US seizes domains of China-linked hacking platforms QScan and QTRouter

Share:
Audio Loading voice…
US seizes domains of China-linked hacking platforms QScan and QTRouter

Synopsis

The US Justice Department and FBI dismantled two China-linked hacking platforms — QScan and QTRouter — by seizing their core domains, rendering the tools inoperable. Attributed to a state-sponsored group employed by a Nanjing-based tech firm and allegedly serving China's Ministry of State Security and the PLA, the platforms had reportedly penetrated some of America's most sensitive institutions, from NASA to the US Senate.

Key Takeaways

The US Justice Department and FBI seized internet domains of QScan and QTRouter on 26 August , disabling both platforms.
The platforms are attributed to QTFY , a state-sponsored Chinese hacking group employed by Nanjing Xinjiuwei Network Technology Company .
Alleged clients included China's Ministry of State Security and the People's Liberation Army .
Targets reportedly included NASA , the Federal Reserve , the US Senate , the Energy Department , and the NIH .
The FBI and NSA issued a joint cybersecurity advisory to help organisations detect QTFY activity.
Attorney General Todd Blanche warned that further prosecutions are expected.

The US Justice Department and the Federal Bureau of Investigation (FBI) on Wednesday, 26 August seized internet domains underpinning two China-linked hacking platforms — QScan and QTRouter — that allegedly penetrated American critical infrastructure, including NASA, the Federal Reserve, and the US Senate. The court-authorised action rendered both platforms inoperable and marks one of the most sweeping US cyber operations against alleged Beijing-backed hackers in recent years.

What Was Seized and Why

Court documents unsealed in the Southern District of California attributed the two platforms to QTFY, which US authorities described as a state-sponsored Chinese hacking group. QTFY was reportedly employed by Nanjing Xinjiuwei Network Technology Company, a China-based technology firm. The seized domains were built into both malware platforms and were essential for communication, authentication, and operational control — taking them down made QScan and QTRouter non-functional, according to the Justice Department.

How the Platforms Operated

According to court documents, QScan automatically searched for and infected thousands of internet-connected devices globally. Those compromised devices were then absorbed into QTRouter, a hacker-controlled network that also leveraged commercial proxy services and leased virtual private servers. The architecture was designed to mask the Chinese origin of attacks — malicious communications appeared to originate from infected computers located outside China, in some cases near the very networks being targeted.

The Targets and the Alleged Clients

US authorities alleged that QTFY offered hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army (PLA). The identified targets spanned some of the most sensitive institutions in the United States: NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health (NIH), and the US Senate.

What US Officials Said

Attorney General Todd Blanche issued a direct warning: 'State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted.' He added, 'We are here to ensure security for the American people and will use every tool we have to keep that promise.' Blanche confirmed that federal investigators had also disabled the group's malicious software as part of a broader series of operations against hacking activity allegedly sponsored by Beijing.

FBI Director Kash Patel described the action as 'the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure,' adding that 'these tools were used by People's Republic of China (PRC) cyber actors to hide the origin of their attacks.'

Advisory and What Comes Next

The FBI and the National Security Agency (NSA) jointly issued a cybersecurity advisory containing technical indicators to help organisations worldwide detect possible QTFY activity. This operation is part of a continuing US effort to counter alleged state-sponsored Chinese cyber intrusions — a pattern that has intensified since the Volt Typhoon and Salt Typhoon campaigns drew congressional scrutiny earlier this decade. Further prosecutions are expected as investigators continue to analyse the seized infrastructure.

Point of View

But for what the court documents reveal: a Chinese tech company openly selling hacking services to the PLA and the Ministry of State Security, with NASA and the Federal Reserve on the target list. That is not opportunistic espionage — it is industrialised cyber warfare for hire. What mainstream coverage tends to underplay is the botnet architecture: by routing attacks through compromised devices near the target, QTFY made attribution nearly impossible in real time, which means the true scale of infiltration may still be unknown. The FBI-NSA advisory is a tacit admission that the damage assessment is ongoing. Whether US counter-measures deter future operations or simply prompt Beijing-linked actors to rebuild under new infrastructure remains the central unanswered question.
NationPress
27 Aug 2026

Frequently Asked Questions

What are QScan and QTRouter?
QScan and QTRouter are two complementary China-linked hacking platforms that US authorities say were used to infiltrate American critical infrastructure. QScan automatically infected internet-connected devices globally, which were then absorbed into QTRouter, a hacker-controlled network designed to conceal the Chinese origin of attacks.
Who is behind the QScan and QTRouter hacking platforms?
US court documents attribute the platforms to QTFY, described by American authorities as a state-sponsored Chinese hacking group. QTFY was allegedly employed by Nanjing Xinjiuwei Network Technology Company and reportedly offered hacking services to China's Ministry of State Security and the People's Liberation Army.
Which US institutions were targeted by the Chinese hackers?
According to US authorities, the targets included NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.
How did the US government disable these platforms?
The Justice Department obtained court authorisation to seize the internet domains that were built into both malware platforms and were required for communication and authentication. Taking control of those domains rendered QScan and QTRouter inoperable.
What should organisations do after this operation?
The FBI and the National Security Agency have jointly issued a cybersecurity advisory containing technical indicators to help organisations detect possible QTFY activity on their networks. Organisations, particularly those operating critical infrastructure, are advised to review the advisory and apply the recommended detection measures.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 2 months ago
  4. 2 months ago
  5. 3 months ago
  6. 4 months ago
  7. 6 months ago
  8. 1 year ago
Google Prefer NP
On Google