Pull to refresh
Logo
US seizes China-linked hacking platforms QScan and QTRouter

US seizes China-linked hacking platforms QScan and QTRouter

Force in Play

FBI operation disables cyber intrusion tools used against US agencies since 2018

August 26th, 2026: QScan and QTRouter domains seized

Overview

Updated Aug 27

The US Justice Department and FBI seized three internet domains on August 26, disabling two hacking platforms that Chinese state-sponsored operators used against NASA, the Federal Reserve, the Justice Department, and the US Senate. The takedown shut down QScan and QTRouter, tools the group known as QTFY had run since at least 2018.

QScan automatically infected thousands of internet-connected devices worldwide. QTRouter routed malicious traffic through those devices so attacks appeared to originate from computers near the target, not from China. The seized domains were hard-coded into both platforms, so the operation made them inoperable.

Why it matters

Chinese state hackers used these platforms for eight years to reach US government agencies and critical infrastructure. They now need to rebuild.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

8
Years of QTFY intrusion activity
Campaign documented since at least 2018, targeting US agencies and critical infrastructure.
3
Domains seized
qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, hard-coded into both malware platforms.
7
Federal agencies identified as victims
NASA, Federal Reserve, Department of Energy, Justice, Health and Human Services, NIH, and the Senate.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

January 2018 August 2026

5 events Latest: August 26th, 2026 · 2 weeks ago
Tap a bar to jump to that date
  1. QTFY begins operations

    Origins

    QTFY starts operating QScan and QTRouter, targeting US networks and critical infrastructure.

Scenarios

1

QTFY rebuilds infrastructure within a year

Likely Resolves by Aug 26, 2027

Discussed by: Lumen Black Lotus Labs, cybersecurity analysts at SecurityScorecard

Black Lotus Labs warned that static blocking alone is unlikely to be effective because QTFY traffic passes through dynamically rotating commercial proxy services. The group could register new domains or shift to commercial infrastructure. Richard Hummel of SecurityScorecard noted that taking two platforms offline 'costs the operators real capability they were using every day,' but Chinese state groups have historically rebuilt after takedowns. The FBI and NSA published indicators of compromise to help defenders spot QTFY activity in the interim.

2

DOJ files charges against QTFY operators

Possible Resolves by Aug 26, 2027

Discussed by: US Justice Department, prior precedent from 2014 PLA Unit 61398 indictments

Attorney General Blanche said hackers 'will be stopped and prosecuted.' The unsealed affidavit in the Southern District of California identifies Nanjing Xinjiuwei and its employees, giving prosecutors a factual basis to bring charges. The DOJ charged Chinese state hackers before, in the 2014 PLA Unit 61398 case, and has continued to pursue individual accountability for state-sponsored cyber operations. Named individuals would face computer fraud and economic espionage charges.

3

China issues formal protest or denies allegations

Possible Resolves by End of 2026

Discussed by: Reuters, diplomatic reporting

Beijing has historically rejected US accusations of state-sponsored hacking. China's Ministry of Foreign Affairs could issue a formal denial or protest, or respond with countermeasures in cyberspace. The US seizure publicly names a Chinese company and links it to intelligence and military agencies, raising diplomatic stakes. Previous US takedowns of Chinese hacking infrastructure drew official Chinese statements denying state involvement.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

May 2014

PLA Unit 61398 indictments (2014)

The DOJ indicted five officers of China's People's Liberation Army Unit 61398, charging them with hacking US companies including Westinghouse Electric and US Steel. It was the first time the US charged state-sponsored Chinese hackers with crimes.

Then

China denied the allegations and rejected the charges. None of the five officers faced trial in US courts.

Now

Set a precedent for prosecuting state hackers and established the DOJ's pattern of pairing technical takedowns with criminal charges.

Why this matters now

Shows the DOJ has a track record of pursuing criminal accountability for Chinese state hackers, which could apply to QTFY members.

2023

Volt Typhoon botnet disruption (2023)

The FBI disrupted a botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal exploitation of US and foreign critical infrastructure, including water utilities and energy systems.

Then

Volt Typhoon's infrastructure was disrupted, forcing the group to find new ways to hide its operations.

Now

Demonstrated the FBI's technical takedown playbook against Chinese hacking groups, later applied to QTFY.

Why this matters now

Direct precedent for the QScan and QTRouter seizure, which used the same court-authorized technical disruption approach.

2024

Flax Typhoon botnet disablement (2024)

The FBI disabled a botnet of hundreds of thousands of compromised internet-of-things devices that the PRC-sponsored Flax Typhoon group provided to Chinese government customers for cyberattacks.

Then

The botnet was disabled, denying Flax Typhoon its obfuscation infrastructure overnight.

Now

Showed the scale of Chinese IoT-based proxy networks and the FBI's ability to dismantle them through domain seizures.

Why this matters now

Same attack pattern as QTFY: compromising IoT devices and routing attacks through them. The takedown method was nearly identical.

Sources

(10)