FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
ID: 807c2fe5-8f51-592b-832b-918c322c4200
STIX ID: report--807c2fe5-8f51-592b-832b-918c322c4200
Feed Name: Security Affairs
The U.S. Department of Justice and FBI seized two China-linked platforms, QScan and QTRouter, operated by a group called QTFY (via Nanjing Xinjiuwei) that scanned for and automatically infected thousands of IoT devices and used them—alongside commercial proxies and leased VPS—to route malicious traffic and obfuscate state-origin intrusions against U.S. critical infrastructure and government entities; the seizures disrupted the malware by taking control of domains hard-coded for authentication and command-and-control. The report details exploited products (Fortinet, Citrix, Exchange, F5, Log4j, Confluence, etc.), use of web shells/RATs/stolen credentials, and frames the operation as an industrialized “quartermaster” service, concluding with defensive guidance: inventory, patching, remove unsupported devices, and monitor outbound proxy traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
