Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Amberleigh Jack. This week's edition is sponsored by Dropzone AI.
You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.

This week, the US Department of Justice (DoJ) announced it had disrupted two Chinese cyberespionage systems. The government has disrupted several Chinese botnets in recent years, but Beijing won't be giving up anytime soon. The botnets are simply too useful.
The disrupted systems were known as QScan and QTRouter. An FBI affidavit says the group running the platforms, QTFY, works for the private Chinese company Nanjing Xinjiuwei Network Technology.
QScan and QTRouter are just two components of a complex system, but both used hard-coded domains, making them susceptible to court-authorised domain seizures.
Qscan was a distributed vulnerability scanning system that was used to find and scan target networks plus identify vulnerable Internet of Things (IoT) devices that could be co-opted into QTFY's various botnets. An FBI/NSA joint cybersecurity advisory says that Qscan populates a QTFY database containing nearly a decade's worth of internet scanning. This database is used when targeting a specific victim or to quickly identify targets of interest when new vulnerabilities are discovered.
QTRouter was a covert communications platform to obfuscate the Chinese origin of traffic. Malicious traffic would be routed through compromised IoT devices.
QTFY customers include China's Ministry of State Security and the People's Liberation Army. The FBI affidavit alleges these customers' targets included federal government agencies, the US Senate and private sector entities including hospitals, telecommunications companies and financial institutions.
This was the third botnet facilitating China's state-backed cyberespionage to have been disrupted by the US government since December 2023. What we've learned about the botnets shows just how useful these networks have been to China.
The first to be disrupted was the KV botnet in December 2023. Lumen Technology's Black Lotus Labs, who discovered it, said the botnet had been active since at least February 2022. Two years seems a pretty good run, particularly considering the network was used by Volt Typhoon, a group compromising US critical infrastructure for potential sabotage.
In retrospect, though, it appears the KV botnet detection was an outlier compared to the other two, in that it was detected relatively quickly.
Raptor Train, also discovered by Black Lotus Labs, was formed in May of 2020 and was disrupted four and a half years later in September 2024. The DoJ linked that botnet with a different Chinese state-sponsored group, Flax Typhoon.
It's not clear how long QTRouter and QScan have been around, but the QTFY group has been supporting the Chinese government for close to a decade, since "at least 2018", according to the DoJ. Lumen, which described the broader QScan and QTRouter system last week, said that it had been tracking the network for a year.
It's clear that China is very effectively leveraging its commercial sector to develop these cyberespionage botnets. As well as QTFY, Raptor Train was also attributed by the US government to a Chinese technology company.
In addition, QTFY itself is also using commercial services. To backhaul traffic into China it buys what Lumen describes as "high-tier corporate subscriptions" to a Chinese commercial VPN service, Fastlink. Lumen believes it does this because it is easier than having to compromise and manage even more devices in a relay network.
So, China has been making hay for years using commercially provided services and these systems are resilient to US disruption efforts. Lumen reports that since the KV botnet was disrupted in late 2023, a sister network known as the JDY botnet has more than doubled in size.
So we're in the midst of a US-China discover, disrupt, rebuild and hack cycle. The US won this week's battle, but China hasn't lost the war.
The ATF Hack May Have Been a Big Deal
The Qilin ransomware group has claimed it breached the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). This is the kind of incident that makes the group a perfect target to unleash America's private sector hackers on.
On Tuesday this week, the Russian-speaking Qilin ransomware-as-a-service group, per the International Cyber Digest X account, "briefly published" 6.3 GB of data it claimed to have stolen from the ATF. This included case folders that held names, phone numbers and IP addresses of investigation targets and forensic data from mobile phones.
While the ATF hasn't confirmed that the data was actually from its systems, late last week the Bureau's Director Rober Cekada confirmed the ATF was investigating the breach of its CALEA system or lawful exceptional access system.
That appears consistent with the information published by Qilin.
It feels like an odd, risky move for a ransomware operator to extort a US federal government law enforcement organisation. The government is unlikely to pay a ransom and there is also a risk of retaliation. There's a far higher chance of all pain, no gain than there is of yielding a big payday.
From the US government's perspective, it would be nice to reinforce that by punching back in a way that deters other criminals. Unfortunately, breaches of government systems are distressingly common and historically it hasn't had spare capacity to try to scare cybercriminals away from its systems.
Last month, however, the Trump administration decided to unleash America's private sector on cybercriminals. Before this announcement, it was inconceivable that the FBI or Cyber Command would target Qilin in response. They've got too many other pressing priorities.
The memo announcing that private sector hackers would be recruited to tackle cybercrime didn't spell out how operations would be prioritised. But a Russian-speaking ransomware operation targeting a government CALEA system? That should be up there.
Water Water Everywhere, But No Money
This week National Cyber Director Sean Cairncross announced the launch of Project Watershed 250, a six-month pilot program in Texas, as reported by CyberScoop. The initiative might find bang-for-buck ways to improve security, but it's not actually providing any more bucks.
Cairncross said the initiative "is designed to make our water and wastewater critical infrastructure more resilient and resistant to cyber attacks by proactively finding and fixing system weaknesses".
A dozen companies are involved in the project, including Microsoft, Google, AWS and Dragos. Cairncross said they will provide "world-class cyber capabilities", such as red teaming to test defences, and the latest private sector cyber and AI tools. The idea is to figure out what works and then scale that across the country.
That's great and all, but knowing what to fix is just half of the solution. Water sector entities need enough people with the skills and time to actually implement fixes. That’s a pretty significant other half, one that Project Watershed 250 doesn't address at all.
Let's not forget that much of the US water sector has very bad security. In the aftermath of recent Iranian cyber attacks on water utilities, CISA's advice was remedial: Remove targeted devices from the internet and to connect to them using VPNs, enable passwords and make them strong, and allowlist IP addresses for remote access. So, do the basics.
The sector is also highly decentralised, with 50,000 community water systems, most of which serve less than 10,000 people. Most water organisations are small. Cybersecurity? They don't have the resources to deal with that.
Recent Iranian attacks may be providing motivation to fix things, but handing a bunch of free tools to poorly resourced, unskilled and insecure organisations, then wishing them luck, won't fix much.
Watch James Wilson and Tom Uren discuss this edition of the newsletter:
Three Reasons to Be Cheerful This Week:
- Meta tackles terrorists, fraud, surveillance-for-hire: Meta's August 2026 adversarial threat report describes how it has tackled a variety of different threats and disrupted the networks associated with them. It's striking how many varied threats Meta is taking on and it is great that the company is doing this work. Although we can't help thinking that Meta sometimes has conflicting priorities and it should be encouraged to do even more.
- US government to centralise logins: The Office of Management and Budget has issued a memo directing public-facing federal agencies to move toward the login.gov single sign-on platform. The centralised service should be more secure and more efficient, although we expect it will take time to get there. Federal News Network has more coverage.
- Nigerians extradited for sextortion charges: Two Nigerian men have been extradited to the US to face charges related to financially motivated sextortion. The abuse resulted in the death of teenagers in Mississippi and North Carolina. The pair were arrested in 2023.
Sponsor Section
In this Risky Business sponsor interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, "an attacker only has to be right once."
Risky Biz Talks
You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (RSS, iTunes or Spotify).
In our last "Between Two Nerds" discussion Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals.
Or watch it on YouTube!
From Risky Bulletin:
BGP hijack targets Virtualizor to deliver malicious updates: An unidentified threat actor has pulled off a successful BGP hijack that commandeered some of the IP address space and internet routing for software company Softacolous to deliver malicious updates for the Virtualizor web hosting management platform.
The BGP hijack took place for almost 33 hours, from Friday to Sunday last week.
The Virtualizor team says the hacker performed the BGP hijack, obtained a TLS certificate in its name, and hosted a clone website that delivered the malicious updates.
Virtualizer says it can't tell how many users were affected by the incident because it didn't see or log any of the hijacked traffic, which passed exclusively through the attacker's infrastructure.
[more on Risky Bulletin]
Dutch intel services to get extensive new powers: The Dutch government has put forward a new bill that would greatly expand the surveillance powers of the country's two intelligence agencies.
The new bill simplifies procedures to improve operational speed but also adds new requirements and capabilities.
Officials cited the threat of war with Russia and the increasing aggressiveness of countries like China and Iran as the main reason to overhaul the capabilities of AIVD, its domestic security and intelligence service, and MIVD, its military counterpart.
The main changes are in regards to surveillance and offensive hacking operations that target countries designated as "foreign adversaries."
[more on Risky Bulletin]
Two TeamPCP members arrested in Australia: The Australian Federal Police has arrested on Wednesday two suspects believed to be part of the TeamPCP hacking group.
The suspects were detained in Cottesloe and Mandurah, near the city of Perth, in Western Australia. They appeared in front of a Perth magistrate to be charged on Thursday.
According to local media, the suspect arrested in Cottesloe was identified as Ruben Thomson, 21, the group's alleged leader. The Mandurah man was identified as Louis Gaebler, 23.
The two are accused of carrying out multiple software supply-chain attacks earlier this year. Their most successful incidents include the compromises of open-source projects like Trivy, KICS, LiteLLM, and Telnyx.