DOJ, FBI seize QScan and QTRouter used in PRC hacking

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp

The Justice Department and FBI announced court-authorized domain seizures targeting QScan and QTRouter, two complementary platforms allegedly used by state-sponsored hackers to attack U.S. critical infrastructure and other sensitive networks. According to court documents unsealed in the Southern District of California, a People’s Republic of China state-sponsored group known as QTFY, linked to Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter. Cited targets include the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.

Attorney General Todd Blanche said federal authorities will pursue and prosecute state-sponsored malicious hackers, adding that investigators disabled PRC-linked malware as part of an ongoing effort to counter broad hacking campaigns attributed to the People’s Republic of China.

FBI Director Kash Patel said the action disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure. Patel credited FBI San Diego, the FBI Cyber Division, and Justice Department partners with seizing adversary infrastructure and shutting the platforms down, characterizing the move as part of a broader push to defend the homeland in cyberspace.

Assistant Attorney General for National Security John A. Eisenberg said the seizures reflect the department’s commitment to counter cyber threats to national security, noting that the action denies PRC-linked hackers access to tools used in online attacks against critical infrastructure.

U.S. Attorney Adam Gordon for the Southern District of California said authorities are acting to protect essential services Americans rely on daily. Special Agent in Charge Mark Remily of the FBI San Diego Field Office said the bureau will continue complex investigations and technical operations with partners to identify, disrupt, and impose costs on cyber adversaries.

How QScan and QTRouter operated

Court filings state that QTFY offered hacking services to paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army. QScan and QTRouter functioned together. QScan scanned and automatically infected thousands of internet-of-things devices worldwide, which were then added to the QTRouter network. QTRouter comprised those compromised devices, commercial proxy services, and leased virtual private servers. The network acted as an obfuscation layer that concealed the PRC origin of intrusion activity by making malicious traffic appear to come from systems outside China, sometimes near targeted networks.

Investigators said the seized domains were hard-coded into both malware strains and used for essential communication and authentication. The court-authorized seizures rendered QScan and QTRouter inoperable.

Recent related disruptions and U.S. critical infrastructure

Officials said the takedown is part of a series of court-authorized technical operations against PRC-linked hacking. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers after infections attributed to the group Mustang Panda. In 2024, the FBI disabled a botnet of hundreds of thousands of infected internet-of-things devices associated with Flax Typhoon and allegedly provided to Chinese government customers. In 2023, the FBI disrupted a different botnet used by Volt Typhoon to mask exploitation of U.S. and foreign critical infrastructure.

Authorities added that the FBI and National Security Agency also released a cybersecurity advisory with indicators of compromise tied to QTFY, based on activity dating back to at least 2018. Separately, Lumen Technologies’ Black Lotus Labs published a report detailing QTFY’s tactics, techniques, and procedures.

The investigation and disruption were led by the FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division.

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp