DOJ, FBI Seize China-Linked QScan and QTRouter Tools
The DOJ and FBI seized QScan and QTRouter, platforms a China state-sponsored group used to breach NASA, the Federal Reserve, and the US Senate. What happened.
The U.S. Justice Department and FBI announced on August 26, 2026 that they had carried out court-authorized domain seizures to disable two hacking platforms — QScan and QTRouter — that a China state-sponsored group used to target U.S. critical infrastructure and sensitive government networks. Court documents unsealed the same day in the Southern District of California name victims that read like a directory of the federal government: NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
Two tools, one intrusion pipeline
QScan and QTRouter were built to work together, and the seizure targeted both halves of the operation.
QScan was the reconnaissance engine. It continuously scanned the internet for vulnerable devices, and prosecutors say it infected thousands of Internet of Things (IoT) devices — the routers, cameras, and embedded systems that sit exposed at the edge of networks and rarely get patched. Those compromised devices gave the operators a large, disposable population of footholds to launch attacks from.
QTRouter was the concealment layer. It functioned as an obfuscation network, routing malicious traffic through systems outside China so that intrusions appeared to originate somewhere else. That indirection is what makes state-sponsored campaigns so hard to attribute and block: by the time a defender sees the traffic, it is arriving from a compromised device in a third country, not from the operator’s real infrastructure. It is the same logic that makes botnets and distributed denial-of-service attacks so difficult to trace to a source.
Together the two platforms formed a pipeline — QScan to find and infect exposed devices, QTRouter to launder the resulting traffic — that let a small team project intrusions across a wide surface while staying hidden.
Who was behind it
According to the unsealed court documents, the platforms were created and operated by a People’s Republic of China state-sponsored group known as “QTFY,” employed by a China-based firm, Nanjing Xinjiuwei Network Technology Company. The group did not act alone or purely for the state’s direct benefit: prosecutors say QTFY offered hacking services to paying clients, and that those clients included China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA).
That “hackers-for-hire” structure — a nominally commercial company selling intrusion capabilities to intelligence and military customers — has become a recurring feature of Chinese cyber operations. It gives the state deniability and a layer of separation, while giving the contractor a business model. It also blurs the line between espionage and crime in a way that complicates the U.S. response.
Attorney General Todd Blanche framed the action in enforcement terms: “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.”

Why seizing domains actually works
Taking down a nation-state operation by seizing a handful of web domains sounds modest. In this case it was surgical.
The seized domains were hard-coded into both the QScan and QTRouter malware and used for essential functions — command-and-control communication and authentication. Malware that phones home to a fixed set of domains is only as durable as its ability to reach them. Because the operators baked those addresses directly into the code, redirecting the domains under court order rendered QScan and QTRouter inoperable: the infected devices could no longer receive instructions or authenticate to their operators, and the tools went dark without the FBI having to touch every compromised machine.
That is the leverage law enforcement looks for. Rather than chasing thousands of individual IoT infections, agents cut the single cord the whole network depended on. It is a reminder of why hard-coded infrastructure is a design weakness — and why more sophisticated malware families invest so heavily in resilient, decentralized command-and-control.
Part of a pattern
The takedown lands amid a steady drumbeat of Chinese state-linked activity against U.S. and allied networks. Some of it is opportunistic exploitation of unpatched enterprise software — the same week brought fresh warnings about China-linked exploitation of a maximum-severity flaw in Oracle WebLogic’s proxy plug-in, used against governments in more than 100 countries. Some of it is the industrialization of intrusion tooling into rentable platforms, of which QScan and QTRouter are a textbook example.
The strategic aim behind targeting entities like the Department of Energy, the Federal Reserve, and NASA is not always immediate theft. Access to critical-infrastructure and government networks is a strategic pre-position — a foothold held in reserve, to be used for espionage now or disruption later. That is precisely the threat model that has pushed U.S. agencies and enterprises toward architectures that assume breach rather than trust the perimeter, an approach we cover in our explainer on zero-trust security.
The broader trend is that offensive tooling keeps getting easier to operate and harder to attribute, whether it is a state contractor’s obfuscation network or the agentic ransomware starting to automate the attack chain itself.
What it means
The QScan and QTRouter seizure is a real disruption, but it is best understood as attrition, not victory. Knocking out two platforms inoperable today does not arrest the operators, who sit in China beyond the reach of a U.S. warrant, and it does not stop QTFY — or the next contractor — from rebuilding with fresh domains and new infrastructure. The Justice Department’s own framing, promising that hackers will be “stopped and prosecuted,” runs into the hard limit that prosecution requires custody the U.S. is unlikely to get.
What the action does accomplish is threefold. It buys defenders time by severing a live command-and-control network. It converts classified intelligence into a public, court-documented record that names the company, the group, and the government clients — raising the diplomatic and reputational cost of the operation. And it demonstrates a repeatable playbook: find the fixed infrastructure a campaign depends on, get a court order, and cut it, without having to remediate every victim device.
The uncomfortable takeaway for defenders is the attack surface itself. QScan’s entire foothold came from thousands of exposed, unpatched IoT devices — the routers and cameras and embedded systems that organizations forget they own. Nation-state operators do not need a zero-day when the internet is full of edge devices with default credentials and no update path. The single most durable lesson from this case is not about QTFY’s cleverness; it is that the raw material for a state-sponsored botnet is sitting, unmanaged, on ordinary networks. Until that changes, seizing domains will keep being a game of cutting one cord while the next is already being spliced.
Keep reading
Chisato · · 7 min read CISA Warns: AI-Written Exploits Hit Siemens Water PLCs
Five U.S. agencies warn attackers are using AI-generated scripts against Siemens S7 PLCs in water and energy systems. Advisory AA26-231A, the incidents, defenses.
Chisato · · 7 min read DeepSeek AI Autonomous Cyberattack: Unit 42 Findings
Palo Alto's Unit 42 found a Chinese-speaking hacker wiring DeepSeek into the Hermes Agent framework to attack 460+ servers, largely on its own via Telegram.
Kurumi · · 6 min read AI Stocks Fall, Cybersecurity Rallies on Slowdown Calls
Chip and AI names sold off while CrowdStrike and Palo Alto surged after Amodei, Altman and Musk backed pacing frontier AI. Jensen Huang pushed back.