U.S. Seizes China-Linked Hacking Platforms Targeting Critical Infrastructure
The Justice Department and FBI said Wednesday, August 26, 2026, that they seized three domains used by a China-linked hacking group to run scanning and routing platforms that targeted U.S. critical infrastructure and other sensitive networks.
Federal officials said the court-authorized action made the platforms, known as QScan and QTRouter, inoperable because the seized domains were hard-coded into the systems for communication and authentication. The Justice Department updated its announcement on Friday, August 28.
What the seizure disrupted
U.S. authorities attribute the platforms to QTFY, which federal records associate with Nanjing Xinjiuwei Network Technology Company. The Justice Department and FBI say the company provided hacking services to paying customers that allegedly included users linked to China’s Ministry of State Security and People’s Liberation Army.
Those descriptions come from a federal affidavit and cybersecurity advisory. They are allegations and investigative assessments, not adjudicated findings.
According to the joint advisory issued by the FBI, National Security Agency and Cyber National Mission Force, QScan was used to scan for vulnerable internet-connected devices and victim networks and to support exploitation activity. QTRouter used compromised internet-of-things devices, commercial proxy devices and leased virtual private servers to obscure the origin and route of attack traffic.
The seizure disrupted the specific command, scanning and routing infrastructure tied to the three domains. It did not establish that every device previously compromised by QTFY had been removed from the group’s control, or that the broader China-linked threat had ended.
Agencies and sectors identified in federal records
Federal records name or describe targeting involving NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health and the U.S. Senate. The records also identify defense contractors, financial institutions, universities, telecommunications companies, hospitals, state and local governments, water systems and election-related networks.
The advisory separates vulnerability scanning, attempted access, successful exploitation and confirmed data theft. Some activity succeeded, including the exfiltration of data from more than 300 organizations in 2024. Other activity was unsuccessful, including scans or attempted intrusions involving the Senate, a hospital system and election-related networks, according to the federal assessment.
That distinction matters: being scanned or targeted does not by itself establish that an organization was breached.
A threat documented over years
The joint advisory traces QTFY-related activity to at least 2018. It lists exploitation of vulnerabilities affecting products including Pulse Secure, Citrix, Microsoft Exchange, Log4j, Atlassian Confluence, Check Point, Ivanti, CrushFTP and BeyondTrust.
The timeline includes unsuccessful scanning or access attempts involving U.S. government, health care, power, Senate and election-related networks, as well as successful exploitation and data theft affecting other organizations. Because the activity spans multiple years and product categories, organizations may need to examine older records rather than rely only on current alerts.
What security teams should do
The FBI has released QTFY indicators-of-compromise files for defensive review. Security teams should compare the official indicators against historical DNS, proxy, firewall and NetFlow records and preserve relevant logs if a match appears.
Organizations should confirm that internet-facing applications, routers, IoT devices, VPNs, remote-support tools and security appliances have current software and firmware. Federal guidance also recommends protecting operational information exposed through internet-facing services and isolating critical systems from edge devices wherever feasible.
If an organization finds relevant indicators, incident responders should determine whether the activity involved only scanning or progressed to access, persistence or data exfiltration. The advisory directs organizations to contact the FBI’s Internet Crime Complaint Center or a local FBI field office when reporting suspicious or criminal activity, while preserving available evidence and incident details.
What remains unresolved
The court-authorized seizure disabled the specific platforms tied to the three domains, but it does not resolve questions about historical compromises, remaining infected devices or replacement infrastructure. It also does not mean that every organization named in federal records was breached.
The advisory’s recommendations are aimed primarily at government agencies, critical-infrastructure operators and security teams. For most consumers, the practical significance is indirect: services that depend on affected organizations may face cyber risk, but the federal action does not identify a general consumer breach or require routine household action.
Next steps to watch include updated technical guidance, victim notifications, further domain seizures, criminal charges or additional findings about how QTFY customers used the infrastructure.
Sources
- U.S. Department of Justice seizure announcement, updated August 28, 2026
- FBI-NSA-Cyber National Mission Force joint QTFY cybersecurity advisory
- Reuters report on the U.S. seizure and named targets
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.