DoJ seizes QScan and QTRouter China-espionage botnet domains; Outsider phishing kit rebounds with 700+ new pages; ThreatsDay adds Teams, Spring Ring and Gentlemen campaigns
The US Department of Justice seized the domains of QScan and QTRouter, espionage botnet platforms run by private firm QTFY for China's MSS and PLA — the third Chinese state-backed botnet disrupted since December 2023. Group-IB reports the Outsider phishing…
The US Department of Justice seized the domains of QScan, a distributed vulnerability scanning system whose database held nearly a decade of internet scanning data used for target selection, and QTRouter, a covert communications platform that obscured the origins of Chinese traffic by routing it through compromised IoT devices. Both platforms were operated by the private firm QTFY under Chinese company Nanjing Xinjiuwei Network Technology; per FBI and NSA advisories, QTFY's customers include China's Ministry of State Security and the People's Liberation Army, targeting federal agencies, the US Senate, hospitals, telecoms and financial institutions. This is the third Chinese state-backed botnet disrupted since December 2023, following the KV botnet (Volt Typhoon) and Raptor Train (Flax Typhoon), and a sister network, JDY, has more than doubled since the KV disruption. QTFY bought high-tier subscriptions to the Chinese commercial VPN Fastlink for traffic backhaul, and QTRouter's hard-coded domains enabled the seizure. In an unrelated incident, the Qilin ransomware group claimed a breach of the ATF's CALEA system, briefly publishing 6.3 GB of case folders and forensic data allegedly stolen from the ATF. Separately, Group-IB linked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, to more than 100,000 phishing pages across 54+ countries between December 2025 and May 2026. After the FBI, Google and Lumen's Black Lotus Labs seized core admin servers, a Shopify storefront, about $100,000 and thousands of domains under Operation Ghost Hook in June 2026, over 700 new phishing domains appeared within a month; The Hacker News independently cites Group-IB's finding of 700+ new pages, describing the same rebound (Infosecurity calls the additions domains, The Hacker News calls them pages). The kit offered 267 templates for finance, telecom, postal, government and toll scams, adversary-in-the-middle MFA interception that dynamically served MFA challenges and relayed victim input in real time via WebSockets, and SMS delivery via a Telegram affiliate ecosystem with more than 5,000 subscribers, including a smishing campaign impersonating Singapore's LTA to harvest data for SMS code interception; researchers recommend tracking file-name signatures to trigger phishing page takedowns. The Hacker News ThreatsDay roundup adds several distinct items: Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help…
- DoJ seized the domains of QScan (distributed vulnerability scanning system with nearly a decade of internet scanning data) and QTRouter (covert comms platform routing traffic through compromised IoT devices), operated by QTFY under Chinese…
- FBI and NSA advisories say QTFY's customers include China's Ministry of State Security and the People's Liberation Army, targeting federal agencies, the US Senate, hospitals, telecoms and financial institutions.
- Third Chinese state-backed botnet disrupted since December 2023, after the KV botnet (Volt Typhoon) and Raptor Train (Flax Typhoon); sister network JDY has more than doubled since the KV disruption.
- QTFY bought high-tier subscriptions to the Chinese commercial VPN Fastlink for traffic backhaul; QTRouter's hard-coded domains enabled the seizure.
- Qilin ransomware group claimed a breach of the ATF's CALEA system, briefly publishing 6.3 GB of case folders and forensic data allegedly stolen from the ATF.
- Group-IB linked the Outsider Phishing Kit (operator: ChenLun) to more than 100,000 phishing pages across 54+ countries between December 2025 and May 2026.
- Operation Ghost Hook (June 2026) by the FBI, Google and Lumen's Black Lotus Labs seized core admin servers, a Shopify storefront, about $100,000 and thousands of domains; 700+ new phishing pages/domains appeared within a month.
- Outsider kit features: 267 templates, adversary-in-the-middle MFA interception with WebSocket-based live operator communication, SMS delivery via a Telegram affiliate ecosystem with 5,000+ subscribers, and a smishing campaign impersonating…
Coverage timelineoldest first · each row is one article
- · 14d agoSrsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting
Risky Business News· 76
DoJ seized domains of Chinese espionage botnet platforms QScan and QTRouter, run by private firm QTFY for MSS and PLA targeting.