US DOJ and FBI seize QScan and QTRouter platforms used by China-linked QTFY hackers

More Articles

Tejaswini Deshmukh
Tejaswini Deshmukh
Tejaswini Deshmukh is the contributing editor of RegTech Times, specializing in defense, regulations and technologies. She analyzes military innovations, cybersecurity threats, and geopolitical risks shaping national security. With a Master’s from Pune University, she closely tracks defense policies, sanctions, and enforcement actions. She is also a Certified Sanctions Screening Expert. Her work highlights regulatory challenges in defense technology and global security frameworks. Tejaswini provides sharp insights into emerging threats and compliance in the defense sector.

The U.S. DOJ (Department of Justice) and FBI (Federal Bureau of Investigation) announced court-authorized seizures of domains associated with two complementary hacking platforms, QScan and QTRouter.

According to court documents unsealed in the Southern District of California, the platforms were created and operated by QTFY, a PRC (People’s Republic of China) state-sponsored hacking group employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).

The platforms were allegedly used to target U.S. critical infrastructure and other sensitive networks. Victims identified in court documents include the National Aeronautics and Space Administration (NASA), Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, and National Institutes of Health.

Summary

Key detail Information
Platforms seized QScan and QTRouter
Threat actor QTFY
Country linked to threat actor China / PRC
Associated company Nanjing Xinjiuwei Network Technology Company
Primary targets U.S. critical infrastructure and sensitive networks
QScan function Scans and automatically infects IoT devices
QTRouter function Uses compromised devices and other infrastructure as an obfuscation network
Government customers identified PRC Ministry of State Security and People’s Liberation Army
Action taken Court-authorized domain seizures
Result QScan and QTRouter were rendered inoperable
Investigation FBI San Diego Field Office and FBI Cyber Division

DOJ and FBI disrupt QScan and QTRouter

The court-authorized seizures were designed to prevent malicious cyber actors from accessing QScan and QTRouter.

According to the DOJ, the two platforms worked together to enable computer intrusion activity. QScan was used to identify and automatically infect internet-connected devices, while QTRouter used compromised infrastructure to help conceal the origin of cyberattacks.

QScan targeted internet-connected devices

According to court documents, QTFY offered computer hacking services to paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army.

QScan allegedly scanned thousands of internet-of-things (IoT) devices around the world and automatically infected vulnerable devices. These compromised devices were subsequently incorporated into the QTRouter network controlled by QTFY.

QTRouter created an obfuscation network

QTRouter consisted of compromised IoT devices, commercial proxy service devices and leased virtual private servers.

The network allegedly functioned as an “obfuscation network,” allowing QTFY and other malicious cyber actors to conceal the PRC origin of their computer intrusion activities.

As a result, malicious communications could appear to originate from computers outside China, including devices located near or within networks being targeted.

Iranian national charged for smuggling illegal aliens into united states — DOJ.

Why the domain seizures disrupted the platforms

The seized domains played an important role in the operation of QScan and QTRouter.

Domains were hard-coded into the malware

According to the DOJ, the seized domains were hard-coded into both QScan and QTRouter malware and were required for functions including communication and authentication.

By taking control of those domains through court-authorized seizures, U.S. authorities disrupted the platforms’ ability to perform essential functions.

The action therefore made QScan and QTRouter inoperable, preventing the operators and other malicious actors from continuing to use the seized infrastructure in the same manner.

Official statements from U.S. authorities

Attorney General Todd Blanche said state-sponsored malicious hackers targeting U.S. critical infrastructure would be stopped and prosecuted.

Chinese national pleads guilty in attempt to obtain sensitive U.S. military technology

He added that the Justice Department would use available tools to protect the security of Americans.

FBI Director highlights technical disruption

FBI Director Kash Patel said federal law enforcement had investigated and disabled the malicious software and described the action as part of broader efforts to disrupt PRC-sponsored hacking activities.

Patel said the platforms had been used by PRC cyber actors to hide the origin of their attacks.

He also credited the FBI San Diego Field Office, FBI Cyber Division and DOJ partners for helping seize adversary infrastructure and shut down the platforms.

National Security Division response

Assistant Attorney General for National Security John A. Eisenberg said the action demonstrated the Justice Department’s commitment to taking an offensive approach against cyber threats to U.S. national security.

He said the court-authorized seizures deny PRC-linked hackers access to tools used to target U.S. critical infrastructure.

Southern District of California response

U.S. Attorney Adam Gordon for the Southern District of California said the government was taking action against PRC-sponsored cybercriminals to protect critical services relied upon by Americans.

Special Agent in Charge Mark Remily of the FBI San Diego Field Office said the FBI would continue using complex investigations and technical operations to identify and disrupt nation-state cyber actors.

China stops Meta’s Manus acquisition over concerns about AI expertise transfer

QTFY activity and previous U.S. cyber operations

The QScan and QTRouter disruption is part of a broader series of U.S. technical operations targeting infrastructure associated with PRC-sponsored cyber activity.

Previous FBI disruptions

  • 2025: The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the PRC-sponsored hacker group Mustang Panda.
  • 2024: The FBI disabled a botnet consisting of hundreds of thousands of infected IoT devices that the PRC-sponsored hacking group Flax Typhoon was allegedly providing to customers in the Chinese government.
  • 2023: The FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal exploitation of U.S. and foreign critical infrastructure.

FBI and NSA publish QTFY cybersecurity advisory

Alongside the domain seizures, the FBI and NSA (National Security Agency) published a cybersecurity advisory containing indicators of compromise associated with QTFY.

Iran in freefall could trigger India’s next strategic crisis

The advisory is based on analysis of QTFY’s malicious cyber activity dating back to at least 2018.

The information is intended to help organizations identify activity associated with the threat actor and strengthen their defenses against related cyber threats.

Threat intelligence analysis

Lumen Technologies’ threat intelligence group, Black Lotus Labs, also published an analysis of QTFY’s tactics, techniques and procedures.

The analysis provides additional information about the infrastructure and methods associated with the China-linked cyber activity.

The FBI’s San Diego Field Office and Cyber Division, along with the U.S. Attorney’s Office for the Southern District of California, were involved in the investigation and disruption.

What the QScan and QTRouter seizure means

The action demonstrates how U.S. authorities can use court-authorized technical operations and domain seizures to disrupt cyber infrastructure used by state-sponsored threat actors.

Rather than targeting only individual hackers, the operation focused on infrastructure that supported the delivery, communication and concealment of malicious cyber activity.

The disruption also highlights the security risks posed by compromised IoT devices, proxy infrastructure and virtual private servers when they are incorporated into larger networks used to conceal the source of cyberattacks.

The DOJ and FBI said the operation is part of continuing efforts to identify, disrupt and impose costs on cyber actors threatening U.S. national security and critical infrastructure.

To read the original order please visit DOJ (department of justice) website

Latest