The Justice Department and FBI have seized the domains behind QScan and QTRouter, two platforms run by China state-sponsored hackers whose victims include NASA, the Federal Reserve, and the US Senate.
Court documents identify the operators as a group called QTFY, employed by Nanjing Xinjiuwei Network Technology Company.
According to the documents, QTFY sold hacking services to paying clients. Those clients include China’s Ministry of State Security and the People’s Liberation Army. Both sit at the center of Beijing’s intelligence and military structure.
The press release listed several federal entities among the group’s victims. This includes NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the Senate.
Follow us on X to get the latest news as it happens
Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of @FBISanDiego ,… https://t.co/4JllIFik0f
— FBI Director Kash Patel (@FBIDirectorKash) August 26, 2026
QScan swept the internet for Internet of Things (IoT) devices and automatically infected thousands of them. Each compromised device then joined the QTRouter network.
QTRouter pooled those devices with commercial proxy services and leased virtual private servers. The result was an obfuscation network that made Chinese intrusions appear to start outside the country.
Investigators found the seized domains hard-coded into both tools for communication and authentication. Removing them left QScan and QTRouter inoperable.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” Attorney General Todd Blanche said.
The operation extends a run of US takedowns. The FBI removed PlugX malware from more than 4,000 American computers in 2025, disabled the Flax Typhoon botnet in 2024, and disrupted the Volt Typhoon infrastructure in 2023.
Meanwhile, the tempo of these intrusions keeps climbing. Chinese state-linked groups have doubled their attack volume since handing routine work to artificial intelligence (AI) models, Taiwanese threat intelligence firm TeamT5 reported this week.
The case sits with prosecutors in the Southern District of California. Whether indictments follow the seizures will show how far the department wants to push past infrastructure takedowns.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights