Overview
- U.S. authorities obtained court orders and seized internet domains on Wednesday, Aug. 26, 2026, that were central to two malicious platforms, rendering those systems inoperable and disrupting the group's global botnet.
- Federal filings identify the operator as a China-linked group called QTFY that worked through Nanjing Xinjiuwei Network Technology Company and sold services to customers tied to China’s Ministry of State Security and the People’s Liberation Army.
- The operation used two complementary tools: one that scanned the internet and automatically infected thousands of internet-connected devices including routers and cameras, and another that routed attacker traffic through those compromised devices, commercial proxies, and rented servers to hide origin.
- Court documents list a wide set of victims and targets including NASA, the Federal Reserve, the Department of Justice, the U.S. Senate, Department of Energy labs, HHS, NIH, hospitals, telecoms, power firms, banks, defense contractors and companies in the U.S. and South Korea.
- Authorities seized specific domains (including qtproxy.xyz, qt-proxy.org and qt-team.com) and said the action is part of ongoing technical operations and investigations because the full extent of any data exfiltration remains unknown and similar capabilities could reappear.