DOJ and FBI Seize Alleged China-Linked Hacking Platforms
The Justice Department and FBI said Wednesday, August 26, 2026, that they had seized domains supporting two China-linked hacking platforms that officials say were used to target U.S. critical infrastructure and other sensitive networks.
The court-authorized action made the platforms, known as QScan and QTRouter, inoperable, according to the Justice Department. The agency said the seized domains were hard-coded into the malware and were needed for communication and authentication.
The operation disrupted two named tools. It did not establish that the alleged operators, QTFY-related infrastructure or the broader threat had been eliminated.
How QScan and QTRouter worked
According to unsealed court documents and a joint cybersecurity advisory from the FBI, National Security Agency and Cyber National Mission Force, the platforms were designed to work together.
QScan automated large-scale scanning and exploitation activity. It was used to identify vulnerable internet-connected devices and probe websites, applications and networks. The advisory says QScan processed more than two million scanning and penetration-testing tasks on a single day in 2024.
QTRouter functioned as an obfuscation network. It used compromised routers and other internet-of-things devices, commercial proxy services and leased servers to relay traffic. That could make malicious activity appear to originate outside China, including from systems closer to a targeted organization.
The advisory says QTRouter could chain proxy nodes and mix malicious traffic with legitimate traffic, making the activity harder to identify and trace. Independent analysis from Lumen Technologies described the broader setup as a reusable “quartermaster” service that combined reconnaissance, relay infrastructure and tools for managing access.
What the government alleges about QTFY
Federal officials attribute QTFY to Nanjing Xinjiuwei Network Technology Company, a China-based firm established in 2018. The joint advisory says the company had business relationships with units of China’s Ministry of State Security and with private China-based cyber-enabling companies.
The advisory also says some QTFY actors included former People’s Liberation Army members and that the group participated in China-based freelance brokering networks that bought and sold exploits and access to victim networks.
Those descriptions are allegations drawn from government investigations, an official cybersecurity advisory and unsealed court records, not findings from a completed criminal trial. The Justice Department announced domain seizures, not arrests, indictments or prosecutions of the alleged operators.
Federal agencies and critical sectors were named in the account
The Justice Department identified NASA, the Federal Reserve, the Department of Energy, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate among organizations named in the government’s account of QTFY intrusion activity.
The joint advisory also describes activity involving cleared defense contractors, energy and telecommunications companies, financial institutions, universities and local governments. Its sample timeline runs from 2018 through June 2026.
The record includes unsuccessful scanning or access attempts as well as incidents in which officials say attackers exploited vulnerabilities or exfiltrated data. The list of named organizations does not mean every organization experienced the same type or severity of compromise.
Among the examples, the advisory says QTFY scanned the Department of Energy in May 2018 and a U.S. election system in July 2019, with unsuccessful attempts to gain access. It also describes exploitation attempts involving the Justice Department, Federal Reserve and NASA in August 2019.
In May 2024, officials say QScan was used against U.S. power and telecommunications companies and that data was exfiltrated from more than 300 organizations in the United States and elsewhere. The advisory lists U.S. defense contractors, financial institutions and universities among the victims in that activity.
More recently, the advisory says QTFY used QScan against a U.S. state government and targeted a U.S. water district in February 2026. In March, it scanned the U.S. Senate and a hospital system; in June, it scanned a U.S. election system. The Senate and election-system attempts were described as unsuccessful.
What organizations should do now
The federal advisory urges organizations to apply current software and firmware updates, protect operational information exposed through internet-facing applications and isolate critical systems from edge devices.
Security teams can also use the advisory’s indicators of compromise and infrastructure information to check networks and devices. The complete files are intended for defenders and should be accessed through official cybersecurity channels rather than reproduced in a way that could help attackers.
For consumers, the government announcement does not identify ordinary households as direct targets. But compromised home routers, cameras and other connected devices can be used as relay points in attacks, making updates, strong administrative passwords and replacement of unsupported equipment important safeguards.
What the seizure does and does not accomplish
The seizure is an immediate disruption to two named platforms because their hard-coded domains were needed for core functions. It is not proof that QTFY activity has ended or that replacement infrastructure cannot be built.
Commercial proxy networks and rotating compromised devices can make static blocking difficult. Lumen’s analysis said the infrastructure could automatically rotate commercial proxy paths and blend malicious traffic with legitimate consumer activity. That means defenders may need to focus not only on blocking known domains, but also on patching exposed systems, monitoring unusual access patterns and separating critical assets from internet-facing edge devices.
The next developments to watch include additional court filings, indictments or sanctions, new technical indicators, victim notifications and evidence that related operators have rebuilt infrastructure or resumed activity.
Sources
- Justice Department and FBI seizure announcement
- FBI, NSA and Cyber National Mission Force joint advisory
- The Record: QScan and QTRouter takedown
- Lumen Black Lotus Labs analysis
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.