On 26 August 2026 the Department of Justice and the Federal Bureau of Investigation announced court-authorized seizures of internet domains hard-coded into two operational platforms run by a China-linked group that identifies itself as QTFY, QT, and QTCYBER. The seizures, executed under authority granted in the Southern District of California, rendered both platforms inoperable. The Bureau, the National Security Agency, and the Cyber National Mission Force published a joint advisory the same morning attributing the group to Nanjing Xinjiuwei Network Technology Co., a Chinese firm established in 2018, and Lumen Technologies’ Black Lotus Labs published a year of accumulated telemetry describing the same infrastructure from the outside.
What makes this action worth an analyst’s attention is not the takedown itself, which follows a now-familiar template, but what the seized platforms actually were. QTFY is not an intrusion set in the conventional sense. It is a supplier. The company built, maintained, and rented an industrialized reconnaissance engine, a curated exploit library, and a transit layer engineered to make hostile traffic indistinguishable from consumer internet activity, and it sold access to those capabilities to customers that, according to the Justice Department, included units of the Ministry of State Security and the People’s Liberation Army. The intrusions attributed to this infrastructure were, in many cases, not carried out by QTFY at all. They were carried out through it.
The single most consequential technical detail in the disclosure is that QTFY did not build its primary obfuscation layer by compromising devices. It bought it. The company purchased high-tier corporate subscriptions to a commercial Chinese circumvention proxy service and selectively co-opted its premium egress nodes, placing state-directed reconnaissance traffic on the same infrastructure carrying ordinary Chinese consumers past the Great Firewall. Every defensive control that depends on knowing an address is bad — reputation feeds, geolocation heuristics, known-infrastructure blocklists — is structurally defeated by that arrangement, because the address is not bad. It is a paying customer’s egress node that also happens to be carrying an intelligence service.
THE ANALYTIC FRAME
Read this as a supply-chain disruption, not a botnet takedown. The relevant question for defenders is not whether QTFY was stopped, but how much of the PRC operational ecosystem was renting the capability that just went dark — and how quickly a company with pre-provisioned domains and a purchasable transit layer can restore it.
The following judgments are rendered under ICD 203 standards. Confidence reflects the quality and convergence of sourcing, not the probability of the underlying event. Where an assessment rests on inference rather than reported observation, that is stated explicitly.
KJ-1. QTFY operates an enablement or quartermaster business model rather than a conventional espionage intrusion set. The company sells reconnaissance telemetry, exploitation capability, and attribution-shielding transit as a multi-tenant service to state customers, which structurally separates the entity that builds infrastructure from the entities that use it against targets. (High confidence)
KJ-2. The co-opting of a commercial circumvention proxy service is the material innovation in this disclosure and the element most likely to be replicated by other actors. It converts obfuscation from an asset that must be built and defended into a subscription that can be repurchased, and it defeats indicator-based network defense by design rather than by evasion. (High confidence)
KJ-3. QTFY retained privileged access to vulnerability information ahead of public disclosure. The group’s use of three Ivanti Cloud Services Appliance zero-days in September 2024 immediately following participation in a Chinese attack-and-defense exercise is consistent with, though not conclusive proof of, the documented state pipeline routing vulnerability research through regulatory reporting channels to state security consumers. (Moderate–High confidence)
KJ-4. The disruption has degraded but not eliminated the capability. Domain seizure removed the control plane; it did not remove the exploit library, the historical scanning database, the operator relationships, or the ability to purchase new proxy subscriptions. Precedent from the two comparable disruptions indicates restructuring activity within days and partial capability restoration within weeks to months. (Moderate–High confidence)
KJ-5.Organizations operating internet-facing edge appliances — particularly VPN concentrators, remote-support platforms, file-transfer applications, and managed-file or gateway devices — should assume they were profiled by this infrastructure regardless of whether a compromise was detected. The platform processed more than two million scanning and penetration-testing tasks in a single day in 2024 and matched new vulnerability disclosures against nearly a decade of retained scan results. (High confidence)
KJ-6. No individual has been charged and no sanctions have been imposed in connection with this action. This is a domain-seizure operation only, which places it below the i-Soon and Integrity Technology Group actions on the escalation ladder and suggests either that attribution to named individuals remains under development or that prosecutorial equities were weighed against disruption timing. (High confidence — observed, not inferred)
The Justice Department’s announcement describes seizures of domains that the two platforms required in order to function. This is the operative detail. The domains were not merely command-and-control endpoints in the ordinary sense of a beacon destination; they were hard-coded into both QScan and QTRouter and used for essential tasks including communication and authentication. Removing them did not blind the operators. It unbuilt the platforms. Court documents, and two independent outlets citing the sealed affidavit, identify the seized domains as qtproxy.xyz, qt-proxy.org, and qt-team.com — a set that spans both the current and the legacy naming conventions, indicating the government seized the migration path as well as the live infrastructure.
The named federal victims are unusually senior. Court documents cite the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the United States Senate. Beyond the federal enterprise, the filings describe targeting of hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The Attorney General characterized the operation as the latest in a series of technical operations to dismantle indiscriminate hacking activity sponsored by the People’s Republic of China; the FBI Director framed it as the disruption of a global botnet and hacking platform.
Three organizational details are worth recording precisely because they are easy to get wrong in secondary reporting. The joint advisory is authored by the FBI, the NSA, and the Cyber National Mission Force — three signatories, not two, notwithstanding that the Justice Department press release names only the first two. The seizure authority was obtained in the Southern District of California, with the FBI San Diego Field Office, the FBI Cyber Division, and the National Security Division’s National Security Cyber Section as the investigating components. And the supporting affidavit is a domain-seizure affidavit, not an indictment; nothing in this action charges a person.
Nanjing Xinjiuwei Network Technology Co. — XJW — was established in 2018 and, according to Chinese business records cited in press reporting, employed seventeen people as of last year. Seventeen. That number deserves a moment, because it is the clearest available measure of how much leverage the model generates. A firm the size of a small consultancy built and operated the reconnaissance substrate for intrusions against the Federal Reserve, three Department of Energy national laboratories, and the United States Senate, and did so by selling shared capability rather than performing bespoke intrusion work.
The advisory describes XJW as an enabling company for cyber operations, with business relationships extending to Ministry of State Security units and to larger private Chinese cyber-enabling firms. QTFY personnel include former members of the People’s Liberation Army who leverage those contacts to obtain contracts and subcontracts, and who participate in China’s freelance broker networks for the trading of exploits and network access. The Justice Department states plainly that the paying customers included the MSS and the PLA. Administrative telemetry supports the customer relationship independently: distinctive user-agent strings observed logging into the QTRouter management plane resolve to QTFY personnel and to Chinese government personnel located in Jiangsu, Qingdao, Jilin, and Sichuan.
XJW does not sit alone. The advisory documents a business network that places the firm inside the same contracting lattice already mapped through the i-Soon disclosures and the Salt Typhoon attribution. The entities below are those the government identifies as having a business relationship with XJW as of June 2026, together with the significance of each. For ICS and OT practitioners, the notable feature of this table is how much of it is industrial: power-system vulnerability detection, industrial control security, radio-frequency hardware, and command-and-control system design all appear.
One caution on this table. The advisory’s own rendering of it contains a copy-paste defect: the Chinese-language name for Changyang / Cy-Tech is erroneously repeated in the rows for CNITSEC Jilin and Bozhi Security. Analysts building entity records from the PDF should not treat those two Chinese strings as authoritative. The English entity names and the described relationships are unaffected.
Lumen’s telemetry, accumulated over roughly a year of tracking, resolves the operation into four functional components. The government advisory describes substantially the same architecture using partially different naming. Taken together they describe a reconnaissance engine, a transit layer, an access appliance, and a set of node-management consoles — designed to interoperate but, critically, rentable in isolation.
QScan is a distributed scanning and exploitation platform built on conventional message-queue engineering rather than on anything exotic. Operators submit work to a central task broker running Celery over RabbitMQ, which stages jobs to a globally dispersed worker fleet leased on commercial virtual private servers outside China; results return to a Redis backend. The worker fleet rotates across address blocks on a thirty-day lifecycle, which is short enough to age out of most indicator feeds before those feeds have finished propagating.
Task queues cover web scraping, TLS certificate collection, subdomain enumeration, general penetration testing, and a dedicated queue for content-management-system plugin detection. Behind the queues sits a library of more than two hundred proof-of-concept exploits written in Python and engineered for volume rather than finesse. The throughput figure the advisory reports is the one to remember: on a single day in 2024, the platform processed more than two million scanning and penetration-testing tasks.
The genuinely dangerous property of QScan is not its throughput but its memory. The platform is backed by a scanning database approaching a decade in depth. When a new vulnerability is disclosed, the operators do not need to go find affected hosts; they query historical scan results and generate a target list immediately. This inverts the defender’s usual assumption about patch windows. The window is not the time between disclosure and the attacker discovering you. It is the time between disclosure and the attacker running a database query against a record of your perimeter that was captured months or years ago.
Lumen further observed two distinct deployment postures. Against well-defended federal, military, and intelligence address space, the platform ran wide-spectrum perimeter profiling — mapping boundaries, logging interfaces, and cataloguing configuration drift over time. Against high-value targets, the broad engine was suppressed in favor of quiet, high-port, application-layer sweeps designed to elicit kernel fingerprints, edge trust boundaries, and remote management interfaces without generating the volumetric signature that would trigger review.
Chinese consumers who want to reach the open internet buy subscriptions to services colloquially known as airports. These are commercial circumvention providers that sell access to egress node pools reached through clients such as Clash and Shadowrocket over V2Ray, Shadowsocks, and Trojan transports, frequently backed by dedicated international private-line circuits and multi-homed routing to keep streaming traffic smooth. Node registries rotate through client subscription URLs, so the egress pool is fluid by design rather than by evasion.
QTFY purchased high-tier corporate subscriptions to one such provider and selectively co-opted its premium egress nodes, which resolve to identifiable subdomain patterns under a single provider domain. State-directed reconnaissance then transited the same nodes carrying thousands of ordinary subscribers watching video. Lumen observed the quartermaster’s master control portal testing and calibrating those nodes before leasing access to downstream actors — a detail that matters analytically, because it demonstrates the provider relationship is managed as a product line, with quality assurance, rather than as opportunistic abuse.
The consequence for defenders is categorical rather than incremental. A static blocklist of these egress addresses would disrupt legitimate commercial traffic while catching only whatever fraction of the pool happened to be current at the moment the list was built. Geolocation is equally useless: the entire purpose of the provider is to present egress in a jurisdiction other than the subscriber’s. Reputation scoring inherits the same defect, because the aggregate behavior of the node is dominated by legitimate consumers. The infrastructure is not hiding from reputation systems. It is riding inside their blind spot by construction.
Lumen also established the tethering between the two layers. Sectors mapped by QScan subsequently received inbound connections from Fast Labyrinth proxies within the same window — research universities working in advanced physics, bioinformatics, and aerospace or satellite programs; United States military and defense networks including communications gateways, access control systems, and logistics suppliers; geological and environmental agencies; European infrastructure; and judicial nodes worldwide. Scout and transit were pointed at the same objectives. They remained, however, independently rentable, which means the presence of one does not guarantee the presence of the other in any given campaign.
QTRouter is the operator-facing access appliance: routers running custom OpenWrt firmware, using Clash for proxy connections, with the ability to enumerate available nodes and chain them together into multi-hop paths. Nodes are drawn from three pools — compromised IoT devices, commercial proxy addresses purchased from the airport provider, and Alibaba Cloud infrastructure supplemented by leased virtual private servers. Authentication runs against a Proxy Node Management System console. A jump server sits in front of the environment, and the naming of that jump server across two domain generations is one of the cleaner artifacts of the December 2025 rebrand.
The compromised-IoT component serves a purpose distinct from volume. It provides geographic proximity to targets, so that an intrusion attempt against a regional utility or a municipal network arrives from an address that plausibly belongs in that region. Combined with the commercial proxy layer, this gives operators a choice of cover story per operation: blend into consumer traffic, or blend into the neighborhood.
Three consoles manage the compromised-device estate. The first, Proxy Platform Management, handles node administration and configures proxy software on compromised hosts; its client, agent, and server components were recovered from open web directories, which is an operational security failure of the kind that tends to accompany rapid growth. The second, the Proxy Pool Management System, aggregates compromised IoT and — significantly — hosts both an exploit database and a server fingerprint database, enabling instant target identification when a new vulnerability lands. It maintains access credentials organized by category, including SOCKS5 proxy bots, MikroTik RouterOS devices, and PPTP endpoints. The third, QTBotnet, comprises a main controller, second-level control servers, and the compromised devices themselves, and adds distributed denial-of-service capability alongside node import, remote command execution, and management of the second-tier servers.
The Proxy Platform Management binaries deserve a note of their own. The advisory publishes roughly thirty SHA-256 hashes spanning a Go-style cross-compilation matrix that covers x86, x86-64, ARM in four variants, MIPS in four variants, PowerPC, RISC-V, IBM s390x, and ARC700. That build matrix is not the product of opportunistic device compromise. It is the product of an engineering decision to support essentially every CPU architecture present in the global embedded-device population, which is what a supplier does when it does not know in advance which devices its customers will need.
The advisory presents what it characterizes as a sample of observed activity dating to at least 2018. It is worth reading as a single continuous record rather than as a list of incidents, because the through-line is a supplier steadily broadening its catalogue: early unsuccessful scanning of federal departments, a first significant intrusion in 2019, a decade of edge-appliance exploitation, and — by 2026 — election infrastructure, a state government, a water district, the Senate, and a hospital system inside a six-month span.
It is tempting to summarize the above as exploitation of nearly every major edge-device vulnerability within weeks of disclosure. That formulation is partly right and, in one direction, materially understated. The record actually contains three distinct behaviors, and conflating them produces a misleading picture of the threat.
The first is genuine zero-day use. The September 2024 Ivanti Cloud Services Appliance cluster was exploited ahead of public disclosure. This is a capability statement, not a speed statement, and it is the single strongest indicator in the record that QTFY enjoyed privileged access to vulnerability information. The second is rapid n-day exploitation, where the group weaponized a disclosure within days to weeks: Log4j in December 2021, Confluence in October 2023, Check Point in May 2024, and BeyondTrust in February 2026 all fall in this band, and all four are cases where the platform’s historical scan database would have produced an instant target list. The third is opportunistic legacy exploitation, where a vulnerability more than a year old was used against hosts that had simply never been patched — the F5 BIG-IP activity in 2021 against a 2020 disclosure, and the Kentico CMS activity the same year against a 2019 disclosure.
Every vulnerability above except CVE-2019-10068 is confirmed on the CISA Known Exploited Vulnerabilities catalogue; the Kentico entry could not be verified in this reporting cycle and is flagged as an open item rather than asserted. On one point of housekeeping: the Fortinet identifier in the advisory is correct as published. CVE-2018-13379 is the path-traversal and credential-exposure flaw, distinct from CVE-2018-13382, the authentication bypass frequently confused with it in secondary reporting.
THE PRACTICAL IMPLICATION
A patch program calibrated to a thirty-day service level is not calibrated to this actor. Four of the fourteen vulnerabilities above were weaponized inside the first month, and three were weaponized before a patch existed. For internet-facing edge appliances specifically, emergency change authority — not the standard cycle — is the control that matters.
The advisory makes an observation in passing that deserves more weight than its placement suggests: QTFY participates on the offensive side of Chinese attack-and-defense exercises conducted against domestic critical infrastructure, and the group’s use of the Ivanti Cloud Services Appliance zero-days occurred directly after one of those events. The advisory reports the sequence. It does not assert causation, and neither should we.
The context that makes the sequence significant is structural. Since September 2021, Chinese regulation has required companies to report newly discovered network product vulnerabilities to the Ministry of Industry and Information Technology within forty-eight hours, while prohibiting public disclosure or proof-of-concept release ahead of a patch. Published research on the resulting flow describes vulnerability information moving from that regulatory channel into national vulnerability databases, one of which is operated by the Ministry of State Security, with access held by a regional MSS office, a PLA-affiliated contractor, and a university research center. The advisory’s own business-network table supplies the local instance of this mechanism: it records that as of September 2021, CNITSEC provided vulnerabilities to the MSS 13th Bureau for review prior to public publication, and it places a CNITSEC subcenter inside XJW’s business network.
The assessment therefore runs as follows. It is observed that XJW maintains a relationship with an organization documented to route pre-publication vulnerability information to a state security consumer. It is observed that QTFY participates in exercises that surface novel vulnerabilities. It is observed that zero-day use followed one such exercise immediately. It is inferred — at moderate-to-high confidence, not asserted — that these facts describe a supply relationship rather than a coincidence. The alternative hypothesis, that QTFY developed the Ivanti exploits independently and the timing is incidental, is not excluded by the available reporting but is the less economical explanation given the documented structure.
For a defender, the operational consequence of this assessment is narrow but real. If a Chinese enabling company can receive vulnerability information before the vendor publishes, then the interval during which an internet-facing appliance is safe because nobody knows about the flaw does not exist for this class of actor. Compensating controls — segmentation, egress restriction, management-interface isolation — have to carry weight that patching cannot.
The three primary sources converge on the substance and diverge on the details, in ways that matter for anyone building detections or entity records directly from them. Publishing the corrections is part of the analytic product.
The advisory body text places this platform at one address; the advisory’s own indicator table and the published infrastructure CSV both place it at another. The two strings differ by digit placement. The value appearing twice, including in the machine-readable file, should be treated as authoritative, and the body-text value should be treated as a transcription error. Building a block or hunt rule from the narrative text rather than the CSV would produce a rule that matches nothing.
Several rows in the advisory’s infrastructure table carry first-seen and last-seen values in which the range begins after it ends, and at least one carries a year in the future. The corresponding CSV rows are internally consistent. Where the PDF and the CSV disagree, the CSV should be preferred.
The advisory marks at least one jump-server address as active while the CSV records a last-seen date in December 2025. A second host shows a first-seen date in the PDF that precedes the CSV first-seen date by more than three years. Neither discrepancy changes the assessment, but both should temper any use of the advisory’s active designation as a current-state indicator.
The vendor report renders the QScan broker and backend hostnames with hyphenated separators where the government sources use dotted subdomains. These describe the same infrastructure. The dotted forms are authoritative for detection content.
The vendor blog carries content-management timestamps suggesting a March 2026 publication date. The report was published on 26 August 2026 in coordination with the government action. Citing the earlier date would misrepresent the disclosure timeline.
WHAT THIS ACTION IS NOT
No individual has been indicted. No entity has been designated by the Office of Foreign Assets Control. This is a seizure of domains, and it should not be described as a prosecution. The contrast with prior actions is instructive: the i-Soon matter produced unsealed indictments of eight company employees and two Ministry of Public Security officers alongside Rewards for Justice offers, and the Flax Typhoon disruption was followed within months by Treasury sanctions on Integrity Technology Group. That escalation has not occurred here — at least not yet.
Two prior disruptions supply the base rate. In December 2023 the Bureau obtained court authority to dismantle the KV-botnet operated in support of Volt Typhoon. Vendor telemetry recorded the operators beginning to restructure within two days of the operation, interacting with more than three thousand unique addresses over a seventy-two-hour period. An initial revival attempt in early 2024 failed. By late 2024 the group had rebuilt on a different device population, with one vendor reporting compromise of roughly thirty percent of the visible installed base of a targeted router family inside thirty-seven days. In September 2024 a second court-authorized operation dismantled the Raptor Train botnet associated with Flax Typhoon and its contractor, Integrity Technology Group; Treasury sanctioned the contractor the following January.
The pattern across both is consistent. Infrastructure disruption degrades capability measurably and imposes real cost, but the operators retain the tooling, the target knowledge, and the institutional relationships, and they rebuild. The interval is days for restructuring activity and weeks to months for partial capability restoration.
QTFY should be expected to recover faster than either precedent, for three reasons that follow from its own architecture. First, its obfuscation layer is purchased rather than built; restoring transit requires a new corporate subscription, not a new compromise campaign. Second, the group has already demonstrated a domain migration, moving from one brand to another in December 2025, which means the operational muscle memory for rebranding exists and the seizure removed a path the operators had already shown they can rebuild. Third, indicator data shows registration terms on associated domains extending as far as 2031 and 2032, indicating deliberate pre-provisioning of infrastructure well beyond current need.
Against that, the seizure took the legacy domain as well as the current one, which forecloses the simplest form of fallback and imposes a genuine rebuild rather than a switchover. An independent analyst quoted in coverage of the action framed the broader dynamic directly: actions of this kind are necessary to disrupting Chinese operations at scale, but the robust domestic market for offensive services effectively guarantees a return to operations.
Assessment. QTFY capability is degraded, not eliminated. Expect re-domaining and re-subscription to commercial proxy egress within weeks to months. Reappearance of QScan worker check-in behavior, or new egress patterns resembling the co-opted provider’s node naming, would confirm rebuild. Absence of both through the fourth quarter of 2026 would argue the disruption was more durable than precedent suggests. (Moderate–High confidence — inference from precedent, not observation)
The central defensive problem this disclosure poses is that the actor has decoupled its network identity from its intent. A defender who blocks the indicators in the published files will remove the QScan worker fleet and the management infrastructure from their environment, which is worth doing, and will do essentially nothing about the transit layer. Detection has to move to behavior. The following are ordered by leverage rather than by ease.
A commercial proxy hides where traffic comes from; it does not hide what generated the traffic. TLS client fingerprinting — the JA3 family and its JA4 successor suite — characterizes the handshake produced by the connecting software regardless of the address it arrives from. This is directly applicable here: the vendor reporting notes administrative logins to the management plane presenting a generic Go HTTP client user-agent, precisely the sort of automation signature that fingerprinting surfaces even when the network path is laundered. JA4 improves on JA3 for this purpose by sorting cipher and extension lists and stripping randomized values, which defeats the client-side randomization that has eroded JA3 reliability. The related JA4T variant can indicate the presence of a tunnel or proxy through TCP option and maximum-segment-size overhead.
Peer-reviewed work presented at USENIX Security in 2024 demonstrated a protocol-agnostic method for identifying obfuscated proxy traffic by detecting encapsulated TLS handshakes — the structural signature left when a TLS session is nested inside another. The technique reliably identifies Shadowsocks, VMess, VLESS, Trojan, and XTLS-Vision at network-operator scale with low collateral impact, and is implementable on Zeek. Because it keys on the encapsulation rather than on any provider’s address pool, it survives the node rotation that defeats blocklists. For organizations that have no legitimate business reason to see these transports on their networks, this is the highest-value detection investment available in response to this disclosure.
Recent measurement work on residential proxy abuse establishes the scale of the underlying problem: a large fraction of unique addresses observed targeting edge devices are residential, and the substantial majority are invisible to reputation feeds. That research also identifies two exploitable signals. Compromised consumer hosts follow the diurnal rhythm of the household they sit in, producing a detectable activity curve that hosting infrastructure does not exhibit. And the division of labor is measurable: residential sessions carry payloads at roughly a tenth the rate of hosting-based sessions, because residential egress is used for reconnaissance while exploitation runs from infrastructure. A single-sign-on or VPN authentication arriving from a residential-tagged address is a stronger signal than an impossible-travel alert, and is not defeated by the geographic proximity that the compromised-IoT layer is specifically designed to provide.
Netflow retention is the control that would have detected this activity historically. The vendor recommendation is specific: audit historical netflow and DNS records for anomalous bidirectional loops to the co-opted provider’s egress subdomains. More generally, the QScan worker fleet’s thirty-day address rotation and the precision-interrogation posture — low-volume, high-port, application-layer probing — produce a flow shape that volumetric alerting will not surface but that beaconing and periodicity analysis will. Organizations that retain ninety days or more of flow data can perform this retrospectively today.
Given the throughput and the historical database, the working assumption for any organization with internet-facing infrastructure should be that its perimeter has been profiled and that configuration drift has been tracked over time. The defensive response to that assumption is not detection but reduction: inventory internet-facing appliances against end-of-support status, remove management interfaces from public reachability, and audit public-facing applications for inadvertently exposed API keys, tokens, and configuration detail. The advisory raises this last item explicitly as a key action, which suggests the authoring agencies observed it being exploited.
For ICS and OT operators the advisory’s most important recommendation is zero-trust segmentation between critical systems and edge devices. The targeting record supports the emphasis: remote access trojans on Taiwan energy sector systems in 2021, power company reconnaissance in 2025, a water district in early 2026, and a business network populated with firms specializing in power-system vulnerability detection and industrial control security. The exposure pattern in this record is consistently the edge appliance as the entry point to a process network that had no independent reason to trust it.
POSTURE SHIFT
Operational relay networks of this kind should be tracked as evolving entities with their own tactics, techniques, and lifecycle characteristics — in the same way an intrusion set is tracked — rather than as static indicator lists. Individual addresses may participate for as little as a month. Block-and-move-on no longer describes an adequate response.
The authoritative indicator sets are the two government-published CSV files and the vendor’s continuously updated repository, all listed in the source register. The consolidated set below covers the platform infrastructure and is intended as a starting point for hunting, not as a complete list; the infrastructure CSV alone carries several hundred addresses, including at least three domains that do not appear in the advisory’s printed tables. Indicators should be investigated before being blocked, since a subset of this infrastructure touches legitimate commercial proxy services carrying uninvolved consumer traffic.
The advisory maps five techniques against Enterprise v19: Active Scanning via Vulnerability Scanning (T1595.002); Exploit Public-Facing Application (T1190); Server Software Component via Web Shell (T1505.003); Acquire Infrastructure via Virtual Private Server (T1583.003); and Develop Capabilities (T1587). This mapping is notably thin relative to the behavior the same document describes. Credential use, multi-hop proxy chaining, and distributed denial-of-service capability are all narrated in the text and unmapped in the matrix. Detection engineers building coverage from the ATT&CK mapping alone will underestimate the actor; the mapping should be treated as incomplete rather than as a scoping statement.
The following remain open at time of publication and constitute the collection priorities for follow-on reporting.
– Third-party tracking designation. No commercial vendor has assigned QTFY an independent cluster name, and no overlap with an existing numbered or named intrusion set has been published. Any claim of equivalence with a known group should be treated as unverified until a vendor publishes one.
– Post-seizure rebuild activity. No rebuild has been observed or reported in the sources reviewed. The persistence judgment above rests on precedent, not observation, and requires validation.
– Direct PRC government response. Coverage indicates Beijing rejected the allegations, but no specific Ministry of Foreign Affairs statement on this action was captured. Prior practice on comparable actions has been categorical denial coupled with accusations of defamation.
– Affidavit content. The supporting affidavit is a scanned document without a text layer. Its contents beyond what press reporting paraphrases and the advisory corroborates cannot be independently verified.
– Kentico KEV status. CVE-2019-10068 could not be confirmed on the Known Exploited Vulnerabilities catalogue in this cycle.
– Downstream customer identification. The advisory establishes that MSS and PLA units were customers but does not attribute specific intrusions to specific customers. The mapping between QTFY infrastructure and named intrusion sets is the highest-value outstanding question and is unlikely to be answered in unclassified reporting.
– Airport provider posture. Whether the commercial proxy provider was witting, negligent, or simply a vendor with a paying corporate customer is not addressed in any source reviewed. This bears directly on whether the technique is repeatable against other providers.
This assessment applies ICD 203 analytic tradecraft standards. Confidence expressions describe the analyst’s assessment of source quality and argument strength, not statistical probability. Observed reporting is distinguished throughout from analytic inference, and where a judgment rests on precedent rather than on collected evidence, that basis is stated in the judgment itself.
The allegations describing XJW’s customer relationships, the group’s composition, and the enumerated victim organizations derive from an affidavit that has not been tested in court and from an advisory that has not been independently replicated outside the authoring agencies and one vendor. No person has been charged. Nothing in this report should be read as asserting individual criminal culpability.
Corrections and reader-supplied telemetry are welcome and will be reflected in follow-on reporting. Analysts observing post-seizure rebuild activity — particularly new QScan worker check-in behavior, egress patterns consistent with the co-opted provider’s node naming, or fresh domain registrations following the established naming conventions — are encouraged to make contact.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.