The FBI and Department of Justice have seized control of digital domains used by the Nanjing Xinjiuwei Network Technology Company to orchestrate a widespread, years-long cyber-espionage campaign against US federal agencies and critical infrastructure. The operation successfully disabled tools known as QTRouter and QScan, which were utilized by state-sponsored actors to mask malicious traffic within legitimate internet and VPN communications.
Anatomy of the Disrupted Proxy Network
The US government's recent enforcement action targeted an intricate infrastructure ecosystem designed to obfuscate Chinese state-sponsored hacking activities. At the center of the operation was Nanjing Xinjiuwei Network Technology Company, a firm acting as a technical facilitator for entities including the People's Liberation Army and the Ministry of State Security. The company provided its clients with access to botnets comprised of compromised Internet-of-Things (IoT) devices and commercial proxy services. By using QScan, the group could actively search for vulnerabilities in IoT hardware to expand their reach, while QTRouter served as a management dashboard for directing malicious traffic through these relay points. This sophisticated 'quartermaster' model allowed hackers to blend their activities into the background noise of normal internet traffic, significantly complicating the detection efforts of American cybersecurity defenders.
Scope and Victims of the Intrusion
The breadth of the targeting identified by the FBI reveals a strategic focus on high-value US government and critical infrastructure institutions. Agencies compromised or targeted by the campaign include the Department of Justice itself, NASA, the US Senate, the Federal Reserve, the Department of Energy, and the Department of Health and Human Services. Beyond these federal entities, the proxy network was used to probe defenses at private-sector organizations including defense contractors, telecommunications providers, hospitals, and major financial institutions. While the government has provided a substantial list of targeted institutions, authorities emphasized that the extent of successful breaches remains under ongoing investigation. The campaign, which has been active since at least 2018, appears to prioritize broad, traditional intelligence collection rather than the pre-positioning for infrastructure disruption often associated with groups like Volt Typhoon.
Tactical Evolution: Exploiting VPNs
In a significant tactical pivot over the last twelve months, the hacking group began hijacking Virtual Private Network (VPN) services specifically favored by Chinese citizens to bypass the Great Firewall. By routing their state-sponsored malicious traffic through these existing, benign user channels, the attackers effectively 'cloaked' their operations. This maneuver created a profound visibility challenge for threat researchers, as the malicious signals were inextricably mixed with the legitimate activities of millions of Chinese users seeking access to the open web. Researchers at Lumen Technology's Black Lotus Labs noted that this obfuscation strategy made the bad traffic nearly indistinguishable from ordinary user data. By seizing the hardcoded domains that underpinned these systems and null-routing key traffic, the FBI and its partners have forced a temporary, though likely short-lived, disruption of these capabilities.
Broader Implications for Cyber-Diplomacy
The takedown highlights the evolving nature of the conflict between US defenders and state-aligned private contractors in China. Security analysts suggest that while this operation represents an embarrassing failure for Nanjing Xinjiuwei Network Technology Company, it is unlikely to permanently deter their activities. Because the infrastructure relied on a flexible architecture of rented virtual private servers and compromised devices, researchers anticipate that the actors will quickly move to reconstitute their operations under new domains. Despite the lack of criminal charges against individual operators in this specific announcement, the public identification of the contractor serves as a warning against the private facilitators that provide the 'force multipliers' for state-sponsored cyber-espionage. This ongoing game of cat and mouse underscores the necessity for defenders to continuously adapt their detection methodologies as adversaries shift their reliance toward more creative, obfuscated traffic relay strategies.
⚖ The Balanced View
Supporting view
US Attorney General Todd Blanche emphasized the commitment to halting state-sponsored hacking, stating that the government will utilize every available legal and technical tool to protect American critical infrastructure.
Concerns & criticism
Cybersecurity researchers like Damon Rouse caution that the adversary remains highly adaptable, suggesting that the disruption is only a temporary setback and that the actors will inevitably pivot to new, harder-to-detect infrastructure.
→What's next
Authorities will likely continue to monitor for signs of the group re-establishing their proxy nodes using different command-and-control domains. Meanwhile, private sector firms and federal agencies are expected to further harden their networks against the types of traffic patterns that this specific proxy infrastructure utilized to hide its activities.
































































































































































































































































































