FBI and Justice Department Take Down Chinese State-Backed Proxy Network Targeting US Infrastructure
Federal agents and cybersecurity researchers dismantled server tools operated by a Chinese government contractor that routed covert attacks against federal agencies and private enterprise networks.

Federal law enforcement authorities and network security researchers have dismantled key digital proxy infrastructure used by Chinese state-supported hackers to conceal intrusions against U.S. federal agencies and critical infrastructure providers, as first reported by Wired.
The Department of Justice disclosed on Wednesday that it took down operational domains supporting two specific software tools, identified as QTRouter and QScan. Federal prosecutors linked the malicious utilities to a Chinese threat actor designated as QTFY, which allegedly operates on behalf of a private government contractor based in China called Nanjing Xinjiuwei Network Technology Company. An FBI affidavit filed in connection with the domain seizures revealed that the contractor provided state clients with access to botnets comprised of hijacked internet-of-things devices and commercial proxy channels.
According to federal filings, clients using the proxy infrastructure included China's Ministry of State Security and the People's Liberation Army. U.S. officials indicated that state hackers relied on the proxy servers as relay nodes to execute cyber espionage operations extending back to at least 2018.
The Justice Department reported that threat actors utilizing the proxy network compromised systems across multiple major U.S. government entities. Confirmed victim institutions include the National Aeronautics and Space Administration, the Federal Reserve, the U.S. Senate, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the Department of Justice itself. Nanjing Xinjiuwei Network Technology Company could not be reached immediately for comment regarding the federal actions.
In addition to government bodies, court documents detailed widespread targeting across U.S. commercial and industrial sectors. The proxy infrastructure was leveraged to scan and target electrical power utilities, telecommunications service providers, healthcare facilities, financial institutions, and defense industrial base contractors. Federal authorities did not confirm the exact number of private entities successfully breached or the full extent of network access gained by the attackers.
Technical analysis conducted by security researchers explains how the dismantled software functioned within the hacking pipeline. QScan was deployed to identify security vulnerabilities in connected IoT devices, allowing attackers to enlist compromised hardware into botnets. QTRouter managed client access to those infected botnet nodes alongside virtual private servers rented from commercial providers. Over the past year, the threat group increasingly hijacked consumer virtual private network services that Chinese citizens routinely use to bypass the nation's internet censorship filters.
By routing state-sponsored attacks through civilian VPN nodes, the hackers effectively masked malicious network traffic within volume streams of normal civilian web activity. "It made it difficult for us to see the bad, state-sponsored traffic because there was so much typical user VPN traffic in the nodes they were coopting," Damon Rouse, a threat intelligence researcher at Lumen Technology's Black Lotus Labs, told Wired. Lumen, which assists in operating global internet backbone infrastructure, collaborated with law enforcement to execute "null-routing" procedures that rendered the targeted proxy domains inoperable.
Rouse described the Nanjing-based contractor as a functional "quartermaster" that supplied essential digital tooling to Chinese intelligence services. "The scale is really giant," Rouse noted, adding that "this is a very long lasting campaign, and this company and these people involved in it have very close ties to the highest levels of the People's Liberation Army."
U.S. Attorney General Todd Blanche issued a statement regarding the operation, warning that state-backed cyber operations against critical systems will face law enforcement responses. "State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted," Blanche stated. Justice Department filings did not include formal criminal indictments against individual company executives or operators. Researchers observed that while the activity focused on wide-scale information gathering rather than infrastructure disruption like the Volt Typhoon group, the contractor will likely attempt to re-establish infrastructure over time. "I think this will have a direct effect on the company and its perception in China. This is an egg-on-the-face moment for them," Rouse said. "I think we can also safely assume they'll pivot and stand up new infrastructure."
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


