The U.S. DOJ (Department of Justice) and FBI (Federal Bureau of Investigation) announced court-authorized seizures of domains associated with two complementary hacking platforms, QScan and QTRouter.
According to court documents unsealed in the Southern District of California, the platforms were created and operated by QTFY, a PRC (People’s Republic of China) state-sponsored hacking group employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).
The platforms were allegedly used to target U.S. critical infrastructure and other sensitive networks. Victims identified in court documents include the National Aeronautics and Space Administration (NASA), Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, and National Institutes of Health.
Summary
| Key detail | Information |
|---|---|
| Platforms seized | QScan and QTRouter |
| Threat actor | QTFY |
| Country linked to threat actor | China / PRC |
| Associated company | Nanjing Xinjiuwei Network Technology Company |
| Primary targets | U.S. critical infrastructure and sensitive networks |
| QScan function | Scans and automatically infects IoT devices |
| QTRouter function | Uses compromised devices and other infrastructure as an obfuscation network |
| Government customers identified | PRC Ministry of State Security and People’s Liberation Army |
| Action taken | Court-authorized domain seizures |
| Result | QScan and QTRouter were rendered inoperable |
| Investigation | FBI San Diego Field Office and FBI Cyber Division |
DOJ and FBI disrupt QScan and QTRouter
The court-authorized seizures were designed to prevent malicious cyber actors from accessing QScan and QTRouter.
According to the DOJ, the two platforms worked together to enable computer intrusion activity. QScan was used to identify and automatically infect internet-connected devices, while QTRouter used compromised infrastructure to help conceal the origin of cyberattacks.
QScan targeted internet-connected devices
According to court documents, QTFY offered computer hacking services to paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army.
QScan allegedly scanned thousands of internet-of-things (IoT) devices around the world and automatically infected vulnerable devices. These compromised devices were subsequently incorporated into the QTRouter network controlled by QTFY.
QTRouter created an obfuscation network
QTRouter consisted of compromised IoT devices, commercial proxy service devices and leased virtual private servers.
The network allegedly functioned as an “obfuscation network,” allowing QTFY and other malicious cyber actors to conceal the PRC origin of their computer intrusion activities.
As a result, malicious communications could appear to originate from computers outside China, including devices located near or within networks being targeted.
Iranian national charged for smuggling illegal aliens into united states — DOJ.
Why the domain seizures disrupted the platforms
The seized domains played an important role in the operation of QScan and QTRouter.
Domains were hard-coded into the malware
According to the DOJ, the seized domains were hard-coded into both QScan and QTRouter malware and were required for functions including communication and authentication.
By taking control of those domains through court-authorized seizures, U.S. authorities disrupted the platforms’ ability to perform essential functions.
The action therefore made QScan and QTRouter inoperable, preventing the operators and other malicious actors from continuing to use the seized infrastructure in the same manner.
Attorney General Todd Blanche said state-sponsored malicious hackers targeting U.S. critical infrastructure would be stopped and prosecuted.
Chinese national pleads guilty in attempt to obtain sensitive U.S. military technology
He added that the Justice Department would use available tools to protect the security of Americans.
FBI Director highlights technical disruption
FBI Director Kash Patel said federal law enforcement had investigated and disabled the malicious software and described the action as part of broader efforts to disrupt PRC-sponsored hacking activities.
Patel said the platforms had been used by PRC cyber actors to hide the origin of their attacks.
He also credited the FBI San Diego Field Office, FBI Cyber Division and DOJ partners for helping seize adversary infrastructure and shut down the platforms.
National Security Division response
Assistant Attorney General for National Security John A. Eisenberg said the action demonstrated the Justice Department’s commitment to taking an offensive approach against cyber threats to U.S. national security.
He said the court-authorized seizures deny PRC-linked hackers access to tools used to target U.S. critical infrastructure.
Southern District of California response
U.S. Attorney Adam Gordon for the Southern District of California said the government was taking action against PRC-sponsored cybercriminals to protect critical services relied upon by Americans.
Special Agent in Charge Mark Remily of the FBI San Diego Field Office said the FBI would continue using complex investigations and technical operations to identify and disrupt nation-state cyber actors.
China stops Meta’s Manus acquisition over concerns about AI expertise transfer
QTFY activity and previous U.S. cyber operations
The QScan and QTRouter disruption is part of a broader series of U.S. technical operations targeting infrastructure associated with PRC-sponsored cyber activity.
Previous FBI disruptions
- 2025: The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the PRC-sponsored hacker group Mustang Panda.
- 2024: The FBI disabled a botnet consisting of hundreds of thousands of infected IoT devices that the PRC-sponsored hacking group Flax Typhoon was allegedly providing to customers in the Chinese government.
- 2023: The FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal exploitation of U.S. and foreign critical infrastructure.
FBI and NSA publish QTFY cybersecurity advisory
Alongside the domain seizures, the FBI and NSA (National Security Agency) published a cybersecurity advisory containing indicators of compromise associated with QTFY.
Iran in freefall could trigger India’s next strategic crisis
The advisory is based on analysis of QTFY’s malicious cyber activity dating back to at least 2018.
The information is intended to help organizations identify activity associated with the threat actor and strengthen their defenses against related cyber threats.
Threat intelligence analysis
Lumen Technologies’ threat intelligence group, Black Lotus Labs, also published an analysis of QTFY’s tactics, techniques and procedures.
The analysis provides additional information about the infrastructure and methods associated with the China-linked cyber activity.
The FBI’s San Diego Field Office and Cyber Division, along with the U.S. Attorney’s Office for the Southern District of California, were involved in the investigation and disruption.
What the QScan and QTRouter seizure means
The action demonstrates how U.S. authorities can use court-authorized technical operations and domain seizures to disrupt cyber infrastructure used by state-sponsored threat actors.
Rather than targeting only individual hackers, the operation focused on infrastructure that supported the delivery, communication and concealment of malicious cyber activity.
The disruption also highlights the security risks posed by compromised IoT devices, proxy infrastructure and virtual private servers when they are incorporated into larger networks used to conceal the source of cyberattacks.
The DOJ and FBI said the operation is part of continuing efforts to identify, disrupt and impose costs on cyber actors threatening U.S. national security and critical infrastructure.
To read the original order please visit DOJ (department of justice) website

