Skip to main content
Threat Intelligence

DOJ and FBI Seize QScan and QTRouter: China-State Hacking Platforms Targeting U.S. Critical Infrastructure

2026-08-27Updated 2026-08-284 min read

The U.S. Justice Department and FBI seized domains powering the QScan and QTRouter platforms operated by PRC-state group QTFY (Nanjing Xinjiuwei Network Technology Company), used since at least 2018 to target NASA, the Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate. DOJ later corrected its statement to clarify the agencies were targets, only some of which were compromised.

Core Technical Takeaways

  • >QTFY is a PRC state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company whose customers include the Ministry of State Security and the People's Liberation Army; members include former PLA personnel.
  • >QScan auto-infects IoT devices worldwide and feeds them into QTRouter, an obfuscation network that masks the PRC origin of intrusions by routing traffic through compromised devices local to the target.
  • >Seized domains were hard-coded into both malware families for communication and authentication, so the court-authorized seizures rendered QScan and QTRouter inoperable.
  • >DOJ issued a correction on August 28 clarifying that NASA, the Federal Reserve, the Senate, and others were "targets" of QTFY, not all confirmed victims; the FBI affidavit states the NASA attempt was unsuccessful because the agency had patched the targeted software.

The disruption announced August 26, 2026

The U.S. Justice Department and FBI announced court-authorized domain seizures to deny malicious cyber actors access to two complementary hacking platforms, QScan and QTRouter, used to target U.S. critical infrastructure. Court documents were unsealed in the Southern District of California. Per the DOJ press release, the platforms were created and operated by a PRC state-sponsored group known as QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).

Attribute Specification
Threat actor QTFY (PRC state-sponsored)
Front company Nanjing Xinjiuwei Network Technology Company (Nanjing, China)
Customers PRC Ministry of State Security, People's Liberation Army
Platforms seized QScan (IoT scanner/infectors) and QTRouter (obfuscation proxy network)
Activity window At least 2018 through 2026
Legal venue Southern District of California (unsealed affidavit)

How QScan and QTRouter work together

QTFY sells hacking services to paying customers, including the PRC's Ministry of State Security and the People's Liberation Army. QScan scans and auto-infects thousands of IoT devices worldwide, which are then added to the QTRouter network, comprised of compromised IoT devices, commercial proxy services, and leased VPS. QTRouter functions as an obfuscation network, concealing the PRC origin of intrusion activity by making malicious communications appear to originate from devices outside the PRC, sometimes local to the targeted networks. Because the seized domains were hard-coded into both malware families for communication and authentication, the seizures rendered both platforms inoperable.

Targets and the August 28 correction

The original August 26 statement listed NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate as victims. The affidavit also describes targeting of hospitals, telecommunications providers, power companies, financial institutions, and defense contractors, and alleges September 2024 intrusions at three DOE labs, NIH, and an HHS agency.

On August 28, 2026, the DOJ issued a correction. As Reuters reported, the revised statement said the Senate, the Federal Reserve, NASA, and others were "among the targets of QTFY," only some of which were successfully compromised. The FBI affidavit states the attempted breach of NASA was unsuccessful because the agency had patched the targeted software. The affidavit also describes targeting of the U.S. Senate that occurred in 2026.

Supporting guidance and prior PRC operations

The FBI and NSA published a cybersecurity advisory with indicators of compromise (IOCs) based on QTFY activity dating back to at least 2018. Lumen Technologies' Black Lotus Labs published QTFY's tactics, techniques, and procedures. The DOJ contextualized the takedown within prior operations against PRC-sponsored hacking: 2025, Mustang Panda PlugX removal from 4,000+ U.S. computers; 2024, Flax Typhoon IoT botnet disablement; 2023, Volt Typhoon botnet disruption.