DOJ and FBI Seize QScan and QTRouter Platforms Used in Chinese State-Sponsored Campaign Against U.S. Government Agencies
August 26, 2026
The Department of Justice and FBI today announced the court-authorized seizure of three internet domains tied to two Chinese state-sponsored hacking platforms: QScan and QTRouter [1]. The confirmed victim list reads like a catalog of America's most sensitive institutions: NASA, the Federal Reserve, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate [1]. Unnamed hospitals, telecommunications providers, power companies, financial institutions, and defense contractors were also targeted [1][5]. The group behind these tools has been operating since at least 2018 [3][7].
This is not a one-off takedown. The Justice Department described the action as "the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China" [1].
The Contractor Model: QTFY, Nanjing Xinjiuwei, and Their Clients
Court documents unsealed in the Southern District of California name a PRC state-sponsored group called QTFY (also tracked as QT and QTCYBER) as the creator and operator of both platforms [1][2]. QTFY was employed by Nanjing Xinjiuwei Network Technology Company (εδΊ¬ι«ηη»΄η½η»η§ζζιε ¬εΈ), a China-based firm established in 2018 that had just 17 employees as of last year, according to Chinese business records [6]. The company has no publicly traceable web presence [7].
QTFY's paying customers include the PRC's Ministry of State Security (MSS) and the People's Liberation Army (PLA) [1][5]. Court documents reveal that the group includes former members of the PLA [2]. FBI Assistant Director Brett Leatherman stated that Nanjing Xinjiuwei "sells stolen data and hacking services to Chinese military and intelligence agencies" and that QTFY also maintained unspecified customers outside the Chinese government [3]. QTFY sold access to QScan and QTRouter to third-party actors beyond MSS and PLA, enabling a broader hacker-for-hire ecosystem [2].
Dakota Cary, a China analyst at SentinelOne, provided context in media reporting on the seizure: "Over the last decade, the number of companies offering niche offensive services has exploded" [3]. This is the operational model China has refined over the past decade: a nominally private tech company serving as a contractor for military and intelligence services, providing enough separation for plausible deniability while delivering state-grade capabilities.
The Digital Quartermaster: A Four-Component Framework
Lumen's Black Lotus Labs, which tracked QTFY's infrastructure for over 18 months, describes the group as a "digital quartermaster" that industrialized the construction of Operational Relay Box (ORB) networks for downstream China-nexus espionage operators [4][2]. Black Lotus Labs assessed that the quartermaster has been active since at least 2018 [4].
The framework comprises four interconnected components [4][2]:
QScan: Reconnaissance and Mass Infection
QScan is a scanning and exploitation platform that identifies and profiles high-value targets, collecting open ports, application banners, OS fingerprints, and configuration data [2][4]. It also scans and automatically infects thousands of IoT devices worldwide, feeding them into the QTRouter network [1][3]. The DOJ describes it bluntly: "Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet" [3].
QScan's task brokering infrastructure relied on a central RabbitMQ-based engine at mq-task.qt-proxy.org (154.64.238.222) and a Redis database cluster for scan results at mq-result.qt-proxy.org (154.64.238.247) [4].
Fast Labyrinth: The Encrypted ORB Relay
Fast Labyrinth is the operational layer. Rather than building a conventional ORB from scratch using only compromised devices, QTFY purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws [2][4]. These co-opted nodes formed an encrypted relay network that blended espionage traffic with legitimate consumer proxy traffic and automatically rotated its egress infrastructure [2]. The effect: malicious traffic appeared to originate from non-PRC computers, including devices geographically local to targeted networks [1].
Black Lotus Labs identified that targets discovered or profiled by QScan later appeared in bidirectional communications through Fast Labyrinth, providing the strongest evidence linking the reconnaissance and operational access phases [4]. Rather than generating large traffic spikes, the network patterns reflected a "steady, precise focus on select targets," a deliberate counter-detection tradecraft [4].
Fast Labyrinth egress nodes operated under yotocloud.com subdomains following patterns like flanycast-xxxx.yotocloud.com and flnode-xxxx.yotocloud.com [4]. The admin plane was accessible at www.qtproxy.xyz (1.32.216.171), and an active operational jump box ran at jump.qt-proxy.org (8.148.149.147) [4].
QTRouter: Physical Access Device
QTRouter is a preconfigured physical device that manages operator and customer access to the proxy infrastructure and proxy node management system [4][2]. The DOJ describes it as an "obfuscation network" consisting of compromised IoT devices, commercial proxy service devices, and leased virtual private servers [1][2][7]. It allowed Chinese actors to make cyberattacks appear as though they originated from other countries, and in some cases made incidents look like local attackers [3].
QTProxy: Route Management
QTProxy manages Fast Labyrinth operational nodes, allowing operators to use preconfigured relays or tailor unique paths to target entities [4][2]. The quartermaster's master control portal was actively interacting with, testing, and calibrating fastlink.ws nodes before leasing access to downstream threat actors [4].
Together, these components "streamline target discovery, communication routing and operational access, allowing Chinese espionage operators to conduct activities more efficiently while hiding their tracks" [4].
The Trail Back to 2019: CVE-2019-11510 and NASA
One of the first attacks investigated by the FBI was a 2019 intrusion at NASA in which hackers attempted to exploit CVE-2019-11510, an arbitrary file read vulnerability in Pulse Secure VPN [3][7]. Investigators traced the IP addresses used in the NASA attack back to locations and email addresses in China [3]. That investigation launched a years-long effort to unravel QTFY's infrastructure, which continued through a 2026 attack on the U.S. Senate [3]. The affidavit does not explain whether specific senators or committees were attacked, and the DOJ declined to comment further [3].
The full damage assessment has not been made public [5][6]. Any counterintelligence evaluation of what was actually taken is likely to remain classified [6]. CNN described the operation as "in some ways the culmination of an intense spy-on-spy affair" [6]. The FBI, and likely other intelligence community elements, spent months unraveling the deception operation [6].
The Seizure: Architectural Fragility as a Weapon
The three seized domains are qtproxy.xyz, qt-proxy.org, and qt-team.com [2][7]. All three now display law enforcement seizure banners [7]. These domains were hard-coded into both QScan and QTRouter malware and used for essential tasks including communication and authentication [1][5]. The seizures rendered both platforms inoperable [1][5].
Black Lotus Labs also disrupted QTFY infrastructure independently by null-routing traffic to known infrastructure points used by the quartermaster operators [2][4]. The hard-coded infrastructure model that made these tools easy to deploy at scale also made them brittle against coordinated legal and technical disruption.
IOC Table
| Type | Value | Context | Confidence | Source |
|---|---|---|---|---|
| Domain | qtproxy.xyz |
Hard-coded C2 domain; seized by DOJ/FBI | HIGH | [1] |
| Domain | qt-proxy.org |
Hard-coded C2 domain; seized by DOJ/FBI | HIGH | [1] |
| Domain | qt-team.com |
Hard-coded C2 domain; seized by DOJ/FBI | HIGH | [1] |
| Domain | fastlink.ws |
Commercial proxy service co-opted for Fast Labyrinth | HIGH | [2] |
| Domain | yotocloud.com |
Underlying transit nodes co-opted for Fast Labyrinth | HIGH | [4] |
| Domain | mq-task.qt-proxy.org |
QScan central task broker (RabbitMQ) | HIGH | [4] |
| Domain | mq-result.qt-proxy.org |
QScan Redis results database | HIGH | [4] |
| Domain | jump.qt-proxy.org |
Fast Labyrinth operational jump box | HIGH | [4] |
| Domain | instantmessagehub.tech |
Probable Fast Labyrinth admin interface (LOW CONFIDENCE) | LOW | [4] |
| Domain | www.qtproxy.xyz |
Fast Labyrinth admin plane | HIGH | [4] |
| Domain | flanycast-us.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-us-bak.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-hk.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-hk-bak.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-jp.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-tw.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flanycast-sg.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flnode-ulus.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| Domain | flnode-dl.yotocloud.com |
Fast Labyrinth egress node | HIGH | [4] |
| IP | 154.64.238.222 |
mq-task.qt-proxy.org; QScan task broker | HIGH | [4] |
| IP | 154.64.238.247 |
mq-result.qt-proxy.org; QScan results DB | HIGH | [4] |
| IP | 1.32.216.171 |
www.qtproxy.xyz; Fast Labyrinth admin plane | HIGH | [4] |
| IP | 8.148.149.147 |
jump.qt-proxy.org; operational jump box | HIGH | [4] |
| IP | 47.76.131.175 |
instantmessagehub.tech; probable admin interface (LOW CONFIDENCE) | LOW | [4] |
| Malware | QScan |
Scanning and exploitation platform | HIGH | [1] |
| Malware | QTRouter |
Obfuscation network / ORB relay platform | HIGH | [1] |
| Malware | QTProxy |
Relay selection and route management tool | HIGH | [2] |
| Malware | Fast Labyrinth |
Encrypted ORB relay network | HIGH | [2][4] |
MITRE ATT&CK Mapping
| Technique ID | Name | Context |
|---|---|---|
| T1595.001 | Active Scanning: Scanning IP Blocks | QScan profiles targets via port scanning and OS fingerprinting [2][4] |
| T1190 | Exploit Public-Facing Application | CVE-2019-11510 (Pulse Secure VPN) exploited in 2019 NASA intrusion [3][7] |
| T1584.005 | Compromise Infrastructure: Botnet | IoT devices and SOHO routers compromised and incorporated into ORB relay mesh [1][2] |
| T1583 | Acquire Infrastructure | Premium access purchased from fastlink.ws commercial proxy service [2][4]. Note: specific subtechnique (e.g., T1583.003 Virtual Private Server) depends on the nature of the purchased proxy nodes. |
| T1090.003 | Proxy: Multi-hop Proxy | QTRouter and Fast Labyrinth route traffic through globally distributed compromised and commercial nodes [1][4] |
Detection and Hunting
Domain and DNS Indicators. The most immediate detection opportunity is DNS. Query logs should be searched for any resolution attempts to the seized domains (qtproxy.xyz, qt-proxy.org, qt-team.com) and the Fast Labyrinth infrastructure domains (yotocloud.com subdomains, instantmessagehub.tech, fastlink.ws) [1][4]. Any historical hits, even failed resolutions, indicate a compromised device on your network that was part of or communicating with the ORB mesh.
index=dns (query="*qtproxy.xyz" OR query="*qt-proxy.org" OR query="*qt-team.com" OR query="*yotocloud.com" OR query="*instantmessagehub.tech" OR query="*fastlink.ws")
| stats count by src_ip, query, answer
IP-based Hunting. The five IP addresses listed in the IOC table should be searched across firewall logs, proxy logs, and netflow data. Pay particular attention to 154.64.238.222 and 154.64.238.247, which served as QScan's task broker and results database respectively [4].
IoT Device Audit. QScan targeted IoT devices, SOHO routers, and security cameras for automatic infection [1][3]. Any enterprise-managed network should audit all IoT and SOHO devices for unexpected outbound connections, particularly to the domains and IPs listed above. Devices that cannot be audited should be isolated on segmented VLANs with strict egress filtering.
Pulse Secure / Ivanti VPN Review. The initial FBI investigation traced back to exploitation of CVE-2019-11510 in Pulse Secure VPN [3][7]. Organizations still running Pulse Secure (now Ivanti Connect Secure) should verify patches for CVE-2019-11510 (patched in Pulse Connect Secure 9.0R3.4 and later) and review historical access logs for anomalous authentication events. Note: Pulse Connect Secure has reached end-of-support. Organizations should migrate to current Ivanti Connect Secure versions. Any appliance still vulnerable to CVE-2019-11510 after seven years should be treated as presumed compromised and subjected to full forensic review.
ORB Traffic Patterns. Fast Labyrinth was designed to avoid traffic spikes, instead producing "steady, precise" communication patterns with select targets [4]. Traditional volume-based alerting will not catch this. Hunt for low-volume, periodic beaconing to residential IP ranges or known commercial proxy services, particularly from sensitive network segments.
Sigma Rule: DNS Query for QTFY Infrastructure
title: DNS Query to QTFY / Fast Labyrinth Infrastructure Domains
id: a7c3e2f1-8b4d-4e9a-b5c6-1d2e3f4a5b6c
status: experimental
author: RedSheepSec
date: 2026/08/26
description: Detects DNS queries to domains associated with the QTFY quartermaster infrastructure including seized C2 domains and Fast Labyrinth relay nodes.
logsource:
category: dns
detection:
selection:
query|endswith:
- 'qtproxy.xyz'
- 'qt-proxy.org'
- 'qt-team.com'
- 'yotocloud.com'
- 'instantmessagehub.tech'
condition: selection
falsepositives:
- Unlikely in enterprise environments
level: high
tags:
- attack.command_and_control
- attack.t1090.003
Analysis
This takedown represents a meaningful tactical disruption but not a strategic defeat of Chinese cyber espionage capability. The hard-coded domain architecture was a gift to law enforcement. Once seized, both platforms stopped functioning [1][5]. But QTFY's operators are experienced enough to rebuild. The quartermaster model itself -- packaging reconnaissance, infection, relay management, and route selection into a reusable service layer -- is the real product [4]. The domains are replaceable. The operational concept is not easily disrupted.
The scope of confirmed victims is significant. The Federal Reserve, NASA, DOJ, DOE, HHS, NIH, and the U.S. Senate are all named in court documents [1][5]. This is consistent with a systematic intelligence collection campaign targeting America's scientific, financial, legislative, and law enforcement pillars. The inclusion of hospitals, power companies, and telecoms alongside these agencies suggests both espionage and possible pre-positioning objectives [5][6].
Beijing routinely denies responsibility for hacking activity. The Chinese Embassy did not immediately return comment requests on this operation [6].
Red Sheep Assessment
Confidence: Moderate-High
The sources collectively point to something the DOJ press release does not state directly: QTFY is, in our assessment, not just a hacking group but a managed service provider for Chinese state cyber operations. The four-component architecture, the commercial proxy purchases, the client list spanning MSS and PLA plus unnamed third parties -- this is a mature SaaS model for espionage. Black Lotus Labs calls it a "quartermaster." A more precise analogy is an infrastructure-as-a-service platform purpose-built for state-sponsored intrusions.
The 17-employee headcount of Nanjing Xinjiuwei [6], set against the reported scale of the operation, suggests one of two things: either the company is much larger than its official Chinese business records indicate, or it is a thin corporate shell sitting atop a deeper PLA/MSS operational apparatus. Both scenarios are consistent with documented Chinese contractor models exposed in previous cases, including the i-Soon (Anxun) leak.
The fragility of the hard-coded domain architecture is puzzling for a group that has reportedly been active since 2018. One explanation: the operators did not anticipate coordinated U.S. law enforcement action against domains registered through providers subject to U.S. legal process. Another possibility is that the domains were considered expendable infrastructure, and QTFY has already migrated to alternative C2 channels that have not been publicly disclosed. Federal agencies reportedly planning to release a techniques advisory [6] likely have additional indicators they are holding for coordinated disclosure.
The contrarian read: this seizure may have come too late to prevent the primary intelligence collection objectives from being achieved. Years of reported access to NASA, the Federal Reserve, and DOE means data exfiltration likely occurred well before today's press conference. The disruption protects future targets but does not recover what was already taken.
Defender's Checklist
- ▢[ ] Hunt for QTFY domains in DNS logs immediately. Search for
qtproxy.xyz,qt-proxy.org,qt-team.com,yotocloud.comsubdomains (especiallyflanycast-andflnode-patterns),instantmessagehub.tech, andfastlink.wsacross all DNS logging. Any hit, including NXDOMAIN responses after today's seizure, means a device on your network was part of or communicating with this infrastructure.
- ▢[ ] Block the five known IPs at perimeter firewalls and hunt in historical netflow. Add
154.64.238.222,154.64.238.247,1.32.216.171,8.148.149.147, and47.76.131.175to blocklists and search 90+ days of firewall and proxy logs for any prior connections.
- ▢[ ] Audit all IoT devices, SOHO routers, and IP cameras for compromise. QScan's primary function was mass IoT infection [1][3]. Segment unmanaged IoT devices onto isolated VLANs with restricted egress. Devices that cannot be patched or audited should be replaced.
- ▢[ ] Verify Pulse Secure / Ivanti Connect Secure patching status for CVE-2019-11510. Ensure appliances are running Pulse Connect Secure 9.0R3.4 or later. Pulse Connect Secure has reached end-of-support; organizations should migrate to current Ivanti Connect Secure versions. Any appliance still vulnerable to CVE-2019-11510 after seven years should be treated as presumed compromised. Review VPN appliance logs for historical anomalous access, particularly from residential or commercial proxy IP ranges [3][7].
- ▢[ ] Monitor for follow-on CISA and FBI advisories. Federal agencies are reportedly planning to release additional technical advisories with further indicators [6]. Monitor CISA's advisories page and FBI flash alerts for supplementary IOCs and TTPs.
References
[1] https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
[2] https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
[3] https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools
[4] https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model
[5] https://www.cnbc.com/2026/08/26/china-hacker-federal-reserve-doj-nasa.html
[6] https://www.cnn.com/2026/08/26/politics/us-alleged-chinese-cyber-spying-campaign
[7] https://www.tomshardware.com/tech-industry/cyber-security/us-justice-department-claims-chinese-state-sponsored-hackers-infiltrated-systems-at-nasa-senate-federal-reserve-and-more-fbi-moves-forward-with-domain-seizures
Event Timeline
Timeline
Entity Relationships
Entity Graph (12 entities, 12 relationships)
Diamond Model
Diamond Model
Hunt Guide: QTFY / QScan / QTRouter β Chinese State-Sponsored ORB Network Infrastructure
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If QTFY infrastructure (QScan, QTRouter, Fast Labyrinth, QTProxy) has been active in our environment, we expect to observe DNS resolutions to seized C2 domains (qtproxy.xyz, qt-proxy.org, qt-team.com) and Fast Labyrinth relay domains (yotocloud.com subdomains, fastlink.ws), network connections to known QTFY IP addresses (154.64.238.222, 154.64.238.247, 1.32.216.171, 8.148.149.147, 47.76.131.175), exploitation attempts against CVE-2019-11510 on Pulse Secure/Ivanti VPN appliances, and low-volume periodic beaconing from IoT/SOHO devices to residential or commercial proxy IP ranges in DNS logs, firewall logs, Zeek/Corelight network metadata, and endpoint telemetry.
Intelligence Summary: The DOJ and FBI seized three domains (qtproxy.xyz, qt-proxy.org, qt-team.com) that were hard-coded C2 infrastructure for QScan and QTRouter, two platforms operated by the Chinese state-sponsored group QTFY (employed by Nanjing Xinjiuwei Network Technology Company) and sold as hacking services to the PRC Ministry of State Security and People's Liberation Army. Confirmed victims include NASA, the Federal Reserve, the U.S. Senate, DOJ, DOE, HHS, NIH, along with unnamed hospitals, telecoms, power companies, and defense contractors, with the campaign active since at least 2018. Lumen's Black Lotus Labs describes QTFY as a 'digital quartermaster' that industrialized Operational Relay Box (ORB) networks via a four-component framework β QScan for reconnaissance/IoT infection, Fast Labyrinth for encrypted proxy relay, QTRouter for physical access management, and QTProxy for route management β blending espionage traffic with legitimate commercial proxy traffic to evade detection.
Confidence: High | Priority: Critical
Scope
- Networks: All enterprise network segments including DMZ, internal server VLANs, IoT/SOHO device segments, VPN concentrator networks, and any segments hosting Pulse Secure/Ivanti Connect Secure appliances. Special attention to medical IoT devices, IP cameras, and SOHO routers that may have been compromised by QScan for ORB mesh participation.
- Timeframe: Retrospective hunt covering at minimum 90 days of historical data. Given QTFY has been active since 2018 and the campaign spans 2019-2026, extend to maximum available log retention (ideally 12+ months) for high-confidence IOC matches. Ongoing monitoring should be established for all indicators.
- Priority Systems: Pulse Secure / Ivanti Connect Secure VPN appliances (CVE-2019-11510); IoT devices, SOHO routers, and IP cameras on enterprise networks; internet-facing services; DNS resolvers; perimeter firewalls; systems in segments hosting sensitive research, financial, or command-and-control data
MITRE ATT&CK Techniques
T1595.001 β Active Scanning: Scanning IP Blocks (Reconnaissance) [P1]
QScan profiles targets via port scanning, OS fingerprinting, application banner grabbing, and configuration data collection. It also mass-scans the internet for vulnerable IoT devices (SOHO routers, IP cameras) for automatic infection and incorporation into the QTRouter botnet. The scanning task infrastructure relied on a RabbitMQ broker at mq-task.qt-proxy.org (154.64.238.222).
Splunk SPL:
index=corelight sourcetype=corelight_conn (id_resp_h="154.64.238.222" OR id_resp_h="154.64.238.247" OR id_orig_h="154.64.238.222" OR id_orig_h="154.64.238.247")
| stats count values(id_resp_p) as dest_ports values(service) as services by id_orig_h, id_resp_h
| sort -count
Elastic KQL:
(destination.ip:"154.64.238.222" OR destination.ip:"154.64.238.247" OR source.ip:"154.64.238.222" OR source.ip:"154.64.238.247")
Sigma Rule:
title: Network Connection to QScan Task Broker or Results Database
id: b8d4e5f6-1a2b-3c4d-5e6f-7a8b9c0d1e2f
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects network connections to QScan RabbitMQ task broker (154.64.238.222) or Redis results database (154.64.238.247) IPs associated with QTFY quartermaster infrastructure.
logsource:
category: network_connection
detection:
selection:
dst_ip|contains:
- '154.64.238.222'
- '154.64.238.247'
condition: selection
falsepositives:
- Unlikely; these IPs are confirmed QTFY infrastructure
level: critical
tags:
- attack.reconnaissance
- attack.t1595.001
These IPs were identified by Black Lotus Labs as QScan's central task broker and results database. Any connection to these IPs from internal assets is a high-fidelity indicator of compromise or ORB mesh participation. Check historical logs going back 90+ days.
T1190 β Exploit Public-Facing Application (Initial Access) [P1]
QTFY-linked hackers exploited CVE-2019-11510, an arbitrary file read vulnerability in Pulse Secure VPN, during a 2019 intrusion at NASA. This vulnerability allows unauthenticated remote attackers to read arbitrary files, including sensitive system files containing credentials. Organizations still running Pulse Secure (now Ivanti Connect Secure) remain at risk.
Splunk SPL:
index=corelight sourcetype=corelight_http (uri="*/dana-na/auth/deviceid.cgi*" OR uri="*/dana/html5acc/guacamole/*" OR uri="*dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd*" OR uri="*?template=saltproc*")
| stats count by id_orig_h, id_resp_h, uri, status_code
| sort -count
Elastic KQL:
url.path:(*dana-na* AND *deviceid.cgi*) OR url.path:(*dana* AND *guacamole* AND *etc/passwd*) OR url.path:(*template=saltproc*)
Sigma Rule:
title: CVE-2019-11510 Pulse Secure VPN Exploitation Attempt
id: c9e5f6a7-2b3c-4d5e-6f7a-8b9c0d1e2f3a
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects HTTP requests indicative of CVE-2019-11510 exploitation attempts against Pulse Secure VPN appliances, as used by QTFY in the 2019 NASA intrusion.
logsource:
category: webserver
detection:
selection_uri:
cs-uri-query|contains:
- 'dana-na/../dana/html5acc/guacamole'
- '/etc/passwd'
- '/etc/hosts'
- 'dana-na/auth/deviceid.cgi'
condition: selection_uri
falsepositives:
- Legitimate Pulse Secure admin access (review URI patterns)
- Vulnerability scanners (Nessus, Qualys)
level: critical
tags:
- attack.initial_access
- attack.t1190
- cve.2019.11510
CVE-2019-11510 was patched in Pulse Connect Secure 9.0R3.4 and later. Pulse Connect Secure has reached end-of-support. Any appliance still vulnerable after seven years should be treated as presumed compromised. Check VPN logs for anomalous authentication from residential/commercial proxy IP ranges.
T1584.005 β Compromise Infrastructure: Botnet (Resource Development) [P1]
QScan automatically infects thousands of IoT devices worldwide (SOHO routers, IP cameras, smart devices) and feeds them into the QTRouter relay network. These compromised devices form the Operational Relay Box (ORB) mesh that obscures the origin of espionage traffic.
Splunk SPL:
index=corelight sourcetype=corelight_dns (query="*qtproxy.xyz" OR query="*qt-proxy.org" OR query="*qt-team.com" OR query="*yotocloud.com" OR query="*fastlink.ws" OR query="*instantmessagehub.tech")
| stats count values(answers) as resolved_ips by id_orig_h, query
| sort -count
Elastic KQL:
dns.question.name:(*qtproxy.xyz OR *qt-proxy.org OR *qt-team.com OR *yotocloud.com OR *fastlink.ws OR *instantmessagehub.tech)
Sigma Rule:
title: DNS Query to QTFY Seized C2 Domains or Fast Labyrinth Infrastructure
id: a7c3e2f1-8b4d-4e9a-b5c6-1d2e3f4a5b6c
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects DNS queries to domains associated with the QTFY quartermaster infrastructure including seized C2 domains and Fast Labyrinth relay nodes. Any hit, including NXDOMAIN responses after seizure, indicates a device was part of or communicating with the ORB mesh.
logsource:
category: dns
detection:
selection:
query|endswith:
- 'qtproxy.xyz'
- 'qt-proxy.org'
- 'qt-team.com'
- 'yotocloud.com'
- 'instantmessagehub.tech'
- 'fastlink.ws'
condition: selection
falsepositives:
- Unlikely in enterprise environments
level: critical
tags:
- attack.resource_development
- attack.t1584.005
- attack.command_and_control
- attack.t1090.003
The three seized domains (qtproxy.xyz, qt-proxy.org, qt-team.com) were hard-coded into QScan and QTRouter malware. Post-seizure, DNS queries will resolve to law enforcement sinkhole IPs or return NXDOMAIN. Any historical or current resolution attempt is a critical finding. Also hunt for yotocloud.com subdomains matching patterns flanycast- and flnode-.
T1583 β Acquire Infrastructure (Resource Development) [P1]
QTFY purchased premium access to selected nodes operated by the Chinese commercial proxy service fastlink.ws. These co-opted commercial proxy nodes were integrated into the Fast Labyrinth encrypted relay network, blending espionage traffic with legitimate consumer proxy traffic.
Splunk SPL:
index=dns (query="*fastlink.ws" OR query="*yotocloud.com")
| stats count by src_ip, query, answer
| sort -count
Elastic KQL:
dns.question.name:(*fastlink.ws OR *yotocloud.com)
Sigma Rule:
title: DNS Resolution to Fast Labyrinth Commercial Proxy Infrastructure
id: d0e1f2a3-4b5c-6d7e-8f9a-0b1c2d3e4f5a
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects DNS queries to fastlink.ws and yotocloud.com domains associated with the Fast Labyrinth encrypted ORB relay network used by QTFY.
logsource:
category: dns
detection:
selection:
query|endswith:
- 'fastlink.ws'
- 'yotocloud.com'
condition: selection
falsepositives:
- Possible if users are using fastlink.ws as a legitimate commercial proxy service; correlate with context
level: high
tags:
- attack.resource_development
- attack.t1583
fastlink.ws is a legitimate commercial proxy service that was co-opted by QTFY. False positives are possible if users intentionally use this service. Correlate with other QTFY indicators for confirmation. The yotocloud.com subdomains (flanycast-, flnode-) are more specific indicators.
T1090.003 β Proxy: Multi-hop Proxy (Command and Control) [P1]
QTRouter and Fast Labyrinth route espionage traffic through globally distributed compromised IoT devices, commercial proxy service nodes, and leased VPS instances. This multi-hop architecture makes traffic appear to originate from non-PRC computers, including devices geographically local to targeted networks. The traffic pattern is described as 'steady, precise focus on select targets' rather than large spikes, deliberately evading volume-based detection.
Splunk SPL:
index=firewall-pan sourcetype="pan:traffic:aggregated" (dest_ip="154.64.238.222" OR dest_ip="154.64.238.247" OR dest_ip="1.32.216.171" OR dest_ip="8.148.149.147" OR dest_ip="47.76.131.175" OR src_ip="154.64.238.222" OR src_ip="154.64.238.247" OR src_ip="1.32.216.171" OR src_ip="8.148.149.147" OR src_ip="47.76.131.175")
| stats count values(dest_port) as ports values(action) as actions by src_ip, dest_ip
| sort -count
Elastic KQL:
(destination.ip:("154.64.238.222" OR "154.64.238.247" OR "1.32.216.171" OR "8.148.149.147" OR "47.76.131.175") OR source.ip:("154.64.238.222" OR "154.64.238.247" OR "1.32.216.171" OR "8.148.149.147" OR "47.76.131.175"))
Sigma Rule:
title: Network Connection to QTFY Fast Labyrinth or QTRouter Infrastructure IPs
id: e1f2a3b4-5c6d-7e8f-9a0b-1c2d3e4f5a6b
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects network connections to known QTFY infrastructure IP addresses including QScan task broker, results database, Fast Labyrinth admin plane, and operational jump box.
logsource:
category: firewall
detection:
selection:
dst_ip:
- '154.64.238.222'
- '154.64.238.247'
- '1.32.216.171'
- '8.148.149.147'
- '47.76.131.175'
condition: selection
falsepositives:
- Unlikely; these are confirmed QTFY infrastructure IPs. 47.76.131.175 is low confidence.
level: critical
tags:
- attack.command_and_control
- attack.t1090.003
Fast Labyrinth was designed to avoid traffic spikes. Hunt for low-volume, periodic beaconing patterns rather than high-volume connections. The IP 47.76.131.175 (instantmessagehub.tech) is assessed with LOW CONFIDENCE per the source report. Prioritize the other four IPs.
T1071 β Application Layer Protocol (Command and Control) [P2]
QScan's task brokering infrastructure uses RabbitMQ (AMQP protocol, typically port 5672) for task distribution and Redis for results storage. Detecting AMQP or Redis protocol traffic to external IPs may reveal QScan participation. Fast Labyrinth egress nodes use HTTPS for encrypted relay communications.
Splunk SPL:
index=corelight sourcetype=corelight_conn (id_resp_p=5672 OR id_resp_p=6379) NOT (id_resp_h="10.*" OR id_resp_h="172.16.*" OR id_resp_h="192.168.*")
| stats count values(id_resp_h) as dest_ips by id_orig_h, id_resp_p, service
| where count > 5
| sort -count
Elastic KQL:
(destination.port:5672 OR destination.port:6379) AND NOT destination.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16)
Sigma Rule:
title: Outbound AMQP or Redis Connection to External IP
id: f2a3b4c5-6d7e-8f9a-0b1c-2d3e4f5a6b7c
status: experimental
author: RedSheepSec
date: 2026/08/27
description: Detects outbound connections on AMQP (5672) or Redis (6379) ports to external IP addresses, which may indicate QScan task broker or results database communication.
logsource:
category: network_connection
detection:
selection:
dst_port:
- 5672
- 6379
filter_internal:
dst_ip|startswith:
- '10.'
- '172.16.'
- '172.17.'
- '172.18.'
- '172.19.'
- '172.20.'
- '172.21.'
- '172.22.'
- '172.23.'
- '172.24.'
- '172.25.'
- '172.26.'
- '172.27.'
- '172.28.'
- '172.29.'
- '172.30.'
- '172.31.'
- '192.168.'
condition: selection and not filter_internal
falsepositives:
- Legitimate cloud-hosted RabbitMQ or Redis services
- SaaS integrations using AMQP
level: medium
tags:
- attack.command_and_control
- attack.t1071
This is a behavioral detection (P2). Many organizations use cloud-hosted message queues and Redis. Tune by whitelisting known legitimate AMQP/Redis endpoints. Correlate hits with other QTFY IOCs for confirmation. QScan specifically used RabbitMQ at mq-task.qt-proxy.org (154.64.238.222) on standard AMQP ports.
Indicators of Compromise
| Type | Value | Context |
|---|---|---|
| domain | qtproxy.xyz |
Hard-coded C2 domain for QScan and QTRouter; seized by DOJ/FBI on Aug 26, 2026 |
| domain | qt-proxy.org |
Hard-coded C2 domain for QScan and QTRouter; seized by DOJ/FBI on Aug 26, 2026; parent domain for mq-task, mq-result, and jump subdomains |
| domain | qt-team.com |
Hard-coded C2 domain for QScan and QTRouter; seized by DOJ/FBI on Aug 26, 2026 |
| domain | fastlink.ws |
Chinese commercial proxy service co-opted by QTFY for Fast Labyrinth ORB relay network |
| domain | yotocloud.com |
Parent domain for Fast Labyrinth egress nodes; subdomains follow patterns flanycast-xxxx.yotocloud.com and flnode-xxxx.yotocloud.com |
| domain | mq-task.qt-proxy.org |
QScan central task broker (RabbitMQ engine) resolving to 154.64.238.222 |
| domain | mq-result.qt-proxy.org |
QScan Redis results database cluster resolving to 154.64.238.247 |
| domain | jump.qt-proxy.org |
Fast Labyrinth operational jump box resolving to 8.148.149.147 |
| domain | instantmessagehub.tech |
Probable Fast Labyrinth admin interface (LOW CONFIDENCE per source report) resolving to 47.76.131.175 |
| domain | www.qtproxy.xyz |
Fast Labyrinth admin plane resolving to 1.32.216.171 |
| domain | flanycast-us.yotocloud.com |
Fast Labyrinth egress node (US) |
| domain | flanycast-us-bak.yotocloud.com |
Fast Labyrinth egress node (US backup) |
| domain | flanycast-hk.yotocloud.com |
Fast Labyrinth egress node (Hong Kong) |
| domain | flanycast-hk-bak.yotocloud.com |
Fast Labyrinth egress node (Hong Kong backup) |
| domain | flanycast-jp.yotocloud.com |
Fast Labyrinth egress node (Japan) |
| domain | flanycast-tw.yotocloud.com |
Fast Labyrinth egress node (Taiwan) |
| domain | flanycast-sg.yotocloud.com |
Fast Labyrinth egress node (Singapore) |
| domain | flnode-ulus.yotocloud.com |
Fast Labyrinth egress node |
| domain | flnode-dl.yotocloud.com |
Fast Labyrinth egress node |
| ip | 154.64.238.222 |
QScan central task broker (RabbitMQ) at mq-task.qt-proxy.org |
| ip | 154.64.238.247 |
QScan Redis results database at mq-result.qt-proxy.org |
| ip | 1.32.216.171 |
Fast Labyrinth admin plane at www.qtproxy.xyz |
| ip | 8.148.149.147 |
Fast Labyrinth operational jump box at jump.qt-proxy.org |
| ip | 47.76.131.175 |
Probable Fast Labyrinth admin interface at instantmessagehub.tech (LOW CONFIDENCE) |
IOC Sweep Queries (Splunk):
index=dns (query="*qtproxy.xyz") OR index=corelight sourcetype=corelight_dns (query="*qtproxy.xyz") OR index=corelight sourcetype=corelight_http (host="*qtproxy.xyz") OR index=firewall-pan (dest_host="*qtproxy.xyz" OR url="*qtproxy.xyz")
| stats count by _time, src_ip, query, dest_ip
| sort -_time
index=dns (query="*qt-proxy.org") OR index=corelight sourcetype=corelight_dns (query="*qt-proxy.org") OR index=corelight sourcetype=corelight_http (host="*qt-proxy.org") OR index=firewall-pan (dest_host="*qt-proxy.org" OR url="*qt-proxy.org")
| stats count by _time, src_ip, query, dest_ip
| sort -_time
index=dns (query="*qt-team.com") OR index=corelight sourcetype=corelight_dns (query="*qt-team.com") OR index=corelight sourcetype=corelight_http (host="*qt-team.com") OR index=firewall-pan (dest_host="*qt-team.com" OR url="*qt-team.com")
| stats count by _time, src_ip, query, dest_ip
| sort -_time
index=dns (query="*fastlink.ws") OR index=corelight sourcetype=corelight_dns (query="*fastlink.ws") OR index=corelight sourcetype=corelight_http (host="*fastlink.ws")
| stats count by _time, src_ip, query, dest_ip
| sort -_time
index=dns (query="*yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="*yotocloud.com") OR index=corelight sourcetype=corelight_http (host="*yotocloud.com")
| stats count by _time, src_ip, query, dest_ip
| sort -_time
index=dns (query="mq-task.qt-proxy.org") OR index=corelight sourcetype=corelight_dns (query="mq-task.qt-proxy.org")
| stats count by _time, src_ip, query, answer
| sort -_time
index=dns (query="mq-result.qt-proxy.org") OR index=corelight sourcetype=corelight_dns (query="mq-result.qt-proxy.org")
| stats count by _time, src_ip, query, answer
| sort -_time
index=dns (query="jump.qt-proxy.org") OR index=corelight sourcetype=corelight_dns (query="jump.qt-proxy.org")
| stats count by _time, src_ip, query, answer
| sort -_time
index=dns (query="*instantmessagehub.tech") OR index=corelight sourcetype=corelight_dns (query="*instantmessagehub.tech")
| stats count by _time, src_ip, query, answer
| sort -_time
index=dns (query="www.qtproxy.xyz") OR index=corelight sourcetype=corelight_dns (query="www.qtproxy.xyz")
| stats count by _time, src_ip, query, answer
| sort -_time
index=dns (query="flanycast-us.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-us.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-us-bak.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-us-bak.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-hk.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-hk.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-hk-bak.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-hk-bak.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-jp.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-jp.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-tw.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-tw.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flanycast-sg.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flanycast-sg.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flnode-ulus.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flnode-ulus.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=dns (query="flnode-dl.yotocloud.com") OR index=corelight sourcetype=corelight_dns (query="flnode-dl.yotocloud.com")
| stats count by _time, src_ip, query, answer
index=firewall-pan (src_ip="154.64.238.222" OR dest_ip="154.64.238.222") OR index=corelight sourcetype=corelight_conn (id_orig_h="154.64.238.222" OR id_resp_h="154.64.238.222")
| stats count by _time, src_ip, dest_ip, dest_port
| sort -_time
index=firewall-pan (src_ip="154.64.238.247" OR dest_ip="154.64.238.247") OR index=corelight sourcetype=corelight_conn (id_orig_h="154.64.238.247" OR id_resp_h="154.64.238.247")
| stats count by _time, src_ip, dest_ip, dest_port
| sort -_time
index=firewall-pan (src_ip="1.32.216.171" OR dest_ip="1.32.216.171") OR index=corelight sourcetype=corelight_conn (id_orig_h="1.32.216.171" OR id_resp_h="1.32.216.171")
| stats count by _time, src_ip, dest_ip, dest_port
| sort -_time
index=firewall-pan (src_ip="8.148.149.147" OR dest_ip="8.148.149.147") OR index=corelight sourcetype=corelight_conn (id_orig_h="8.148.149.147" OR id_resp_h="8.148.149.147")
| stats count by _time, src_ip, dest_ip, dest_port
| sort -_time
index=firewall-pan (src_ip="47.76.131.175" OR dest_ip="47.76.131.175") OR index=corelight sourcetype=corelight_conn (id_orig_h="47.76.131.175" OR id_resp_h="47.76.131.175")
| stats count by _time, src_ip, dest_ip, dest_port
| sort -_time
YARA Rules
QTFY_QScan_QTRouter_Strings β Detects binaries containing string references to QTFY QScan, QTRouter, or QTProxy infrastructure domains and tool names. Useful for scanning endpoints, file shares, or malware repositories for QTFY-related binaries.
rule QTFY_QScan_QTRouter_Strings
{
meta:
author = "RedSheepSec"
description = "Detects binaries with string references to QTFY infrastructure domains and tool identifiers"
date = "2026-08-27"
reference = "https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers"
threat_actor = "QTFY"
strings:
$domain1 = "qtproxy.xyz" ascii wide nocase
$domain2 = "qt-proxy.org" ascii wide nocase
$domain3 = "qt-team.com" ascii wide nocase
$domain4 = "yotocloud.com" ascii wide nocase
$domain5 = "fastlink.ws" ascii wide nocase
$domain6 = "instantmessagehub.tech" ascii wide nocase
$subdomain1 = "mq-task.qt-proxy.org" ascii wide nocase
$subdomain2 = "mq-result.qt-proxy.org" ascii wide nocase
$subdomain3 = "jump.qt-proxy.org" ascii wide nocase
$tool1 = "QScan" ascii wide
$tool2 = "QTRouter" ascii wide
$tool3 = "QTProxy" ascii wide
$tool4 = "QTFY" ascii wide
$tool5 = "QTCYBER" ascii wide
$tool6 = "Fast Labyrinth" ascii wide
$ip1 = "154.64.238.222" ascii wide
$ip2 = "154.64.238.247" ascii wide
$ip3 = "1.32.216.171" ascii wide
$ip4 = "8.148.149.147" ascii wide
condition:
uint16(0) == 0x5A4D or uint32(0) == 0x464C457F or
(any of ($domain*) and any of ($tool*)) or
(any of ($subdomain*)) or
(2 of ($ip*) and any of ($tool*)) or
(3 of ($domain*))
}
Suricata Rules
SID 2026001 β Detects DNS query for QTFY seized C2 domain qtproxy.xyz
alert dns $HOME_NET any -> any any (msg:"QTFY C2 - DNS Query for qtproxy.xyz (Seized Domain)"; dns.query; content:"qtproxy.xyz"; nocase; classtype:trojan-activity; sid:2026001; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026002 β Detects DNS query for QTFY seized C2 domain qt-proxy.org
alert dns $HOME_NET any -> any any (msg:"QTFY C2 - DNS Query for qt-proxy.org (Seized Domain)"; dns.query; content:"qt-proxy.org"; nocase; classtype:trojan-activity; sid:2026002; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026003 β Detects DNS query for QTFY seized C2 domain qt-team.com
alert dns $HOME_NET any -> any any (msg:"QTFY C2 - DNS Query for qt-team.com (Seized Domain)"; dns.query; content:"qt-team.com"; nocase; classtype:trojan-activity; sid:2026003; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026004 β Detects DNS query for Fast Labyrinth egress node domain yotocloud.com
alert dns $HOME_NET any -> any any (msg:"QTFY Fast Labyrinth - DNS Query for yotocloud.com"; dns.query; content:"yotocloud.com"; nocase; classtype:trojan-activity; sid:2026004; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026005 β Detects DNS query for fastlink.ws commercial proxy service co-opted by QTFY
alert dns $HOME_NET any -> any any (msg:"QTFY Fast Labyrinth - DNS Query for fastlink.ws"; dns.query; content:"fastlink.ws"; nocase; classtype:trojan-activity; sid:2026005; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026006 β Detects network connection to QScan task broker IP 154.64.238.222
alert ip $HOME_NET any -> 154.64.238.222 any (msg:"QTFY QScan - Connection to Task Broker 154.64.238.222"; classtype:trojan-activity; sid:2026006; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026007 β Detects network connection to QScan results DB IP 154.64.238.247
alert ip $HOME_NET any -> 154.64.238.247 any (msg:"QTFY QScan - Connection to Results DB 154.64.238.247"; classtype:trojan-activity; sid:2026007; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026008 β Detects network connection to Fast Labyrinth admin plane IP 1.32.216.171
alert ip $HOME_NET any -> 1.32.216.171 any (msg:"QTFY Fast Labyrinth - Connection to Admin Plane 1.32.216.171"; classtype:trojan-activity; sid:2026008; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026009 β Detects network connection to Fast Labyrinth jump box IP 8.148.149.147
alert ip $HOME_NET any -> 8.148.149.147 any (msg:"QTFY Fast Labyrinth - Connection to Jump Box 8.148.149.147"; classtype:trojan-activity; sid:2026009; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
SID 2026010 β Detects DNS query for instantmessagehub.tech (LOW CONFIDENCE QTFY admin interface)
alert dns $HOME_NET any -> any any (msg:"QTFY Fast Labyrinth - DNS Query for instantmessagehub.tech (Low Confidence)"; dns.query; content:"instantmessagehub.tech"; nocase; classtype:trojan-activity; sid:2026010; rev:1; metadata:created_at 2026_08_27, updated_at 2026_08_27;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| DNS Logs (index=dns, index=corelight sourcetype=corelight_dns) | T1584.005, T1583, T1090.003 | DNS logging is the highest-priority data source for this hunt. Ensure all DNS resolvers forward query logs to Splunk. Both index=dns and Corelight DNS logs should be searched. Look for queries to seized domains (will return NXDOMAIN or sinkhole IPs post-seizure) as well as historical resolutions. |
| Corelight/Zeek Network Metadata (index=corelight) | T1595.001, T1090.003, T1071, T1190 | Corelight conn, dns, http, and ssl logs provide network connection metadata essential for identifying communications with QTFY infrastructure IPs. Also used for detecting CVE-2019-11510 exploitation via HTTP URI patterns. |
| Palo Alto Firewall (index=firewall-pan sourcetype=pan:traffic:aggregated, pan:threat) | T1090.003, T1595.001, T1190 | Perimeter firewall logs for blocking and historical lookup of connections to QTFY infrastructure IPs. Check both pan:traffic:aggregated for connection data and pan:threat for IPS/threat signatures. |
| CrowdStrike EDR (index=crowdstrike) | T1584.005, T1190 | Endpoint detection for QScan/QTRouter binary execution, process creation events connecting to QTFY domains/IPs, and any behavioral detections related to IoT scanning or proxy relay activity from managed endpoints. |
| Sysmon (index=sysmon) | T1584.005, T1071 | Sysmon EventID 3 (Network Connection) and EventID 22 (DNS Query) can detect endpoint-level communications to QTFY infrastructure. EventID 1 (Process Create) useful for detecting QScan/QTRouter execution if binaries are found on endpoints. |
| Web Server Logs (index=webserver, index=iis) | T1190 | VPN appliance logs and web server access logs needed to detect CVE-2019-11510 exploitation attempts. Pulse Secure/Ivanti appliances may log to syslog or custom log formats. |
Recommendations
- IMMEDIATE: Execute all IOC sweep queries across DNS logs (index=dns, index=corelight corelight_dns), firewall logs (index=firewall-pan), and Corelight conn logs (index=corelight corelight_conn) with maximum available retention lookback. Any hit to QTFY domains or IPs requires incident response escalation.
- IMMEDIATE: Block all five QTFY infrastructure IPs (154.64.238.222, 154.64.238.247, 1.32.216.171, 8.148.149.147, 47.76.131.175) at perimeter firewalls (PAN) and add all QTFY domains to DNS sinkhole/blocklists.
- IMMEDIATE: Deploy all Suricata rules (SID 2026001-2026010) to network sensors monitoring egress points for real-time alerting on QTFY domain resolution and IP connections.
- HIGH PRIORITY: Audit all Pulse Secure / Ivanti Connect Secure VPN appliances for CVE-2019-11510 patch status. Any appliance running firmware older than Pulse Connect Secure 9.0R3.4 should be treated as presumed compromised and subjected to forensic review. Pulse Connect Secure has reached end-of-support β migrate to current Ivanti Connect Secure versions.
- HIGH PRIORITY: Conduct a comprehensive IoT device audit across all network segments. Identify SOHO routers, IP cameras, and smart devices. Segment unmanaged IoT devices onto isolated VLANs with restricted egress. Devices that cannot be patched or audited should be replaced.
- MEDIUM PRIORITY: Deploy the Sigma rules from this report to Splunk and Elastic detection pipelines for persistent monitoring of QTFY DNS queries, network connections, and CVE-2019-11510 exploitation attempts.
- MEDIUM PRIORITY: Hunt for low-volume periodic beaconing patterns from sensitive network segments to residential IP ranges or known commercial proxy services, consistent with Fast Labyrinth's counter-detection tradecraft of 'steady, precise focus on select targets.'
- ONGOING: Monitor CISA advisories and FBI flash alerts for supplementary IOCs and TTPs. Federal agencies are reportedly planning to release additional technical advisories with further indicators.
- ONGOING: Distribute the YARA rule (QTFY_QScan_QTRouter_Strings) to malware scanning infrastructure for automated detection of QTFY-related binaries on file shares, endpoints, and email attachments.
Sources
- DOJ Press Release: Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers
- BleepingComputer: FBI Disrupts Proxy Network Enabling Chinese Espionage Operations
- The Record: QScan QTRouter US Takedown Alleged China Hacking Tools
- Lumen Black Lotus Labs: The Infrastructure Quartermaster β Inside a China-Nexus State Enablement Model
- CNBC: China Hacker Federal Reserve DOJ NASA
- CNN: US Alleged Chinese Cyber Spying Campaign
- Tom's Hardware: US Justice Department Claims Chinese State-Sponsored Hackers Infiltrated Systems at NASA, Senate, Federal Reserve