U.S. Authorities Disrupt Chinese State-Sponsored Hacking Platforms QScan and QTRouter
The U.S. Justice Department and FBI have seized domains linked to two China-based hacking platforms, QScan and QTRouter, in a court-authorized operation targeting cyber threats to critical infrastructure and government networks. The platforms were operated by QTFY, a state-sponsored group affiliated with Nanjing Xinjiuwei Network Technology Company, which allegedly provides offensive cyber services to China’s Ministry of State Security and People’s Liberation Army.
QTFY’s activities compromised high-profile U.S. targets, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The group employed an infrastructure-as-a-service model, using QScan to scan and exploit vulnerable IoT devices at scale. Compromised devices were then enrolled in QTRouter, a network of hijacked IoT hardware, proxy services, and virtual private servers that masked malicious traffic by routing it through seemingly legitimate systems outside China.
This proxy-based architecture complicated attribution, as security teams often traced attacks to local IP addresses or consumer devices rather than the actual threat actors. The seized domains were hard-coded into the malware, and their takedown rendered the platforms inoperable, disrupting QTFY’s ability to control infected devices.
The operation follows previous U.S. efforts to dismantle China-linked cyber threats, including the 2025 removal of PlugX malware from U.S. systems, the 2024 disruption of the Flax Typhoon IoT botnet, and the 2023 takedown of Volt Typhoon infrastructure. The FBI and NSA also released a cybersecurity advisory detailing QTFY’s indicators of compromise, with activity dating back to at least 2018.
The seizure demonstrates how targeting domain-based infrastructure can disrupt state-backed cyber operations, even when attackers leverage distributed, compromised devices.
Source: https://gbhackers.com/fbi-seizes-china-state-sponsored-hacker-platforms/
Nokia Federal Solutions Inc cybersecurity rating report: https://www.rankiteo.com/company/nokiafederal
"id": "NOK1787826928",
"linkid": "nokiafederal",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': 'Aerospace/Defense',
'location': 'United States',
'name': 'NASA',
'type': 'Government Agency'},
{'industry': 'Finance',
'location': 'United States',
'name': 'Federal Reserve',
'type': 'Government Agency'},
{'industry': 'Energy',
'location': 'United States',
'name': 'Department of Energy',
'type': 'Government Agency'},
{'industry': 'Law Enforcement',
'location': 'United States',
'name': 'Department of Justice',
'type': 'Government Agency'},
{'industry': 'Healthcare',
'location': 'United States',
'name': 'Department of Health and Human Services',
'type': 'Government Agency'},
{'industry': 'Healthcare/Research',
'location': 'United States',
'name': 'National Institutes of Health',
'type': 'Government Agency'},
{'industry': 'Government',
'location': 'United States',
'name': 'U.S. Senate',
'type': 'Government Agency'}],
'attack_vector': ['IoT Device Exploitation', 'Proxy-Based Infrastructure'],
'description': 'The U.S. Justice Department and FBI have seized domains '
'linked to two China-based hacking platforms, QScan and '
'QTRouter, in a court-authorized operation targeting cyber '
'threats to critical infrastructure and government networks. '
'The platforms were operated by QTFY, a state-sponsored group '
'affiliated with Nanjing Xinjiuwei Network Technology Company, '
'which allegedly provides offensive cyber services to China’s '
'Ministry of State Security and People’s Liberation Army. '
'QTFY’s activities compromised high-profile U.S. targets, '
'including NASA, the Federal Reserve, the Department of '
'Energy, the Department of Justice, the Department of Health '
'and Human Services, the National Institutes of Health, and '
'the U.S. Senate. The group employed an '
'infrastructure-as-a-service model, using QScan to scan and '
'exploit vulnerable IoT devices at scale. Compromised devices '
'were then enrolled in QTRouter, a network of hijacked IoT '
'hardware, proxy services, and virtual private servers that '
'masked malicious traffic by routing it through seemingly '
'legitimate systems outside China.',
'impact': {'operational_impact': 'Disruption of state-sponsored hacking '
'infrastructure',
'systems_affected': ['NASA',
'Federal Reserve',
'Department of Energy',
'Department of Justice',
'Department of Health and Human Services',
'National Institutes of Health',
'U.S. Senate']},
'initial_access_broker': {'entry_point': 'Vulnerable IoT devices',
'high_value_targets': ['NASA',
'Federal Reserve',
'Department of Energy',
'Department of Justice',
'Department of Health and '
'Human Services',
'National Institutes of '
'Health',
'U.S. Senate']},
'investigation_status': 'Disrupted (domains seized)',
'lessons_learned': 'Targeting domain-based infrastructure can disrupt '
'state-backed cyber operations, even when attackers '
'leverage distributed, compromised devices.',
'motivation': ['Cyber Espionage', 'Critical Infrastructure Targeting'],
'post_incident_analysis': {'corrective_actions': 'Domain seizure and public '
'disclosure of indicators of '
'compromise',
'root_causes': 'State-sponsored cyber espionage '
'leveraging IoT device '
'vulnerabilities and proxy-based '
'infrastructure'},
'references': [{'source': 'U.S. Justice Department and FBI'},
{'source': 'FBI and NSA Cybersecurity Advisory'}],
'response': {'communication_strategy': 'Public disclosure of operation and '
'cybersecurity advisory',
'containment_measures': 'Domain seizure rendering platforms '
'inoperable',
'law_enforcement_notified': 'Yes (FBI, U.S. Justice Department)'},
'stakeholder_advisories': 'FBI and NSA released cybersecurity advisory '
'detailing QTFY’s indicators of compromise.',
'threat_actor': 'QTFY (affiliated with Nanjing Xinjiuwei Network Technology '
'Company)',
'title': 'U.S. Authorities Disrupt Chinese State-Sponsored Hacking Platforms '
'QScan and QTRouter',
'type': 'State-Sponsored Cyber Espionage',
'vulnerability_exploited': 'Vulnerable IoT devices'}