US seizes domains of China-linked hacking platforms QScan and QTRouter
Synopsis
Key Takeaways
The US Justice Department and the Federal Bureau of Investigation (FBI) on Wednesday, 26 August seized internet domains underpinning two China-linked hacking platforms — QScan and QTRouter — that allegedly penetrated American critical infrastructure, including NASA, the Federal Reserve, and the US Senate. The court-authorised action rendered both platforms inoperable and marks one of the most sweeping US cyber operations against alleged Beijing-backed hackers in recent years.
What Was Seized and Why
Court documents unsealed in the Southern District of California attributed the two platforms to QTFY, which US authorities described as a state-sponsored Chinese hacking group. QTFY was reportedly employed by Nanjing Xinjiuwei Network Technology Company, a China-based technology firm. The seized domains were built into both malware platforms and were essential for communication, authentication, and operational control — taking them down made QScan and QTRouter non-functional, according to the Justice Department.
How the Platforms Operated
According to court documents, QScan automatically searched for and infected thousands of internet-connected devices globally. Those compromised devices were then absorbed into QTRouter, a hacker-controlled network that also leveraged commercial proxy services and leased virtual private servers. The architecture was designed to mask the Chinese origin of attacks — malicious communications appeared to originate from infected computers located outside China, in some cases near the very networks being targeted.
The Targets and the Alleged Clients
US authorities alleged that QTFY offered hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army (PLA). The identified targets spanned some of the most sensitive institutions in the United States: NASA, the Federal Reserve, the Energy Department, the Justice Department, the Department of Health and Human Services, the National Institutes of Health (NIH), and the US Senate.
What US Officials Said
Attorney General Todd Blanche issued a direct warning: 'State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted.' He added, 'We are here to ensure security for the American people and will use every tool we have to keep that promise.' Blanche confirmed that federal investigators had also disabled the group's malicious software as part of a broader series of operations against hacking activity allegedly sponsored by Beijing.
FBI Director Kash Patel described the action as 'the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure,' adding that 'these tools were used by People's Republic of China (PRC) cyber actors to hide the origin of their attacks.'
Advisory and What Comes Next
The FBI and the National Security Agency (NSA) jointly issued a cybersecurity advisory containing technical indicators to help organisations worldwide detect possible QTFY activity. This operation is part of a continuing US effort to counter alleged state-sponsored Chinese cyber intrusions — a pattern that has intensified since the Volt Typhoon and Salt Typhoon campaigns drew congressional scrutiny earlier this decade. Further prosecutions are expected as investigators continue to analyse the seized infrastructure.