, run for long enough, catalogue boundary interfaces and configuration drift. Against high-value scientific and corporate targets, the loud scanner was switched off in favour of quiet application-layer probing tuned to fingerprint operating systems and map remote management interfaces.

The critical correlation was the overlap. Most of the high-value networks QScan had profiled were later seen processing inbound connections from Fast Labyrinth proxies inside the same tracking window. Reconnaissance and operations were tethered to the same objectives. And at the other end, the administrative check-in logs showed sessions from China Telecom and China Unicom address space in Nanjing, interleaved with sessions coming from the co-opted commercial nodes themselves, the operators testing their own relays before leasing them out.

No single victim's logs could establish any of that. Separating a low-volume targeted campaign from high-volume consumer noise crossing the same egress nodes requires seeing both at once, over months.

WHY THIS BREAKS THE USUAL DEFENCES

The concealment layer did not depend on compromising the networks or managed endpoints being targeted. There was therefore little for conventional endpoint tooling to see. And because Airport node registries rotate automatically through client subscription URLs, the egress IP pool kept moving without the operator lifting a finger, so blocklists could age out faster than defenders could reliably maintain them.

The traffic was legitimate. The intent was not. Obfuscation had become a procurement problem rather than an engineering one, and procurement leaves no malware behind to find.

Diagram titled Obfuscation does not delete evidence, it relocates it. Six concealment steps are paired with the artefact that survives each one: hiding origin still leaves an exit proxy IP, rotating the IP still leaves a routing autonomous system, ordinary looking traffic still resolves a control plane domain, replacing domains still leaves naming schemes and certificate history, encrypted payloads still leave session timing and TLS fingerprints, and disposable assets still leave relationships between them.
Fig 2: Each concealment step displaces the observable artefact rather than eliminating it.

Lumen did not need to own the attacker's infrastructure. It needed visibility into the relationships around it, and that turns out to be the harder thing to acquire.

What if you sit somewhere else?

That is the question I could not put down while reading this. If a backbone operator can derive intelligence from what it happens to see, what can everyone else see from their own positions? Different positions resolve different parts of the same operation.

The internet is not one network. A backbone provider sees transit. A cloud provider sees what happens inside its own tenancy. A DNS resolver sees resolution behaviour at population scale. An edge provider sees requests arriving at applications, along with client-side artefacts the attacker cannot easily suppress. The same adversary leaves different traces at each layer, and no single layer necessarily sees the whole operation.

Diagram titled Infrastructure as sensor, who sees what. Five stacked layers: endpoint and EDR observes process execution but sees nothing when activity never reaches a managed host. Application edge such as CDN, reverse proxy and WAF observes HTTP structure, probed URL paths, TLS and JA3/JA4 fingerprints, which survive IP rotation. DNS resolvers observe resolution behaviour at population scale even when payload traffic is invisible. Cloud providers observe activity inside their own tenancy, the staging estate but not the transit. The network backbone observes transit flows and netflow and can separate a low volume targeted campaign from high volume consumer noise on the same nodes.
Fig 3: Five positions in the stack, and what each can and cannot resolve.

Which brings me to Cloudflare, and to a finding I did not expect when I started reading.

The one edge touchpoint in the record

At the traffic layer described in the public record, QTFY’s estate does not appear to have been behind a content-delivery or reverse-proxy edge. The affidavit records www.qtproxy.xyz resolving to 156.234.193.18 in October 2024, the same address used to reach all six victims of the September 2024 Ivanti zero-day campaign. Black Lotus Labs, tracking a later period, places the panel at 1.32.216[.]171. Both are direct origin addresses, not anycast. Neither published snapshot catches the estate behind a content delivery network. There is one documented exception, and it sits somewhere else entirely.

Paragraph 28(b) of the affidavit, at page 9, records that qtproxy.xyz was also registered at Cloudflare with the email account [email protected], which the filing identifies as the recovery email for [email protected], a QTFY account investigators had already searched under warrant in November 2020 and January 2021.

Namecheap is named as domain registrar; Cloudflare is simply where the domain was “also registered.” The registrar of record was Namecheap, established separately at paragraph 38. What paragraph 28(b) most plausibly describes is an account to which the zone had been added.

Diagram titled The registration pivot. Four boxes linked left to right: qtproxy.xyz, the seized domain hosting the QTProxy admin plane, its registrar record, a Cloudflare registration made alongside the Namecheap registrar record, the account email newtimebiz@outlook.com on that registration, and caiwenbai18@gmail.com, the recovery email for that account and a QTFY account already searched under warrant. Source noted as FBI affidavit page 9 paragraph 28b.
Fig 4: A provider's account record joining a seized domain to an already-identified operator account.

So, did Cloudflare play a role in the investigation? In one narrow and documented sense, could be: as the custodian of a subscriber record obtained through legal process, which closed an identity loop the FBI was already working. That is real investigative value and it came from the edge.

But it is account data, not network observation. That distinction matters. Knowing who controlled a domain is fundamentally different from observing the traffic that domain carried. The FBI did not learn this by watching traffic. Whether the zone was ever proxied through the edge (which would imply request-level visibility into traffic reaching the adversary’s control panel) or merely resolved through Cloudflare remains unresolved in the public record, and the resolution history points toward the latter. There is no public evidence that any edge provider observed QTFY traffic, detected the activity, or supplied threat intelligence to anyone here.

I keep coming back to that gap, because it is the most honest thing this case has to teach. A provider knows whether it saw something. Nobody outside can check.

Where SSL/TLS actually fits

This also puts a familiar argument in its place. A malicious site can hold a perfectly valid HTTPS certificate; a certificate proves cryptographic control of a domain and nothing about the operator's intent. Issuance is not endorsement, and the public record here provides no evidence that certificate issuance was itself part of the abuse or that providers monetised it. What QTFY adds is the inversion. Certificate data was a collection target for the attacker. QScan ran a dedicated task queue for TLS certificate collection alongside subdomain enumeration and CMS plugin fingerprinting, and the affidavit's own footnote notes why: certificates can tell an attacker about the software or device type behind an IP address.

Certificates can function as correlation inputs, and both attackers and defenders can use them that way. Certificate to domain, domain to DNS, DNS to IP, IP to traffic, traffic to related infrastructure, and infrastructure to behaviour. The chain is the intelligence. No single link is.

The flywheel

Once infrastructure becomes a sensor, something else follows: the intelligence can be pushed back into the infrastructure that produced it.

Cloudflare is unusually open about this. Its threat events platform is presented as real-time intelligence derived from telemetry on its own network. Its March 2026 engineering write-up describes subscribers using tokens to task Cloudforce One analysts with investigations, with resulting intelligence (including new indicators, actor attributions and campaign notes) fed back into the broader platform. The WAF documentation then describes matching incoming requests against indicators in that database, including known threat actors and targeted industries, and using those signals in firewall and rate-limiting rules.

Diagram titled The intelligence flywheel. A circular loop of five stages: operate infrastructure, observe activity, correlate signals, produce and sell intelligence, enforce in the network, then back to operating infrastructure. Each turn improves the next, as findings from analyst investigations are written back into the feed and the feed is applied as enforcement in the same network that produced the observation.
Fig 5: Observation, analysis, sale and enforcement close into a loop inside a single operator.

Lumen runs a structurally similar loop between Black Lotus Labs and its own defence products, and demonstrated the enforcement half in this very case by null-routing traffic to the quartermaster's infrastructure. The same network carries the traffic and learns from it, and the second business is subsidised by the first.

What QTFY actually teaches

Three separate factors contributed to ending this operation and I think keeping them apart matters more than any single one of them.

The first was positional visibility, the backbone telemetry described above. The second was tradecraft failure, and the operators supplied plenty. A single Gmail account registered the hosting account that leased the attack servers, so abuse complaints from affected organisations landed in the operator's own inbox: a South Korean financial group writing in November 2019 that its infrastructure was a designated national security objective facility, an Ohio medical centre adding in August 2020 that attacking healthcare during a pandemic was wrong and asking the host to enforce its terms of service. Registration emails for the seized domains were recovery addresses for accounts already under warrant. The company's own name appears in the infrastructure list, as xinjiuwei[.]net. Infrastructure was rotated, but elements of the naming and operational pattern persisted. qt-team.com became qt-proxy.org in December 2025 with the naming scheme carried across intact.

The third was a legal instrument. All three domains were hard-coded into both platforms for communication and authentication (compiled in, not resolved from a configurable registry), so seizing them killed both at once. The seizure warrants were instead supported by a money-laundering theory: the affidavit points to registration payments of $85.70 and $43.83 travelling from China to U.S.-based registrars. The warrants were then served on the registries rather than the registrars, targeting the entities that controlled the relevant domain registrations.

None of the three is a security product. One is a vantage point, one is human error, and one is jurisdiction over commercial intermediaries.

Which is worth sitting with. Attackers can distribute infrastructure, but they still have to operate it, pay for it and log into it, and every one of those acts leaves a record with somebody who is not them.

The new threat-intelligence game

The old model of this industry can be summarised as: find malicious indicators, put them in a database, distribute the database. The emerging one runs differently. Operate infrastructure, observe activity, correlate signals, generate intelligence, defend the network, and observe again with better priors.

The difference is not product quality. It is position. A conventional vendor has to acquire its data by buying feeds, running sensors and licensing telemetry from whoever holds it. An operator of infrastructure already sits where the observations occur and pays for that position out of an entirely separate revenue line. Visibility can therefore become a byproduct of carrying traffic, an advantage that is difficult for organisations without comparable network position to replicate.

This is bigger than any one company. Lumen illustrates it from the backbone and Cloudflare from the edge, but Microsoft, Google, Amazon and the large endpoint vendors each run their own sensor estates across cloud, email, endpoints and networks. Each sees a different slice of the same adversary.

What follows from that is not a conspiracy, and I would resist writing it as one. It follows from the shape of the network. But three consequences seem hard to avoid. Attribution is increasingly dependent on telemetry that third parties cannot inspect or reproduce, because findings like these can rest on proprietary commercial visibility and the DOJ cited that research alongside its own indicators. The organisations observing the threat and the organisations operating the infrastructure through which that threat moves are increasingly drawn from the same commercial ecosystem., which makes decisions about what to publish and when a commercial matter rather than a public one. And the vantage points are few and concentrated in one jurisdiction, which is also, not coincidentally, why this seizure worked at all.

So the competitive question for the next decade is probably not who holds the largest threat-intelligence database. Static indicators increasingly decay as infrastructure rotates, making timely observation and correlation more valuable. The question is narrower and considerably less comfortable.

Who owns the sensors?

QTFY spent years trying to disappear inside the internet. The researchers who found it did the opposite. They used the internet itself to look. The infrastructure that was built to move information is quietly becoming the system that reveals who is moving it, and the small number of companies standing closest to it are the ones who get to say what they saw.

What the record does and does not establish

Documented

QTFY's attribution to Nanjing Xinjiuwei and its MSS and PLA relationships; the use of infrastructure associated with the fastlink.ws commercial proxy service, corroborated independently by the affidavit and Black Lotus Labs; QScan's architecture and scale; the hard-coded domain dependency and registry-level seizure; the money-laundering basis for the warrants; the Cloudflare account registration and its pivot to an already-searched operator account at ¶28(b); Cloudflare's own published description of its telemetry-to-product loop.

Argued

That these are instances of one emerging model, and that advantage in threat intelligence is shifting from database scale to sensor placement, with attribution becoming correspondingly unauditable. This is interpretation, not a finding. It is falsifiable: if research houses without infrastructure keep producing primary attribution at the same rate as carriers and edge providers, the thesis weakens.

Not established

That Lumen and Cloudflare collaborated, exchanged QTFY-specific intelligence, or that any edge provider observed QTFY traffic, detected the activity, or contributed QTFY-specific threat intelligence to the DOJ action. A subscriber record disclosed under legal process is not a network observation. Whether qtproxy.xyz was ever proxied rather than merely resolved remains open.

Contested

China's foreign ministry has rejected the U.S. characterisation. The affidavit's assertions are government allegations supporting a seizure warrant, not findings against a named defendant.

Sources

  • Affidavit in Support of Applications for Seizure Warrants, U.S. District Court for the Southern District of California, sworn 24 August 2026, unsealed 26 August 2026 (17 pp.).
  • U.S. Department of Justice, Office of Public Affairs, press release 26-972, 26 August 2026.
  • FBI / NSA / Cyber National Mission Force, Joint Cybersecurity Advisory JCSA-20260826-01, 26 August 2026; indicators at ic3.gov.
  • Lumen Technologies, Black Lotus Labs, “The infrastructure quartermaster: inside a China-nexus state enablement model,” 26 August 2026.
  • Cloudflare, threat events platform announcement, 18 March 2025; “Evolving Cloudflare's Threat Intelligence Platform,” March 2026.