Illustrative image generated with AI
Chinese QScan and QTRouter platforms seized, used to target US agencies
DOJ seizes Chinese QScan and QTRouter platforms used to hack US agencies and infrastructure, part of ongoing cyber operations.
Text generated by artificial intelligence, published without human review. AI transparency
The U.S. Department of Justice announced on Wednesday, August 26, 2026, the seizure of QScan and QTRouter, two platforms operated by the Chinese company Nanjing Xinjiuwei Network Technology Company. They were used by Chinese government hackers, particularly the Ministry of State Security (MSS) and the People's Liberation Army (PLA), to compromise federal agencies and sensitive networks. The group known as QTFY has used these tools since 2018 to target U.S. critical infrastructure and objectives worldwide.
The seizure and the Chinese operator
The takedown operation targeted the hard-coded domains in the two platforms. QScan and QTRouter relied on these addresses for essential activities such as communication and authentication. Seizing the domains rendered both platforms inoperable. Nanjing Xinjiuwei Network Technology Company, based in China, sold stolen data and hacking services to Chinese military and intelligence agencies. The FBI reported that QTFY operates within a complex network of contract hackers and government clients in China. The FBI also stated that QTFY had unspecified clients outside the Chinese government as well.
How QScan and QTRouter worked
QScan was an automated scanning and infection platform for Internet of Things devices. It identified vulnerable home routers, security cameras, and other smart devices worldwide, infected them at scale, and aggregated them into a botnet. QTRouter served as an obfuscation network. It allowed attackers to mask the origin of attacks, making them appear to come from infected devices or other countries. In some cases it simulated local attacks, complicating attribution. The FBI stated that QTFY exploited devices in more than 130 countries. The combination of the two platforms made it possible to scan, infect, and then route malicious traffic through the botnet, hiding the true source.
The victims: federal agencies and critical infrastructure
Compromised agencies include the Federal Reserve, the Department of Energy, the Department of Justice itself, the U.S. Senate, NASA, the Department of Health and Human Services, and the National Institutes of Health. Hospitals, telecommunications providers, electric utilities, financial institutions, and defense contractors were also targeted. The impact extends well beyond the United States: infected devices in more than 130 countries were used as botnet nodes and to obfuscate attacks. No estimate of the total number of compromised devices was provided. It is not known whether individual stolen data was leaked or resold.
The investigations from 2018 to the Senate attack
Investigations into QTFY infrastructure began in 2018. One of the earliest incidents examined by the FBI dates back to 2019, when attackers attempted to exploit a vulnerability in Pulse Secure VPN against NASA. The IP addresses used were traced back to locations and email addresses in China. The investigations continued until an attack on the U.S. Senate this year. It was not specified whether individual senators or committees were targeted. The continuity of operations from 2018 to 2026 indicates a prolonged and organized campaign.
Takedown effects and previous operations
The seizure of the hard-coded domains disrupted communication and authentication, rendering QScan and QTRouter unusable. It was not clarified whether authorities cleaned up already infected devices. Organizations should consider checking their IoT devices for any residual compromise, although no specific mitigations have been communicated. In the past, the FBI and the Department of Justice have obtained court orders to remove malware from devices compromised by Chinese and Russian hackers. Last year the FBI removed the PlugX surveillance malware from thousands of computers in the United States. In 2024 it disrupted botnets operated by Chinese government operations known as Volt Typhoon and Flax Typhoon. The seizure of QScan and QTRouter fits into this series of actions against state-sponsored cyber campaigns.
Sources
This article is an original reworking based on the sources below.
