FBI Disrupts QTFY Router Botnet Behind China-Linked Attacks

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
A home router split between a normal network device and a covert QTFY proxy relay.
QScan infected exposed devices while QTRouter used compromised routers and IoT systems to conceal attack traffic.

The FBI and Justice Department have disabled two platforms used by the China-linked QTFY hacking group: the QScan botnet and the QTRouter proxy network. Court-authorized domain seizures broke hard-coded connections that the platforms relied on, making both systems inoperable, according to the Justice Department.[1]

The operation matters beyond the government agencies and critical-infrastructure organizations QTFY targeted. Thousands of compromised routers, cameras, and other Internet of Things (IoT) devices served as the group’s relay layer. In other words, an ordinary device could help conceal an attack even when its owner was not the intended victim.

How QScan and QTRouter worked together

QTFY operated a two-part system. QScan searched for and exploited exposed devices. QTRouter then routed attack traffic through compromised equipment and commercial proxy services, making malicious connections look as if they originated near the target. The joint FBI, NSA, and U.S. Cyber Command advisory says the activity has affected defense, communications, government, higher education, energy, water, and other sectors since at least 2018.[2]

Component Role Why it mattered
QScan Scanned the internet and tested known exploits Built a pool of compromised routers and IoT devices
QScan botnet Ran tasks through infected devices Distributed reconnaissance and intrusion activity
QTRouter Chained compromised devices and proxy services Obscured the real origin of attacks

The scale was substantial. Investigators found more than 200 proof-of-concept exploits in the QScan database. On one day in 2024, the system handled more than two million scanning and penetration-testing tasks. The advisory also attributes a May 2024 campaign that exfiltrated data from more than 300 organizations to QScan activity.[2]

Lumen’s Black Lotus Labs independently tracked the supporting infrastructure and described QTFY as an “infrastructure quartermaster”: a service that supplied scanning, compromised devices, and proxy routes to other China-nexus operators.[4] That distinction helps explain why both targets and relay devices appear in the same investigation.

What the FBI seizure changed

The seizure removed domains hard-coded into QScan and QTRouter. The Justice Department says losing those domains rendered the platforms inoperable.[1] This is a meaningful disruption: it prevents the seized infrastructure from coordinating the compromised-device pool in its previous form.

It is not the same as remotely repairing every affected router or camera. A seizure does not install current firmware, remove unrelated malware, reverse stolen credentials, or make an unsupported device safe. That is an operational inference from what the government action changed—the command infrastructure—versus what device owners still control. Similar proxy networks can also be rebuilt if exposed equipment remains available.

The NSA therefore pairs the disruption announcement with defensive guidance, not an all-clear. It advises organizations to update software and firmware, protect operational information, isolate critical systems from edge devices, and investigate the published indicators.[3]

Who should check routers and edge devices

Network defenders should prioritize internet-facing routers, VPN appliances, cameras, and other edge or IoT systems—especially models that no longer receive security updates. QTFY’s tooling used a broad library of known exploits, so the relevant question is not whether a device carried a “QTFY” label. It is whether the device was reachable, vulnerable, unexpectedly reconfigured, or communicating through suspicious infrastructure.

Small businesses and home users face a simpler version of the same issue. A compromised router may continue providing normal internet access while proxying someone else’s traffic. Our guide to checking and securing an exposed router covers the settings that deserve attention. The recent Dysphoria router-proxy campaign shows why attackers value residential-looking IP addresses.

What organizations and device owners should do

  1. Install supported firmware and software. Confirm the update on the device itself; do not rely only on an asset spreadsheet.
  2. Remove unnecessary exposure. Disable internet-facing administration, UPnP, and unused forwarded ports unless there is a documented need.
  3. Separate edge and IoT equipment. Do not let a camera or router management interface provide an easy path into sensitive systems.
  4. Review configuration and logs. Check DNS settings, administrator accounts, scheduled tasks, unfamiliar services, and unexplained outbound connections.
  5. Use the official indicators carefully. The joint advisory warns that an indicator alone does not prove compromise. Validate context before blocking shared proxy or cloud infrastructure.[2]
  6. Replace unsupported hardware. If a vendor no longer supplies security updates, a factory reset may remove current changes but cannot fix the underlying exposure.

If compromise is suspected, preserve logs and configuration before resetting the device, rotate management credentials from a known-clean system, and review other accounts that reused the same password. Rebooting alone is not a reliable cleanup method.

Does the seizure mean my router is clean?

No. It means the government disabled the identified QScan and QTRouter control platforms. There is no public, complete consumer device list that can prove a particular router was never involved. Owners should instead verify vendor support, firmware version, remote-management settings, administrator accounts, and unusual network behavior.

References

  1. U.S. Department of Justice: seizure of QScan and QTRouter platforms
  2. FBI, NSA, and U.S. Cyber Command joint cybersecurity advisory JCSA-20260826-01
  3. NSA: warning about QTFY cyber activity
  4. Lumen Black Lotus Labs: QTFY infrastructure analysis
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?