{"id":16662,"date":"2026-09-02T08:31:22","date_gmt":"2026-09-02T08:31:22","guid":{"rendered":"https:\/\/newestek.com\/?p=16662"},"modified":"2026-09-02T08:31:22","modified_gmt":"2026-09-02T08:31:22","slug":"how-china-industrialized-the-infrastructure-behind-state-hacking","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16662","title":{"rendered":"How China industrialized the infrastructure behind state hacking"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Last week, the <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers\">US Justice Department and FBI announced<\/a> court-authorized seizures of domains hard-coded into two complementary hacking platforms known as \u201cQScan\u201d and \u201cQTRouter,\u201d used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.<\/p>\n<p class=\"wp-block-paragraph\">A People\u2019s Republic of China (PRC) state-sponsored group known as \u201cQTFY,\u201d employed by a corporation called China-based <a>Nanjing Xinjiuwei Network Technology Company, <\/a>created and operated QScan and QTRouter.<\/p>\n<p class=\"wp-block-paragraph\">Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and US Senate.<\/p>\n<p class=\"wp-block-paragraph\">The law enforcement agencies said QTFY offers computer hacking services to its paying customers, including the PRC\u2019s Ministry of State Security and the People\u2019s Liberation Army. The hacking services include QScan and QTRouter, with QScan scanning and automatically infecting thousands of internet-of-things (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against US government agencies, power companies, telcos, and major hospital systems,\u201d FBI cyber assistant director <a href=\"https:\/\/www.fbi.gov\/video-repository\/fbi-and-doj-announce-botnet-disruption-082626.mp4\/view\">Brett Leatherman said<\/a>. \u201cQTFY operates within a complex network of hackers-for-hire and government clients in the People\u2019s Republic of China.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The FBI has a long track record of taking down hacking activities of the PRC. Previous actions include removing PlugX surveillance malware from over 4,000 US computers after they had been infected by the PRC-sponsored hacking group Mustang Panda.<\/p>\n<p class=\"wp-block-paragraph\">In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government. In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of US and foreign critical infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">What distinguishes QTFY is the breadth of the shared service it allegedly provided, combining reconnaissance, exploitation capabilities, routing, and obfuscation infrastructure for multiple offensive teams. \u201cIt\u2019s an effective tool to impact multiple offensive hacking teams at one time because they\u2019re using this service,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/dakotacary\/\">Dakota Cary<\/a>, a China-focused consultant at SentinelOne, tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s kind of like a choke point, where you have a bunch of teams using the same network to carry out offensive operations,\u201d he says. \u201cIf you take down that network, they all have to go find new infrastructure to obfuscate their activity.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-quartermaster-model-of-hacking\">The quartermaster model of hacking<\/h2>\n<p class=\"wp-block-paragraph\">For a year prior to the takedown, Lumen\u2019s Black Lotus Labs tracked QTFY as it functioned as a \u201cquartermaster,\u201d integrating reconnaissance, proxy orchestration, and operational routing into \u201ca reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe were able to see the direct targeting of certain things,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/damonrouse\/\">Damon Rouse<\/a>, senior lead information security engineer at Black Lotus Labs, tells CSO. \u201cAnd then from that, we were able to find their scanning framework, their application called QScan. And then we were starting to really do some correlation between QScan activity and then follow-on activity from the proxy network called Fast Labyrinth.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Rouse likened Nanjing Xinjiuwei\u2019s role to that of a defense contractor. \u201cThere\u2019s a ton of these companies in China that are usually started directly after people leave the PLA,\u201d he says. \u201cBecause of their connections to the PLA, they have a specialized status to do certain things for the PRC government. And it gives the government plausible deniability because it\u2019s not actually coming from their units.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"china-has-marketized-state-hacking\">China has marketized state hacking<\/h2>\n<p class=\"wp-block-paragraph\">Nanjing Xinjiuwei\u2019s private-contractor role illustrates how Beijing draws operational capacity from a broader commercial ecosystem.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe company knows that they\u2019re facilitating offensive operations for hackers,\u201d SentinelOne\u2019s Cary says. \u201cThis business exists because the hacking teams have a need for this type of infrastructure, and China has been really good at using capitalism to create a lot of its infrastructure for cyber operations.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The FBI in its investigations was able to track the flow of this marketized state hacking system. \u201cThe FBI is amazing at following the money and creating very elaborate maps of customers and payments and all kinds of good stuff,\u201d Lumen\u2019s Rouse says. \u201cThat\u2019s how they were able to out a lot of these very high-end clients of this company, including PLA units, MSS units and other very, very well-connected Chinese companies that are in the infosec hacking space.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In short, China has cultivated a market of private contractors supplying specialized capabilities to state hacking teams. \u201cThey\u2019ve been very effective at using market incentives in order to facilitate the development of business that meets their operational needs,\u201d Cary says.<\/p>\n<h2 class=\"wp-block-heading\" id=\"efficiency-creates-the-choke-point\">Efficiency creates the choke point<\/h2>\n<p class=\"wp-block-paragraph\">This market-like efficiency gives Beijing scale, speed, and plausible deniability. But it also concentrates risk, making it easy for US law enforcement to knock out one shared service, forcing every team that uses it to scramble for new infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">However, the operation does not provide a permanent answer to China\u2019s reliance on private companies and shared infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">Even though stealthier residential and commercial proxy networks have replaced the old \u201cwhack-a-mole\u201d model, \u201cIt would be naive to say that there\u2019s not going to be another company or another 10 companies that are doing something very similar to this to either pick up their slack or to replace them,\u201d Rouse says.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s even possible that Nanjing Xinjiuwei could stick around, the way a Chinese cybersecurity firm, Chengdu 404, <a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1317206\/dl\">indicted<\/a> by US and international authorities as a front company for the state-sponsored hacking group APT41 has done.<\/p>\n<p class=\"wp-block-paragraph\">\u201cChengdu 404 is a really good example,\u201d Cary says. \u201cThey got indicted, and it was very clear the DOJ and FBI were like, \u2018We know who you are. We know where you work. We know where you live.\u2019 Chengdu 404 is still in business. They still operate out of the same address. They don\u2019t care.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, Cary contrasts the situation with i-Soon, a Shanghai-based private cybersecurity contractor <a href=\"https:\/\/www.sentinelone.com\/labs\/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations\/\">that carried out<\/a> large-scale, state-sponsored hacking and espionage operations for Chinese government agencies. \u201cOn the other end of the spectrum is i-Soon, where i-Soon had those leaks in February of \u201924, and they completely shut down,\u201d he says. \u201cI mean, they closed all their offices. They were done, done, done.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-lessons-for-cisos\">The lessons for CISOs<\/h2>\n<p class=\"wp-block-paragraph\">One of the top operational lessons to come out of this latest action is that geography- and reputation-based IP blocking are increasingly inadequate because Chinese state-sponsored activity appears to originate from seemingly ordinary devices and legitimate commercial infrastructure outside China.<\/p>\n<p class=\"wp-block-paragraph\">The broader QTRouter and Fast Labyrinth obfuscation infrastructure routed traffic through small office routers and IoT devices, commercial proxy infrastructure, leased virtual private servers, and dynamically rotating IP addresses, undermining geography-based and reputation-based blocking.<\/p>\n<p class=\"wp-block-paragraph\">As FBI\u2019s Leatherman said, \u201cInstead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries \u2014 potentially through systems just down the street from the victim\u2019s own network.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Rouse warns that malicious Chinese traffic could look \u201clike it\u2019s traffic originating from the United States from, for example, Charter Communications. It makes it very difficult to see that that\u2019s nefarious.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Experts point CISOs beyond reliance on IP origin and reputation, emphasizing behavioral visibility, tighter edge security, and a clear baseline of legitimate traffic.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEven if the device or the IP address doesn\u2019t resolve to an ASN in China, that doesn\u2019t mean it\u2019s not malicious,\u201d Cary says.<\/p>\n<p class=\"wp-block-paragraph\">Rouse advises CISOs, \u201cMake sure [perimeter devices are] patched; make sure your patching life cycles are shortened to as short of time as possible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He adds, \u201cMake sure you have adequate logging around your firewalls, your perimeter, and look for traffic from residential things. If you have that kind of baseline, you have an understanding of what the traffic should look like, and you can really do a better job at looking at the anomalies.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as \u201cQScan\u201d and \u201cQTRouter,\u201d used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks. A People\u2019s Republic of China (PRC) state-sponsored group known as \u201cQTFY,\u201d employed by a corporation called China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16662\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16662","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16662"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16662\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}