Skip to main content
Cyber DefenseInfrastructure Takedown· 4 min read· in Technology

FBI and DOJ Seize 'QScan' and 'QTRouter' Platforms in Takedown of China-Linked Hacking Network

Federal law enforcement has dismantled two complementary hacking platforms used by state-sponsored actors to mask cyberattacks against U.S. critical infrastructure. The court-authorized seizure of hard-coded domains rendered the tools inoperable, cutting off a major obfuscation network.

By Wei Zhang

Federal Law Enforcement 40%Enterprise Network Defenders 40%The Chinese Government 20%
Federal Law Enforcement
Focuses on active disruption of adversary infrastructure to neutralize immediate threats.
Enterprise Network Defenders
Emphasizes the need to adapt defenses against attacks routed through domestic consumer devices.
The Chinese Government
Denies involvement in offensive cyber operations and accuses the U.S. of hypocrisy.

Perspectives this story doesn't cover

  • Consumer IoT Manufacturers
  • Civil Liberties Groups

How we got here

  1. 2018

    The QTFY hacking group begins operations, targeting U.S. critical infrastructure.

  2. August 2019

    The group attempts to breach NASA by exploiting a virtual private network vulnerability, but fails.

  3. 2023-2024

    The FBI conducts similar takedowns against the Volt Typhoon and Flax Typhoon botnets.

  4. August 26, 2026

    The DOJ and FBI announce the seizure of the hard-coded domains powering QScan and QTRouter.

Why it matters

The takedown exposes how state-sponsored hackers bypass traditional enterprise defenses by routing their attacks through everyday consumer devices. For organizations, it underscores that blocking foreign IP addresses is no longer enough; for consumers, it highlights how an unpatched home router can become an unwitting accessory to international cyber espionage.

When people picture nation-state cyberwarfare, they often imagine elite hackers deploying million-dollar zero-day exploits against fortified government mainframes. The reality is far more mundane—and far more effective. For years, a Chinese state-sponsored group known as QTFY bypassed United States defenses not by breaking the cryptography of federal agencies, but by hijacking thousands of outdated home routers and internet-connected cameras. By routing their attacks through these everyday consumer devices, the hackers made their malicious traffic look like it was coming from local, innocuous sources, effectively blinding traditional perimeter security systems.[1][3]

On August 26, the Department of Justice and the Federal Bureau of Investigation announced the seizure of the infrastructure powering this operation, neutralizing two complementary platforms known as QScan and QTRouter. While official statements heavily emphasize the defense of critical infrastructure, the technical mechanism of the takedown reveals a pragmatic shift in how law enforcement handles these threats. Authorities did not attempt to arrest the operators in China; instead, they identified the hard-coded domains the malware relied on for authentication and seized them through court orders, instantly rendering the platforms inoperable.[1][2]

To understand the threat, it is necessary to look past the 'advanced persistent threat' marketing language often used by cybersecurity vendors and examine the actual capability. The operation relied on a highly automated, two-part system. QScan functioned as the scouting engine, constantly scouring the public internet for vulnerable internet-of-things devices. Once it found a weak smart device, an unpatched router, or an exposed security camera, it infected the hardware and folded it into a growing, globally distributed botnet without the device owner ever noticing a drop in performance.[1][3]

The second half of the system, QTRouter, served as the obfuscation engine. It combined the hijacked internet-of-things devices with commercial proxy services and leased virtual private servers to create a massive, decentralized routing network. When QTFY operators launched an attack against a target, they funneled their traffic through this maze. To the victim's security software, the intrusion did not appear to originate from a server in Beijing; it looked like routine internet traffic coming from a compromised home router in a neighboring city, bypassing geographic blocking entirely.[1][4]

How QTFY utilized QScan and QTRouter to build an obfuscation network.
The second half of the system, QTRouter, served as the obfuscation engine.

This proxy network allowed the group to quietly target high-value U.S. institutions for years. According to unsealed court documents from the Southern District of California, the confirmed victim list includes NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, and the National Institutes of Health. The group also directed its tools at hospitals, telecommunications providers, and defense contractors, using the obfuscated network to probe for vulnerabilities, steal sensitive data, and establish persistent footholds within critical infrastructure networks.[1][2][4]

The Department of Justice attributes the operation to Nanjing Xinjiuwei Network Technology Company, a private firm based in China. Court documents allege that the company operates as a contractor, selling its hacking services and stolen data to paying clients, primarily China's Ministry of State Security and the People's Liberation Army. This 'infrastructure quartermaster' model allows state intelligence agencies to rent ready-made proxy networks rather than building and maintaining their own, lowering the barrier to entry for offensive cyber operations and complicating attribution for defenders.[1][3]

The Department of Justice and the FBI seized the hard-coded domains powering the hacking platforms, instantly rendering them inoperable.

The QScan and QTRouter seizure is not an isolated incident, but rather the latest in a series of technical disruptions aimed at state-sponsored botnets. In 2024, the FBI dismantled a similar internet-of-things botnet operated by the China-linked group Flax Typhoon, and in 2023, it disrupted infrastructure used by Volt Typhoon. The strategy has clearly shifted from issuing indictments against untouchable foreign nationals to actively dismantling the infrastructure they rent to do their jobs, treating cyber defense as an ongoing campaign of resource denial.[1][2]

While the seizure of the QScan and QTRouter domains successfully neutralized this specific network, the underlying vulnerability remains entirely unpatched. The internet is still saturated with insecure, easily compromised consumer devices that can be quickly assembled into new proxy networks by the next contractor. For enterprise defenders, the takedown reinforces a difficult reality: blocking suspicious geographic IP addresses is no longer sufficient when state-sponsored attackers are routing their traffic through the smart thermostat down the street, forcing a necessary shift toward behavioral analysis and zero-trust architectures.[3][4]

What to know

  • The DOJ and FBI seized domains powering QScan and QTRouter, two hacking platforms used by a China-linked group.
  • The platforms hijacked thousands of vulnerable internet-of-things devices to create a massive proxy network.
  • This obfuscation network allowed hackers to hide the origin of attacks against NASA, the Federal Reserve, and the U.S. Senate.
  • The operation highlights a shift in U.S. strategy toward actively dismantling adversary infrastructure rather than just issuing indictments.
  • The seizure rendered the malware inoperable because the targeted domains were hard-coded into the tools for authentication.

Where opinion splits

Federal Law Enforcement

Focuses on active disruption of adversary infrastructure rather than just issuing indictments.

For years, the U.S. government's primary response to state-sponsored hacking was to issue indictments against foreign intelligence officers who would never see a courtroom. The takedown of QScan and QTRouter reflects a strategic pivot toward active technical disruption. By identifying the hard-coded domains that the malware relies on for authentication and seizing them through court orders, the FBI and DOJ can instantly dismantle the tools the attackers use. This approach treats cyber defense as an ongoing campaign of infrastructure denial, forcing adversaries to constantly rebuild their proxy networks.

Enterprise Network Defenders

Highlights the difficulty of detecting attacks that originate from domestic, consumer-grade IP addresses.

For cybersecurity teams protecting critical infrastructure, the tactics used by groups like QTFY present a severe detection challenge. Traditional perimeter defense often relies on blocking traffic from known malicious IP addresses or geographic regions associated with hostile actors. However, when an attack is routed through a compromised home router in the same city as the target, it bypasses these geographic filters. Defenders argue that this necessitates a shift toward behavioral analysis and zero-trust architecture, as the origin of the traffic can no longer be trusted as an indicator of safety.

The Chinese Government

Consistently denies involvement in state-sponsored hacking and accuses the U.S. of hypocrisy.

While the Chinese Embassy did not issue a specific response to the QScan takedown, Beijing's standard diplomatic posture is to categorically deny allegations of state-sponsored cyberattacks. Chinese officials routinely argue that China is a primary victim of cyber espionage and accuse the United States of overstretching the concept of national security to smear Chinese technology companies. They frequently point to the U.S. government's own extensive cyber operations as evidence of a double standard in international cyber norms.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Federal Law Enforcement 40%Enterprise Network Defenders 40%The Chinese Government 20%
  1. [1]U.S. Department of JusticeFederal Law Enforcement

    Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

    Read on U.S. Department of Justice
  2. [2]MeriTalkFederal Law Enforcement

    FBI, DOJ Seize China-Linked Hacking Platforms Targeting Federal Agencies

    Read on MeriTalk
  3. [3]Security AffairsEnterprise Network Defenders

    FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

    Read on Security Affairs
  4. [4]Cyber MagazineEnterprise Network Defenders

    How China-Linked Hackers Targeted NASA, US DoJ and Senate

    Read on Cyber Magazine

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.