Key Takeaways

  • Court-authorized domain seizures rendered QScan and QTRouter inoperable because both platforms depended on hard-coded domains.
  • QTFY allegedly used compromised IoT devices, proxy services, and virtual private servers to conceal the origin of intrusions.
  • The disruption extends a broader U.S. campaign against PRC-linked infrastructure associated with QTFY, Volt Typhoon, Flax Typhoon, and Mustang Panda.

The Justice Department and FBI have disrupted two complementary hacking platforms that a People’s Republic of China state-sponsored group allegedly used to target government agencies, critical infrastructure operators, and other sensitive organizations.

According to the Justice Department, court-authorized seizures took control of domains supporting QScan and QTRouter. Court documents unsealed in the Southern District of California identify QTFY as the group that created and operated the platforms. QTFY is employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), the Justice Department said.

The affected platforms had a straightforward division of labor. QScan searched for vulnerable internet-of-things devices and automatically infected thousands of them worldwide. Those devices were then incorporated into QTRouter, an infrastructure layer that also included commercial proxy devices and leased virtual private servers.

QTRouter functioned as an obfuscation network. Traffic associated with an intrusion could appear to come from a compromised device outside the PRC, potentially even one located near the targeted environment. That arrangement made attribution and network-level blocking more difficult while allowing QTFY and its customers to obscure where operations originated.

An ordinary router, camera, or other connected device can become more than an entry point. Once compromised, it can serve as disposable infrastructure for a campaign aimed somewhere else entirely. To defenders, malicious traffic arriving from a local or otherwise familiar network may initially look less suspicious than a direct connection from overseas.

Taking control of these dependencies made both platforms inoperable, according to the Justice Department, because the domains were hard-coded into QScan and QTRouter and supported essential communication and authentication functions. That does not remove every infected device or eliminate QTFY’s technical knowledge, but it interrupts an operational system that would take time and resources to reconstruct.

QTFY allegedly provided paid hacking services to customers that included the PRC’s Ministry of State Security and the People’s Liberation Army. Its reported victims include the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate. ABC News also reported targeting involving hospitals, telecommunications providers, and power companies.

For business and technology leaders, the victim list reinforces that state-backed campaigns do not remain confined to classified government systems. Telecom networks, health systems, utilities, suppliers, and internet-facing devices can all become parts of the same operational chain. A compromised edge device may be used to reach its owner, relay activity against another organization, or help an attacker blend into routine traffic.

The operation also fits an established pattern. The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by Mustang Panda in 2025. Federal authorities disabled a botnet containing hundreds of thousands of infected IoT devices associated with Flax Typhoon in 2024. Another operation disrupted a botnet used by Volt Typhoon to conceal exploitation of U.S. and foreign critical infrastructure in 2023.

Those earlier cases matter because CISA and partner agencies have warned that PRC state-sponsored actors systematically exploit backbone routers, small-office and home-office equipment, and other edge devices. CISA’s February 2024 advisory AA24-038A described actors maintaining multi-year access in critical infrastructure environments through living-off-the-land techniques, which rely heavily on legitimate administrative tools and normal system functions.

Following this takedown, asset inventories need to include internet-facing appliances and unmanaged IoT equipment, not only laptops and servers. Organizations can also review unsupported devices, restrict unnecessary management access, monitor unusual outbound connections, and compare telemetry with the indicators of compromise released by the FBI and National Security Agency on August 26, 2026.

The seizure imposes an immediate operational cost on QTFY, yet the wider risk remains. Durable defense will depend on reducing the pool of vulnerable edge devices and detecting activity that deliberately resembles normal administration. For infrastructure operators, addressing these fundamental security vulnerabilities remains critical.