The FBI and DOJ seized three domains hard-coded into the QScan and QTRouter platforms, used by China state-sponsored group QTFY to target U.S. critical infrastructure.
What happened
The FBI and the U.S. Department of Justice seized three domains hard-coded into two complementary hacking platforms — QScan and QTRouter — rendering both inoperable. The court-authorized seizures were announced on August 26, 2026, with documents unsealed in the Southern District of California.
Who operated them
The platforms were created and operated by QTFY, a state-sponsored group employed by the China-based company Nanjing Xinjiuwei Network Technology. According to court documents, QTFY sold access to QScan and QTRouter to paying customers, including China's Ministry of State Security and the People's Liberation Army.
How the network worked
QScan scanned and automatically infected thousands of IoT devices worldwide. Compromised devices were then added to QTRouter — an obfuscation network that combined hacked IoT devices, commercial proxy services, and leased virtual private servers to conceal the Chinese origin of intrusions.
Targets
Among QTFY's targets were NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
Scope
The FBI and NSA published indicators of compromise based on QTFY activity dating back to at least 2018.
Source: U.S. Department of Justice press release and court documents unsealed in the Southern District of California.