
DOJ Sinkholes QScan/QTRouter Domains Run by Nanjing Xinjiuwei Since 2018
FBI disruption of QTFY's QScan and QTRouter platforms exposed a commercial proxy service selling access to Chinese state customers since 2018. Technical artifacts confirm IoT botnet chaining but leave open questions on exclusive attribution. Migration of remaining infrastructure is expected within two months.
Court filings and Lumen Black Lotus Labs telemetry show QScan domains qt-proxy.org and mq-task.qt-proxy.org distributed tasks to worker nodes on leased VPS outside China, then fed results into QTRouter nodes running custom OpenWrt and Clash for traffic chaining. The platforms authenticated to qtproxy.xyz servers and mixed botnet traffic with commercial proxies, a pattern Lumen tracked from May 2018 onward. Victims included research institutions across the Western world, consistent with MSS and PLA customer requirements for academic IP. Lumen's year-long collaboration with the FBI produced the domain list and botnet controller artifacts now sinkholed; independent packet captures confirm the same Clash configuration and QTBotnet secondary servers previously reported in 2023 contractor briefings. Official statements attribute activity directly to state tasking, yet the technical evidence shows only a commercial quartermaster selling access to multiple Chinese actors, not exclusive MSS control. The operation reveals a durable supply chain for proxy obfuscation that predates and outlasts publicized Volt Typhoon focus on living-off-the-land techniques. No CVE or exploit chain was published, leaving vendors without patch guidance despite documented IoT infection methods. Remaining QTFY lease agreements and secondary control servers will likely migrate within 60 days; expect renewed domain registrations under variant naming schemes once sinkhole data is analyzed.
Lumen: At least three new qt-proxy variant domains will appear in passive DNS within 90 days.
Sources (3)
- [1]Primary Source(https://www.justice.gov/opa/pr/justice-department-disrupts-qtfy-hacking-platforms)
- [2]Supporting Source(https://blog.lumen.com/black-lotus-labs-qtfy-tracking-report-2025)
- [3]Supporting Source(https://www.cisa.gov/news/2025/08/13/joint-advisory-qtfy-proxy-infrastructure)