US Seizes Domains For Chinese QScan, QTRouter Hacking Tools

US Department of Justice and the Federal Bureau of Investigation (FBI) have seized domains powering QScan and QTRouter, hacking tools linked to a Chinese state-sponsored group.
The action, announced last Thursday, followed court authorisation and targeted infrastructure the department says was used against US critical infrastructure and other sensitive networks.
Court documents unsealed in the Southern District of California identify the group behind the platforms as QTFY, a People’s Republic of China state-sponsored operation employed by Nanjing Xinjiuwei Network Technology Company.
The filings named seven victims of QTFY intrusion activity: the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.
Attorney General Todd Blanche said “state-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
According to the court documents, QTFY sold computer hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. Those services centred on two linked tools.
QScan scanned the internet and automatically infected thousands of IoT devices worldwide. Once compromised, those devices were folded into QTRouter, a network QTFY controlled directly. QTRouter combined three sources of infrastructure: the IoT devices that QScan had compromised, commercial proxy service devices, and leased virtual private servers.
The department describes QTRouter as an “obfuscation network,” meaning it let QTFY and other malicious actors conceal the PRC origin of their intrusion activity. Traffic routed through compromised devices outside China, and in some cases through machines local to the target itself, so the malicious communications could appear to come from anywhere but Beijing.
FBI director, Kash Patel described the seizure as the disruption of “a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure.”
He said the tools “were used by PRC cyber actors to hide the origin of their attacks,” and credited FBI San Diego, the FBI Cyber Division, and Justice Department partners with seizing the infrastructure and shutting the platforms down.
The seizures worked because those domains for essential functions, including communication back to operators and authentication between infected devices. Removing that infrastructure from QTFY’s control left the malware unable to function, according to the department.
Assistant Attorney General for National Security, John A. Eisenberg said the seizures “deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.” He called the operation evidence of “the Justice Department’s steadfast commitment to going on the offensive against cyber threats to national security.”
The action extends a run of court-authorised technical operations over the past few years that the department has taken against PRC-linked hacking groups:
2025: The FBI removed PlugX surveillance malware from more than 4,000 US computers that had been infected by the PRC-sponsored group Mustang Panda.
2024: The bureau disabled a botnet made up of hundreds of thousands of infected IoT devices that the PRC-sponsored group Flax Typhoon had been supplying to customers within the Chinese government.
2023: The FBI disrupted a separate botnet that the PRC-sponsored group Volt Typhoon used to hide its exploitation of critical infrastructure in the United States and abroad.
FBI San Diego Special Agent in Charge Mark Remily said that the field office “will continue to identify, disrupt, and impose costs on our cyber adversaries” through what he called complex investigations, aggressive technical operations, and strong partnerships. Remily said the bureau remains “committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”
The QTFY disruption arrived alongside two other releases. The FBI and National Security Agency published a cybersecurity advisory listing indicators of compromise associated with QTFY, drawn from analysis of activity the two agencies trace back to at least 2018.
Separately, Lumen Technologies’ threat intelligence unit – Black Lotus Labs – published its own account of QTFY’s tactics, techniques, and procedures, describing what it called a China-nexus state enablement model.


