QTFY Distributed Scan & Relay Infrastructure
Executive Summary
QTFY is a PRC-linked cyber-enablement operation attributed by U.S. authorities to Nanjing Xinjiuwei Network Technology. Its QScan platform performs high-volume reconnaissance and exploitation; QTRouter/Fast Labyrinth relays downstream intrusion traffic through compromised IoT devices, commercial proxy services, and leased infrastructure. The documented target set spans government, defense, communications, energy, water, healthcare, finance, higher education, and technology.
Detection strategy: static indicators are useful for retrospective scoping, but the durable signal is a chain: edge scanning or exploitation → web shell or suspicious child process → relay-backed network or authenticated access. The report therefore covers both the edge/endpoint plane and the identity/authentication plane.
Source and Claim Review
Five primary-source streams support the pack. The official JCSA and IOC appendices provide the authoritative actor facts and indicators; Black Lotus Labs independently corroborates the platform architecture and observed targeting.
| ID | Publisher | Tier | Version | Contribution |
|---|---|---|---|---|
| S01 | FBI / NSA / CNMF | T1 government primary | JCSA-20260826-01 | Attribution, timeline, TTPs, IOCs, mitigations |
| S02 | FBI / NSA / CNMF | T1 government IOC | QTFY_IOC_Files.csv | 45 exact SHA-256 indicators |
| S03 | FBI / NSA / CNMF | T1 government IOC | QTFY_IOC_Infrastructure.csv | 390 infrastructure records with dates and roles |
| S04 | Lumen Black Lotus Labs | T1 independent technical research | 2026-08-26 | Fast Labyrinth architecture, telemetry, targets, defensive implications |
| S05 | U.S. Department of Justice | T1 government primary | 2026-08-26 / updated 2026-08-28 | Domain seizure, platform/customer relationships, disruption status |
| S06 | MITRE ATT&CK | T1 canonical framework | Enterprise Groups directory | Confirmed no QTFY group object yet; technique IDs checked |
Hunt Brief and Attack Chain
The hunt model deliberately separates the platform/edge plane from identity/authentication. A single IOC hit is triage input; the strongest case joins behavior across two or more stages.
| Step | Phase | Behavior | ATT&CK | Bucket |
|---|---|---|---|---|
| 1 | Reconnaissance | QScan maps exposed services and vulnerable configurations at scale | T1595.002 | Edge/network |
| 2 | Initial access | Zero-day or N-day exploitation of public-facing appliances and applications | T1190 | Edge/application |
| 3 | Persistence | Web shells, RATs, and obtained legitimate credentials | T1505.003 / inferred T1078 | Endpoint + identity |
| 4 | Obfuscation | QTRouter chains IoT, commercial proxy, and VPS nodes | inferred T1090.002 | Network |
| 5 | Follow-on access | Locally plausible relay traffic and valid-account use reach sensitive systems | inferred T1078 | Identity/auth |
Detection hypotheses
| ID | Hypothesis | Telemetry | Query | Bucket |
|---|---|---|---|---|
| H01 | Published binaries execute on Falcon-covered systems | Process hash telemetry | Q01 | Edge/endpoint |
| H02 | Systems resolve or contact platform infrastructure | DNS and network telemetry | Q02–Q03 | Edge/endpoint |
| H03 | An unexpected proxy client supports relay activity | Process telemetry | Q04 | Edge/endpoint |
| H04 | Public-facing service exploitation creates a shell or transfer process | Process lineage | Q05 | Edge/endpoint |
| H05 | Current workers reach Falcon-covered public services | Accepted network telemetry | Q06 | Edge/endpoint |
| H06 | Relay infrastructure is followed by successful remote authentication | Logon telemetry | Q07 | Identity/auth |
| H07 | One remote source fans out across accounts and hosts | Logon aggregation | Q08 | Identity/auth |
Consolidated IOC Table
This view shows 12 representative hashes plus all 13 indicators marked Present. The machine-readable appendix carries all 45 hashes and the current subset; the source snapshots retain all 390 infrastructure records.
| Type | Value | Confidence | Action | Context |
|---|---|---|---|---|
| SHA-256 | d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357 | high | detect | agent_linux_386 |
| SHA-256 | 7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300 | high | detect | agent_linux_amd64 |
| SHA-256 | c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a | high | detect | agent_linux_arm |
| SHA-256 | e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664 | high | detect | agent_linux_arm64 |
| SHA-256 | 6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224 | high | detect | agent_linux_armhf |
| SHA-256 | 5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2 | high | detect | agent_linux_mips |
| SHA-256 | 69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089 | high | detect | agent_linux_mips64 |
| SHA-256 | 9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa | high | detect | agent_linux_mips64le |
| SHA-256 | dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e | high | detect | agent_linux_mipsle |
| SHA-256 | c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3 | high | detect | agent_linux_powerpc |
| SHA-256 | 4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009 | high | detect | agent_linux_riscv32 |
| SHA-256 | 6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87 | high | detect | agent_linux_riscv64 |
| domain | securelink.qtproxy.xyz | medium | hunt | actor controlled; marked Present |
| ipv4 | 1.32.216.171 | medium | hunt | actor controlled; marked Present |
| ipv4 | 23.95.220.192 | medium | hunt | actor controlled; marked Present |
| ipv4 | 39.104.208.77 | medium | hunt | actor controlled; marked Present |
| ipv4 | 45.202.210.27 | medium | hunt | actor controlled; marked Present |
| ipv4 | 206.119.167.207 | medium | hunt | actor controlled; marked Present |
| ipv4 | 154.64.238.222 | medium | hunt | qscan server; marked Present |
| ipv4 | 154.64.238.247 | medium | hunt | qscan server; marked Present |
| ipv4 | 27.124.24.220 | medium | hunt | qscan worker; marked Present |
| ipv4 | 27.124.24.237 | medium | hunt | qscan worker; marked Present |
| ipv4 | 45.196.221.138 | medium | hunt | qscan worker; marked Present |
| ipv4 | 134.122.150.22 | medium | hunt | qscan worker; marked Present |
| ipv4 | 134.122.150.25 | medium | hunt | qscan worker; marked Present |
ATT&CK Mapping
| Tactic | Technique | Name | Behavior | Coverage |
|---|---|---|---|---|
| Reconnaissance | T1595.002 | Vulnerability Scanning | QScan checks whether exposed systems match vulnerable configurations | Q06 / native edge logs |
| Initial Access | T1190 | Exploit Public-Facing Application | Zero-day and N-day exploitation of public services | Q05 / hardening |
| Persistence | T1505.003 | Web Shell | Scripts expose internet-accessible backdoor capability | Q05 / native web logs |
| Resource Development | T1583.003 | Virtual Private Server | Leased VPS nodes support scanning and relay infrastructure | Q03 / enrichment |
| Resource Development | T1587 | Develop Capabilities | Custom QScan, QTRouter, and multi-architecture tooling | Q01 |
| Command and Control | T1090.002 (inferred) | External Proxy | Compromised IoT and commercial proxy nodes conceal operator origin | Q02–Q04 |
| Defense Evasion / Persistence | T1078 (inferred) | Valid Accounts | Obtained legitimate credentials support persistent access | Q07–Q08 |
The first five mappings are explicitly published in JCSA-20260826-01. T1090.002 and T1078 are analyst mappings retained as inferred because MITRE has not yet published a QTFY group object.
Native / Non-CQL Hunts
| Hunt | Required logs | Logic | Priority |
|---|---|---|---|
| Edge scan-to-session correlation | Firewall, WAF, VPN, IDS/NDR, load balancer | Join low-volume probing to later stable bidirectional sessions or authentication from different relay nodes | High |
| Exposed appliance inventory | ASM, vulnerability scanner, CMDB, firmware manager | Find unsupported firmware, public management planes, known-vulnerable services, and unowned IoT devices | Critical |
| Web-shell review | Web server, EDR, file integrity, reverse proxy | Correlate suspicious requests with new scripts, service child processes, and outbound connections | High |
| Relay-backed authentication | VPN, IdP, PAM, RDP/SMB, AD | Find successful privileged access from consumer/commercial proxy space after edge scanning | High |
| DNS and egress baseline | Recursive DNS, netflow, proxy, router telemetry | Find management/IoT segments contacting new control infrastructure or using unexpected proxy protocols | High |
| Infrastructure lifecycle | Passive DNS and certificate history | Revalidate indicator ownership and resolution, especially after the DOJ seizure | Medium |
CrowdStrike LogScale CQL Hunt Queries
Looks for: execution of any of the 45 government-published Linux agent, client, and script hashes. FP: Exact SHA-256 matches should be rare; confirm local sample provenance before containment.
// HUNT: Published multi-architecture Linux tool hashes // WHAT IT CATCHES: Exact process execution matching the government-published malicious tool set // MITRE: T1587 Develop Capabilities // CONF: high | FP: low | COST: medium // REQUIRES: ProcessRollup2 or SyntheticProcessRollup2 with SHA256HashData // TIMEFRAME: 365d in the Falcon time picker // FP NOTES: Exact hashes are campaign-specific; verify the file and host role before response // TUNING: Do not exclude by filename; exclude only a cryptographically verified authorized sample #event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/ | in(SHA256HashData, values=["d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357","7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300","c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a","e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664","6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224","5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2","69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089","9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa","dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e","c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3","4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009","6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87","12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec","27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3","32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33","00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188","ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31","7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721","26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c","bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f","ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878","ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651","996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a","ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1","08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9","ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb","5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09","0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2","ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846","dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3","86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb","dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991","239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a","b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce","2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562","5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5","ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c","92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245","c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7","bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990","a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a","c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb","5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7","c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35","0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656"]) | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, SHA256HashData, CommandLine, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: DNS activity to the published QScan/QTRouter control-plane roots and subdomains. FP: Several domains were seized; post-seizure lookups may be research, security tooling, or sinkhole traffic.
// HUNT: Distributed scan and relay control-plane DNS // WHAT IT CATCHES: Endpoint DNS requests to published actor-controlled platform infrastructure // MITRE: T1090.002 External Proxy (analyst mapping) // CONF: medium | FP: low | COST: low // REQUIRES: DnsRequest with DomainName and process context // TIMEFRAME: 90d in the Falcon time picker // FP NOTES: Threat-intelligence tools and post-seizure sinkhole checks can resolve these names // TUNING: Exclude only documented security scanners by aid and owner after confirming their purpose #event_simpleName = DnsRequest | DomainName = /(^|\.)(qtproxy\.xyz|qt-proxy\.org|qt-team\.com|instantmessagehub\.tech)$/i | table([@timestamp, aid, ComputerName, UserName, DomainName, ContextBaseFileName, ContextProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: endpoint connections to infrastructure marked Present in the official appendix. FP: Proxy, VPS, and compromised-device addresses can be shared or reassigned; require process and timing corroboration.
// HUNT: Current distributed scan and relay infrastructure contact // WHAT IT CATCHES: Network connections to addresses marked Present in the official IOC appendix // MITRE: T1090.002 External Proxy (analyst mapping) // CONF: medium | FP: medium | COST: low // REQUIRES: NetworkConnectIP4 with remote IP and process context // TIMEFRAME: 30d in the Falcon time picker // FP NOTES: Commercial proxies, leased VPSs, and compromised nodes may carry unrelated traffic // TUNING: Correlate with process rarity, DNS, edge exploitation, and authentication before escalation #event_simpleName = NetworkConnectIP4 | in(RemoteAddressIP4, values=["1.32.216.171","23.95.220.192","39.104.208.77","45.202.210.27","206.119.167.207","154.64.238.222","154.64.238.247","27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"]) | table([@timestamp, aid, ComputerName, UserName, ContextBaseFileName, RemoteAddressIP4, RemotePort, Protocol_decimal, ContextProcessId_decimal]) | sort(@timestamp, order=desc, limit=1000)
Looks for: Clash execution on endpoints where a commercial proxy client is not approved. FP: Clash is legitimate dual-use software and may be common for developers, researchers, or international users.
// HUNT: Unexpected commercial proxy client execution // WHAT IT CATCHES: Clash execution that may support chained relay or traffic-obfuscation activity // MITRE: T1090.002 External Proxy (analyst mapping) // CONF: medium | FP: high | COST: low // REQUIRES: ProcessRollup2 or SyntheticProcessRollup2 // TIMEFRAME: 30d in the Falcon time picker // FP NOTES: Approved developers, researchers, and privacy tooling can legitimately run Clash // TUNING: Join hits to the approved-software inventory and exclude only owner-approved hashes and hosts #event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/ | FileName = /^(clash)(\.exe)?$/i | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, SHA256HashData, CommandLine, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: internet-facing web services creating shells, interpreters, or download utilities after exploitation. FP: Deployment automation and support scripts can create the same parent-child pattern.
// HUNT: Web service child shell or transfer utility // WHAT IT CATCHES: Suspicious post-exploitation process creation from common web-service parents // MITRE: T1190 Exploit Public-Facing Application; T1505.003 Web Shell // CONF: medium | FP: medium | COST: low // REQUIRES: ProcessRollup2 or SyntheticProcessRollup2 with parent and child fields // TIMEFRAME: 30d in the Falcon time picker // FP NOTES: Deployment agents, health checks, and administrator-run web maintenance may match // TUNING: Baseline approved parent-child-command combinations; never exclude an entire web-service parent #event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/ | ParentBaseFileName = /^(httpd|apache2|nginx|php-fpm|tomcat|java)(\.exe)?$/i | FileName = /^(sh|bash|dash|zsh|cmd|powershell|pwsh|python|perl|curl|wget)(\.exe)?$/i | table([@timestamp, aid, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, SHA256HashData, CommandLine, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: accepted inbound connections from QScan workers observed in August 2026. FP: Worker IPs rotate and may be reassigned; a connection alone does not prove exploitation.
// HUNT: Inbound contact from current distributed scan workers // WHAT IT CATCHES: Server-side accepted connections from the newest published worker addresses // MITRE: T1595.002 Vulnerability Scanning // CONF: medium | FP: medium | COST: low // REQUIRES: NetworkReceiveAcceptIP4 on Falcon-covered internet-facing systems // TIMEFRAME: 30d in the Falcon time picker // FP NOTES: Reassigned hosting addresses and authorized external scanning can match // TUNING: Require an exposed-service match or follow-on process, file, or authentication evidence #event_simpleName = NetworkReceiveAcceptIP4 | in(RemoteAddressIP4, values=["27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"]) | table([@timestamp, aid, ComputerName, ContextBaseFileName, LocalAddressIP4, LocalPort, RemoteAddressIP4, RemotePort, Protocol_decimal, ContextProcessId_decimal]) | sort(@timestamp, order=desc, limit=1000)
Looks for: successful remote or network logons associated with infrastructure marked Present. FP: Shared commercial proxies and reassigned addresses can create unrelated matches.
// HUNT: Remote authentication from current distributed relay infrastructure // WHAT IT CATCHES: Successful remote or network logons from published current infrastructure // MITRE: T1078 Valid Accounts (analyst mapping) // CONF: medium | FP: medium | COST: low // REQUIRES: UserLogon with RemoteAddressIP4 and LogonType // TIMEFRAME: 30d in the Falcon time picker // FP NOTES: Authorized VPN, proxy, jump-host, or reassigned-IP activity may match // TUNING: Confirm the account owner, device, MFA record, source ASN, and preceding edge activity #event_simpleName = UserLogon | in(LogonType, values=[3,8,9,10]) | in(RemoteAddressIP4, values=["1.32.216.171","23.95.220.192","39.104.208.77","45.202.210.27","206.119.167.207","154.64.238.222","154.64.238.247","27.124.24.220","27.124.24.237","45.196.221.138","134.122.150.22","134.122.150.25"]) | table([@timestamp, aid, ComputerName, UserName, UserSid, LogonType, RemoteAddressIP4]) | sort(@timestamp, order=desc, limit=1000)
Looks for: one remote source authenticating to several accounts and hosts, consistent with relay-backed credential reuse. FP: VPN concentrators, jump hosts, VDI, scanners, and help-desk infrastructure commonly fan out.
// HUNT: Remote authentication source fan-out // WHAT IT CATCHES: One source address successfully authenticating across multiple users and hosts // MITRE: T1078 Valid Accounts (analyst mapping) // CONF: low | FP: high | COST: medium // REQUIRES: UserLogon with remote IP, account, host, and LogonType // TIMEFRAME: 7d in the Falcon time picker // FP NOTES: VPN concentrators, jump servers, VDI brokers, scanners, and help-desk systems fan out legitimately // TUNING: Exclude approved infrastructure by exact address only after ownership and expected account scope are documented #event_simpleName = UserLogon | in(LogonType, values=[3,8,9,10]) | RemoteAddressIP4 = * | groupBy([RemoteAddressIP4], function=[count(as=SuccessfulLogons), count(UserName, distinct=true, as=DistinctUsers), count(aid, distinct=true, as=DistinctHosts), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen), collect(UserName, limit=20), collect(ComputerName, limit=20)], limit=5000) | DistinctUsers >= 3 | DistinctHosts >= 3 | sort(SuccessfulLogons, order=desc, limit=500)
Operationalization and IOA Candidates
All queries remain manual hunt content. No scheduled alert, Custom IOA deployment, or prevention policy is claimed.
| IOA | Behavior | Rule type | Mode | Source | Promotion gate |
|---|---|---|---|---|---|
| IOA-01 | Unexpected web-service child shell | Process Creation | Detect | Q05 | Pilot 14+ days; exclude only approved parent-child-command triples |
| IOA-02 | Unexpected Clash proxy client | Process Creation | Detect | Q04 | Inventory legitimate use first; do not promote without measured FP rate |
Promotion gates
- Confirm event and field population in the intended repository.
- Run the query over a one-hour window, then the documented lookback.
- Execute a benign, non-destructive positive test in an isolated sensor group.
- Measure representative benign volume and document exclusions.
- Keep detect mode for at least 14 days and require an FP rate below 5% before any prevention review.
Machine-Readable IOC Appendix
The import block contains 58 rows: 45 exact hashes and 13 infrastructure indicators marked Present. All are detect-first; operational blocking requires local review.
type,value,action,severity,expiration,description,tags sha256,d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 sha256,0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656,detect,high,2027-09-01,published QTFY tool hash,actor:qtfy source:jcsa-20260826-01 domain,securelink.qtproxy.xyz,detect,medium,2026-11-30,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,1.32.216.171,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,23.95.220.192,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,39.104.208.77,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,45.202.210.27,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,206.119.167.207,detect,medium,2026-10-01,actor controlled marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,154.64.238.222,detect,medium,2026-10-01,qscan server marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,154.64.238.247,detect,medium,2026-10-01,qscan server marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,27.124.24.220,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,27.124.24.237,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,45.196.221.138,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,134.122.150.22,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01 ipv4,134.122.150.25,detect,medium,2026-10-01,qscan worker marked Present,actor:qtfy source:jcsa-20260826-01
d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357 7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300 c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664 6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224 5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2 69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089 9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3 4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009 6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87 12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec 27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3 32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33 00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188 ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31 7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721 26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878 ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651 996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1 08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9 ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb 5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09 0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2 ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846 dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3 86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991 239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce 2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562 5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5 ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c 92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245 c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7 bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990 a617e06c27d3514c57fd83711c75846d798e3ecefd5a0246b5ac9a191392e98a c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb 5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7 c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35 0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656
domain,securelink.qtproxy.xyz,actor controlled ipv4,1.32.216.171,actor controlled ipv4,23.95.220.192,actor controlled ipv4,39.104.208.77,actor controlled ipv4,45.202.210.27,actor controlled ipv4,206.119.167.207,actor controlled ipv4,154.64.238.222,qscan server ipv4,154.64.238.247,qscan server ipv4,27.124.24.220,qscan worker ipv4,27.124.24.237,qscan worker ipv4,45.196.221.138,qscan worker ipv4,134.122.150.22,qscan worker ipv4,134.122.150.25,qscan worker
QScan: distributed vulnerability scanning and exploitation QTRouter: IoT/commercial-proxy/VPS relay chaining Web service -> shell/interpreter/transfer-tool process Edge probe -> stable session -> remote authentication Unexpected Clash execution on managed systems One remote source -> multiple users and hosts
Hardening — Tiered and Deployable
- Patch exposed edge and web systems. Prioritize internet-facing firmware and applications, enable automatic updates where operationally safe, and replace end-of-support devices. Trace: T1190 → MITRE M1051, M1016; JCSA-20260826-01.
- Remove public management exposure. Bind administration to dedicated interfaces or VPN/jump paths and allowlist approved sources. Trace: T1190 → MITRE M1030, M1037; vendor appliance hardening guidance.
- Hunt before eviction. Preserve edge, DNS, authentication, and process evidence; isolate only demonstrated-compromised devices and revoke only exposed credentials. Trace: T1505.003 / inferred T1078; JCSA incident-response guidance.
- Segment edge and IoT from critical systems. Deny direct management-plane and lateral paths except documented flows. Trace: T1190 / inferred T1090.002 → MITRE M1030, M1037; CISA zero-trust guidance.
- Constrain relay and proxy software. Inventory Clash and other approved proxy clients; use application control and egress policy on fixed-purpose systems. Trace: inferred T1090.002 → MITRE M1037, M1038.
- Harden remote identity. Require phishing-resistant MFA and PAM for privileged/remote access; rotate secrets reachable from compromised edge devices. Trace: inferred T1078 → MITRE M1032, M1026, M1018.
- Build long-window scan-to-session analytics. Retain passive DNS, perimeter, VPN, authentication, and endpoint telemetry long enough to correlate rotating workers with later access. Trace: T1595.002 / T1190 → MITRE M1047.
- Establish edge lifecycle governance. Maintain owner, support date, firmware, exposure, and recovery records for routers, VPNs, firewalls, IoT, and remote-support systems. Trace: T1190 → MITRE M1016, M1051.
Deployable change checklist
1. Export the internet-facing asset inventory and current configurations. 2. Identify end-of-support devices and public management interfaces. 3. Patch a representative pilot; validate service health and rollback artifacts. 4. Restrict management to approved VPN/jump sources; test normal and emergency access. 5. Forward DNS, auth, edge, and configuration-change logs to protected storage. 6. Inventory proxy clients and relay protocols; baseline before enforcing egress controls. 7. Expand only after owners sign off and the pilot has no unexplained impact. Rollback: restore the exported configuration, previous ACL/policy, and approved firmware image; verify service, logging, and emergency access.
Containment Runbook
| Phase | Trigger | Owner | Evidence | Safety constraint |
|---|---|---|---|---|
| 1. Confirm | Correlated IOC or behavior across edge/endpoint and auth | SOC | Raw logs, timeline, asset owner | Do not block shared infrastructure on one hit |
| 2. Scope | Evidence suggests exploitation or unauthorized session | IR lead | Affected devices, accounts, adjacent systems | Preserve volatile appliance data first |
| 3. Contain | Compromise confirmed | IR + service owner | Isolation and dependency record | Use tested bypass/rollback path |
| 4. Evict | Evidence collection sufficient | IR + identity/network | Rebuild record, credential revocation, control-plane changes | Rebuild edge devices; do not trust in-place cleanup alone |
| 5. Recover | Known-good configuration and credentials ready | Service owner | Health checks, monitoring, business validation | Restore in stages with heightened logging |
| 6. Re-hunt | Recovery complete or new IOC published | Detection engineering | Query results and closure decision | Reopen if relay/auth behavior persists |
Escalate immediately: a published hash on an edge device, a web-service child shell followed by relay traffic, or privileged authentication from current infrastructure with no approved business explanation.
Detection Coverage and Validation Evidence
Validation state: STATIC REVIEW PASSED. This label covers local structure, active-content safety, field, syntax-heuristic, and IOC-provenance gates only. It is not Falcon tenant parsing, canary success, or deployment evidence.
| Technique | Behavior | CQL | IOA | Coverage | Gap |
|---|---|---|---|---|---|
| T1595.002 | Vulnerability scanning | Q06 + native perimeter hunt | — | Partial | Denied probes require firewall/IDS telemetry |
| T1190 | Public-facing exploitation | Q05 | IOA-01 | Partial | Exploit-specific appliance logs are tenant/product dependent |
| T1505.003 | Web shell | Q05 + native web hunt | IOA-01 | Partial | File paths and web-shell families were not published |
| T1583.003 | VPS infrastructure | Q03 | — | Partial | Shared hosting reduces indicator confidence |
| T1587 | Develop capabilities | Q01 | — | Good | 45 exact published hashes |
| T1090.002 inferred | External proxy | Q02–Q04 | IOA-02 | Partial | Proxy telemetry and device coverage vary |
| T1078 inferred | Valid accounts | Q07–Q08 | — | Partial | MFA/IdP evidence requires native logs |
Required tenant gates
- Confirm every event and field exists in the selected Falcon repository.
- Parse each query manually in a one-hour window.
- Measure returned volume and review representative benign hits.
- Run only benign tests in an isolated sensor group.
- Keep every IOA in Detect until the false-positive rate is measured and approved.
Hunt Summary Ticket
TITLE: QTFY distributed scanning and relay infrastructure hunt SEVERITY: HIGH — state-linked enablement targeting government and critical infrastructure SCOPE: Internet-facing edge, Linux/endpoint process, DNS/network, and remote-authentication telemetry HYPOTHESIS: QScan/QTRouter activity creates a scan or IOC signal followed by process, relay, or valid-account evidence QUERIES: Q01–Q06 edge/endpoint; Q07–Q08 identity/authentication DO FIRST: Q01, Q02, Q03, Q06, and Q07 using the card-specific lookbacks FINDINGS: GAPS: Denied scans, appliance telemetry, proxy attribution, MFA/IdP detail, and tenant parse evidence ACTIONS: Correlate before blocking; preserve edge evidence; verify current indicator ownership OWNER: SOC / Detection Engineering / Network / Identity / Edge Platform VERSION: v0.1 Draft · 2026-09-01 · STATIC REVIEW PASSED
Changelog
References
| ID | Publisher | Version/date | Accessed | Use | URL |
|---|---|---|---|---|---|
| S01 | FBI / NSA / CNMF | JCSA-20260826-01 | 2026-09-01 | Attribution, timeline, TTPs, IOCs, mitigations | https://www.ic3.gov/CSA/2026/260826.pdf |
| S02 | FBI / NSA / CNMF | QTFY_IOC_Files.csv | 2026-09-01 | 45 exact SHA-256 indicators | https://www.ic3.gov/CSA/2026/QTFY_IOC_Files.csv |
| S03 | FBI / NSA / CNMF | QTFY_IOC_Infrastructure.csv | 2026-09-01 | 390 infrastructure records with dates and roles | https://www.ic3.gov/CSA/2026/QTFY_IOC_Infrastructure.csv |
| S04 | Lumen Black Lotus Labs | 2026-08-26 | 2026-09-01 | Fast Labyrinth architecture, telemetry, targets, defensive implications | https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model |
| S05 | U.S. Department of Justice | 2026-08-26 / updated 2026-08-28 | 2026-09-01 | Domain seizure, platform/customer relationships, disruption status | https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers |
| S06 | MITRE ATT&CK | Enterprise Groups directory | 2026-09-01 | Confirmed no QTFY group object yet; technique IDs checked | https://attack.mitre.org/groups/ |