ctipilot.ch

QScan

tool · tool:qscan

Three-stage reconnaissance/exploitation-target-profiling pipeline (Celery/RabbitMQ task broker, rotating distributed scanner fleet, Redis results backend) used to fingerprint and profile high-value networks worldwide before handoff to the QTRouter/Fast Labyrinth proxy layer (Lumen Black Lotus Labs, 2026-08-26).

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Related entities below
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown · ATT&CK page ↗

Resource Development TA0042

T1584.005Compromise Infrastructure: Botnet×1

Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).

Evidence: 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown · ATT&CK page ↗

Command and Control TA0011

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown · ATT&CK page ↗

T1665Hide Infrastructure×1

Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished by identifying and filtering traffic from defensive tools, masking malicious domains to obfuscate the true destination from both automated scanning tools and security researchers, and otherwise hiding malicious artifacts to delay discovery and prolong the effectiveness of adversary infrastructure that could otherwise be identified, blocked, or taken down entirely.

Evidence: 2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown · ATT&CK page ↗

Story timeline

  1. 2026-08-28DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA — NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named as victims since 2018, with European infrastructure among Lumen's own profiled targets
    active-threatsA PRC state-enablement platform leasing commercial proxy subscriptions as anonymisation infrastructure has been seized — but blocklisting won't be durable

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

used by

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • justice.gov1 (33%)
  • lumen.com1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about QScan (1)

2026-08-28 · view entry permalink →

HIGHNATOA1

DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA — NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named as victims since 2018, with European infrastructure among Lumen's own profiled targets

DOJ and the FBI announced court-authorized domain seizures on 2026-08-26 against "QScan" and "QTRouter", two complementary hacking platforms unsealed court documents attribute to "QTFY" (aka QT/QTCYBER), a PRC state-sponsored contractor run by Nanjing Xinjiuwei Network Technology Company that received payments from China's Ministry of State Security. BleepingComputer's reporting of the unsealed court documents adds a staffing detail neither DOJ's nor Lumen's own material states directly: "Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing" (BleepingComputer, 2026-08-26). QScan is a three-stage reconnaissance pipeline — a Celery/RabbitMQ task broker, a distributed scanner fleet that rotates across /24 subnet blocks on a 30-day cycle to dodge threshold detection, and a Redis results backend — that fingerprints IoT devices, OS kernels and exposed management interfaces worldwide. QTRouter, which Lumen's Black Lotus Labs calls a "quartermaster" enablement layer after tracking the same infrastructure for over a year under the names "Fast Labyrinth" and "QTProxy", turns QScan-compromised IoT devices, leased VPS instances, and — most distinctively — bulk-purchased subscriptions to the Chinese "Airport" (机场) commercial GFW-circumvention proxy service into an obfuscation-as-a-service network: because the seized domains were hard-coded into both platforms for communication and authentication, "the court-authorized seizures made QScan and QTRouter inoperable" (U.S. Department of Justice, 2026-08-26).

Named victims since at least 2018 include NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, NIH, and the U.S. Senate — "among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate" (U.S. Department of Justice, 2026-08-26). Lumen's independent telemetry additionally shows sustained QScan/Fast-Labyrinth targeting of research universities, defense-supplier perimeters, and — explicitly — European infrastructure and judicial nodes worldwide, describing the reconnaissance purpose plainly: "systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously" (Lumen Technologies — Black Lotus Labs, 2026-08-26). Lumen found direct crossover between administrative check-in sessions from Nanjing (China Telecom/Unicom IP space) and the co-opted commercial proxy nodes — evidence the operators actively tested and calibrated the leased infrastructure before leasing it to downstream customers.

The takedown follows the same court-authorized disruption playbook DOJ/FBI used against Flax Typhoon (2024) and Volt Typhoon (2023) ORB networks. Lumen cautions that because the proxy layer rides on dynamically-rotating legitimate commercial subscriptions rather than a static botnet, blocklisting alone will not be durable, and recommends the CISA/NCSC ORB-mitigation guidance. For this constituency, the relevant read is not the US federal victim list but the infrastructure model itself: a hacking-as-a-service anonymisation layer leased to multiple PRC state customers, explicitly profiled by its own independent tracker as reaching European infrastructure and judicial systems, is the same class of ORB (operational relay box) infrastructure prior Volt Typhoon and Flax Typhoon disruptions have shown reaching European routers and critical-infrastructure networks.

actions[] is empty: this is a completed law-enforcement disruption rather than a live exposure this constituency can patch, hunt or block against directly — the transferable lesson is awareness of the ORB infrastructure class and CISA/NCSC's published ORB-mitigation guidance, which the body above already carries.

Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.

Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.

U.S. Department of Justice

Systematic mapping of these remote-access boundaries is necessary to establish the required staging footprints that facilitate future lateral movement, maintain non-attributable backchannels, and conduct stealthy data-harvesting operations across multiple public sectors simultaneously.

Lumen Technologies — Black Lotus Labs 2026-08-26

Court documents reveal that the threat group includes former members of the Chinese People's Liberation Army military wing

BleepingComputer 2026-08-26
threat28 Aug 06:05Zmulti-sourceOpen finding ↗