The U.S. Department of Justice issued a correction to a previously released press statement regarding Chinese threat actor attacks on U.S. government agencies. The DoJ clarified that agencies including NASA, the Federal Reserve, the Department of Energy, and the DoJ itself were targeted rather than confirmed victims. This distinction between 'targeted' and 'victims' is significant in cybersecurity and legal contexts. The correction suggests the initial statement may have overstated the impact or success of the intrusion attempts. The incident highlights ongoing Chinese cyber espionage efforts directed at critical U.S. government institutions. The clarification raises questions about the accuracy of initial threat assessments and public communications from federal agencies.
QTFY (aka QT AND QTCYBER) is a China state-sponsored threat actor operating on behalf of a private Chinese company, Nanjing Xinjiuwei Network Technology Co, with suspected ties to China's Ministry of State Security (MSS). Active since 2018, QTFY functions as a technical quartermaster providing reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage. Its core tools include: (1) QScan - a vulnerability scanning and exploitation platform used to compromise IoT devices and identify vulnerable targets; (2) QTRouter - an obfuscation network used to route malicious traffic through compromised endpoints. QTFY has industrialized the creation of Operational Relay Box (ORB) networks, building decentralized botnets of infected IoT devices and leased VPS servers to obscure the true origins of malicious traffic. The overall architecture, called 'Fast Labyrinth,' is an encrypted relay network that blends malicious traffic with legitimate network activity. The network also incorporates nodes from the Chinese commercial proxy service fastlink[.]ws. QTFY sells access to QScan and QTRouter to other threat actors, enabling them to enlist compromised IoT devices as botnet nodes. In 2019, QTFY attempted to compromise NASA by exploiting CVE-2019-11510, a critical vulnerability in Pulse Secure VPN. Targets have included U.S. federal government agencies (NASA, Federal Reserve, DoE, DoJ, HHS, NIH, U.S. Senate), hospitals, telecom operators, power companies, financial institutions, and defense contractors. Lumen Black Lotus Labs has contributed research into the ORB network infrastructure.
1. The FBI has seized and disrupted domains associated with QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com), neutralizing their malware functions. 2. Organizations should immediately patch CVE-2019-11510 in Pulse Secure VPN if not already done. 3. Block or monitor traffic to/from the identified IOC domains: qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com, and fastlink[.]ws. 4. Monitor for anomalous outbound traffic that may indicate ORB network routing or proxy abuse through IoT devices. 5. Audit and secure internet-facing IoT devices to prevent them from being recruited into botnet infrastructure. 6. Implement network segmentation to limit lateral movement if a device is compromised. 7. Federal agencies and critical infrastructure operators (hospitals, telecoms, power companies, financial institutions, defense contractors) should review logs for signs of reconnaissance or scanning activity associated with QTFY tools. 8. Leverage threat intelligence from Lumen Black Lotus Labs regarding ORB network indicators for enhanced detection.
qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com, fastlink[.]ws