The U.S. Department of Justice and FBI announced August 26, 2026 that they had executed court-authorized domain seizures to disable two linked hacking platforms, known as QScan and QTRouter, used by a China-based, state-sponsored group the department identified as QTFY. According to the DOJ’s press release, court documents unsealed in the Southern District of California name Nanjing Xinjiuwei Network Technology Company as the operator of QTFY, which the department said sells hacking services to clients including the Chinese Ministry of State Security and the People’s Liberation Army.
Court filings describe QScan and QTRouter as complementary tools: QScan searches the internet and automatically infects vulnerable internet-of-things devices, such as home routers and security cameras, while QTRouter forms an obfuscation network from those compromised devices that lets operators route attack traffic through infected machines in more than 130 countries, concealing the true origin of intrusions, FBI Cyber Assistant Director Brett Leatherman said in a video statement released by the bureau.
The DOJ said the disruption made both platforms inoperable because the seized domains were hard-coded into their communication and authentication functions, a technique reported by The Record based on court documents. According to the department, victims of QTFY’s activity since at least 2018 include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, as well as power companies, telecommunications providers, hospitals, financial institutions and defense contractors.
Leatherman described the action as the disruption of “a global botnet used by a Chinese state-sponsored group … to target U.S. critical infrastructure,” adding that QTFY had “exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems” for nearly a decade. The FBI said QTFY’s services were also sold to customers beyond the Chinese government, though it did not name additional clients.
The takedown is the latest in a series of U.S. actions targeting Chinese state-linked infrastructure-scanning and botnet operations, and underscores continuing concern among federal agencies about the use of compromised consumer and small-business IoT devices, including routers and security cameras, as staging infrastructure for espionage-linked intrusions into critical infrastructure networks.

Leave a Reply