<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3" -->

---
title: How China industrialized the infrastructure behind state...
description: The FBI and DOJ seized domains behind QScan and QTRouter, hacking platforms built and operated by a PRC state-sponsored group called QTFY, working through the...
canonical: https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: How China industrialized the infrastructure behind state hacking | daily.dev
og:description: The FBI and DOJ seized domains behind QScan and QTRouter, hacking platforms built and operated by a PRC state-sponsored group called QTFY, working through the...
og:url: https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3
og:image: https://api.daily.dev/og/posts/jjHIqDrb3.png
og:image:alt: How China industrialized the infrastructure behind state hacking
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How China industrialized the infrastructure behind state hacking

**[CSO Online](https://daily.dev/sources/csoonline)** · 7 min read · 0 upvotes · 0 comments

## Summary

The FBI and DOJ seized domains behind QScan and QTRouter, hacking platforms built and operated by a PRC state-sponsored group called QTFY, working through the private contractor Nanjing Xinjiuwei Network Technology Company. QTFY sold reconnaissance, exploitation, routing, and obfuscation infrastructure to multiple Chinese offensive hacking teams, including units linked to the Ministry of State Security and PLA, targeting NASA, the Federal Reserve, DOJ, HHS, NIH, and the US Senate over nearly a decade. Security researchers describe this as a marketized 'quartermaster' model where private Chinese firms supply shared infrastructure to state hackers, giving scale and plausible deniability but also creating a single point of failure law enforcement can disrupt. Experts note traffic was routed through compromised IoT devices and commercial proxies in over 130 countries, making geography- and reputation-based IP blocking ineffective, and recommend CISOs focus on patching, logging, and behavioral baselines instead.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4217274/how-china-industrialized-the-infrastructure-behind-state-hacking.html>

## Questions this post answers

### What were QScan and QTRouter used for by Chinese state-sponsored hackers?

QScan and QTRouter were hacking platforms created by the PRC state-sponsored group QTFY, operated through the China-based company Nanjing Xinjiuwei Network Technology Company. QScan scanned and automatically infected thousands of IoT devices worldwide, which were then added to the QTRouter network to route and obfuscate traffic for offensive hacking teams working for the Ministry of State Security and People's Liberation Army.

_Security teams tracking nation-state botnet infrastructure can follow developments like this on daily.dev._

### Why is IP reputation based blocking no longer reliable against Chinese state-sponsored hacking traffic?

Because QTFY's obfuscation infrastructure routed traffic through everyday small office routers, IoT devices, commercial proxies, leased virtual private servers, and rotating IP addresses across more than 130 countries, so malicious traffic can appear to originate from ordinary US ISPs like Charter Communications rather than China, defeating geography- and reputation-based blocking.

_CISOs rethinking perimeter defenses beyond IP reputation can track this kind of threat analysis on daily.dev._

## Similar posts on daily.dev

- [China-linked crews turn routers into covert attack proxies](https://daily.dev/posts/china-linked-crews-turn-routers-into-covert-attack-proxies-dfktw66a9) · The Register · 0 upvotes · 0 comments
- [UK warns of Chinese hackers using proxy networks to evade detection](https://daily.dev/posts/uk-warns-of-chinese-hackers-using-proxy-networks-to-evade-detection-e65ziyo1f) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"How China industrialized the infrastructure behind state hacking","url":"https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3"},"datePublished":"2026-09-02T08:31:31.191Z","dateModified":"2026-09-02T08:34:05.038Z","description":"The FBI and DOJ seized domains behind QScan and QTRouter, hacking platforms built and operated by a PRC state-sponsored group called QTFY, working through the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4efe4b5406ecfd76f5d79c8580cd3f4c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4efe4b5406ecfd76f5d79c8580cd3f4c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"How China industrialized the infrastructure behind state hacking"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/how-china-industrialized-the-infrastructure-behind-state-hacking-jjhiqdrb3#faq","mainEntity":[{"@type":"Question","name":"What were QScan and QTRouter used for by Chinese state-sponsored hackers?","acceptedAnswer":{"@type":"Answer","text":"QScan and QTRouter were hacking platforms created by the PRC state-sponsored group QTFY, operated through the China-based company Nanjing Xinjiuwei Network Technology Company. QScan scanned and automatically infected thousands of IoT devices worldwide, which were then added to the QTRouter network to route and obfuscate traffic for offensive hacking teams working for the Ministry of State Security and People's Liberation Army. Security teams tracking nation-state botnet infrastructure can follow developments like this on daily.dev."}},{"@type":"Question","name":"Why is IP reputation based blocking no longer reliable against Chinese state-sponsored hacking traffic?","acceptedAnswer":{"@type":"Answer","text":"Because QTFY's obfuscation infrastructure routed traffic through everyday small office routers, IoT devices, commercial proxies, leased virtual private servers, and rotating IP addresses across more than 130 countries, so malicious traffic can appear to originate from ordinary US ISPs like Charter Communications rather than China, defeating geography- and reputation-based blocking. CISOs rethinking perimeter defenses beyond IP reputation can track this kind of threat analysis on daily.dev."}}]}
```

