微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接。
How China industrialized the infrastructure behind state hacking
RSS 官方收录 · 可信分层展示
关键摘要
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…
- A People’s Republic of China (PRC) state-sponsored group known as “QTF…
- Among the targets of QTFY are the National Aeronautics and Space Admin…
- The law enforcement agencies said QTFY offers computer hacking service…
摘要引擎:抽取
正文提要
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.
A People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by a corporation called China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.
Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and US Senate.
The law enforcement agencies said QTFY offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. The hacking services include QScan and QTRouter, with QScan scanning and automatically infecting thousands of internet-of-things (IoT) devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices.
“For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against US government agencies, power companies, telcos, and major hospital systems,” FBI cyber assistant director Brett Leatherman said. “QTFY operates within a complex network of hackers-for-hire and government clients in the People’s Republic of China.”
The FBI has a long track record of taking down hacking activities of the PRC. Previous actions include removing PlugX surveillance malware from over 4,000 US computers after they had been infected by the PRC-sponsored hacking group Mustang Panda.
In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government. In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of US and foreign critical infrastructure.
What distinguishes QTFY is the breadth of the shared service it allegedly provided, combining reconnaissance, exploitation capabilities, routing, and obfuscation infrastructure for multiple offensive teams. “It’s an effective tool to impact multiple offensive hacking teams at one time because they’re using this service,” Dakota Cary, a China-focused consultant at SentinelOne, tells CSO.
“It’s kind of like a choke point, where you have a bunch of teams using the same network to carry out offensive operations,” he says. “If you take down that network, they all have to go find new infrastructure to obfuscate their activity.”
The quartermaster model of hacking
For a year prior to the takedown, Lumen’s Black Lotus Labs tracked QTFY as it functioned as a “quartermaster,” integrating reconnaissance, proxy orchestration, and operational routing into “a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.”
“We were able to see the direct targeting of certain things,” Damon Rouse, senior lead information security engineer at Black Lotus Labs, tells CSO. “And then from that, we were able to find their scanning framework, their application called QScan. And then we were starting to really do some correlation between QScan activity and then follow-on activity from the proxy network called Fast Labyrinth.”
Rouse likened Nanjing Xinjiuwei’s role to that of a defense contractor. “There’s a ton of these companies in China that are usually started directly after people leave the PLA,” he says. “Because of their connections to the PLA, they have a specialized status to do certain things for the PRC government. And it gives the government plausible deniability because it’s not actually coming from their units.”
China has marketized state hacking
Nanjing Xinjiuwei’s private-contractor role illustrates how Beijing draws operational capacity from a broader commercial ecosystem.
“The company knows that they’re facilitating offensive operations for hackers,” SentinelOne’s Cary says. “This business exists because the hacking teams have a need for this type of infrastructure, and China has been really good at using capitalism to create a lot of its infrastructure for cyber operations.”
The FBI in its investigations was able to track the flow of this marketized state hacking system. “The FBI is amazing at following the money and creating very elaborate maps of customers and payments and all kinds of good stuff,” Lumen’s Rouse says. “That’s how they were able to out a lot of these very high-end clients of this company, including PLA units, MSS units and other very, very well-connected Chinese companies that are in the infosec hacking space.”
In short, China has cultivated a market of private contractors supplying specialized capabilities to state hacking teams. “They’ve been very effective at using market incentives in order to facilitate the development of business that meets their operational needs,” Cary says.
Efficiency creates the choke point
This market-like efficiency gives Beijing scale, speed, and plausible deniability. But it also concentrates risk, making it easy for US law enforcement to knock out one shared service, forcing every team that uses it to scramble for new infrastructure.
However, the operation does not provide a permanent answer to China’s reliance on private companies and shared infrastructure.
Even though stealthier residential and commercial proxy networks have replaced the old “whack-a-mole” model, “It would be naive to say that there’s not going to be another company or another 10 companies that are doing something very similar to this to either pick up their slack or to replace them,” Rouse says.
It’s even possible that Nanjing Xinjiuwei could stick around, the way a Chinese cybersecurity firm, Chengdu 404, indicted by US and international authorities as a front company for the state-sponsored hacking group APT41 has done.
“Chengdu 404 is a really good example,” Cary says. “They got indicted, and it was very clear the DOJ and FBI were like, ‘We know who you are. We know where you work. We know where you live.’ Chengdu 404 is still in business. They still operate out of the same address. They don’t care.”
However, Cary contrasts the situation with i-Soon, a Shanghai-based private cybersecurity contractor that carried out large-scale, state-sponsored hacking and espionage operations for Chinese government agencies. “On the other end of the spectrum is i-Soon, where i-Soon had those leaks in February of ’24, and they completely shut down,” he says. “I mean, they closed all their offices. They were done, done, done.”
The lessons for CISOs
One of the top operational lessons to come out of this latest action is that geography- and reputation-based IP blocking are increasingly inadequate because Chinese state-sponsored activity appears to originate from seemingly ordinary devices and legitimate commercial infrastructure outside China.
The broader QTRouter and Fast Labyrinth obfuscation infrastructure routed traffic through small office routers and IoT devices, commercial proxy infrastructure, leased virtual private servers, and dynamically rotating IP addresses, undermining geography-based and reputation-based blocking.
As FBI’s Leatherman said, “Instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries — potentially through systems just down the street from the victim’s own network.”
Rouse warns that malicious Chinese traffic could look “like it’s traffic originating from the United States from, for example, Charter Communications. It makes it very difficult to see that that’s nefarious.”
Experts point CISOs beyond reliance on IP origin and reputation, emphasizing behavioral visibility, tighter edge security, and a clear baseline of legitimate traffic.
“Even if the device or the IP address doesn’t resolve to an ASN in China, that doesn’t mean it’s not malicious,” Cary says.
Rouse advises CISOs, “Make sure [perimeter devices are] patched; make sure your patching life cycles are shortened to as short of time as possible.”
He adds, “Make sure you have adequate logging around your firewalls, your perimeter, and look for traffic from residential things. If you have that kind of baseline, you have an understanding of what the traffic should look like, and you can really do a better job at looking at the anomalies.”