On August 26, federal authorities disrupted two interconnected hacking platforms, seizing the domains necessary for their communication and authentication functions. The Department of Justice announced that QScan and QTRouter targeted critical infrastructure and confidential networks managed by NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.
According to court documents, these platforms belong to QTFY—a state-sponsored Chinese hacking group operating for the company Nanjing Xinjiuwei Network Technology Company. An FBI affidavit justifying the domain seizures alleges that QTFY sold hacking services to clients, which included China's Ministry of State Security and the People's Liberation Army. Three seized domains were hard-coded into the platforms, allowing the operation to take both systems offline.
The seizure disrupted infrastructure that was claimed to help hackers identify vulnerable systems and mask their connections to target networks. Attorney General Todd Blanche stated:
"Federal law enforcement has investigated and neutralized malicious PRC software—this is the latest in a series of technical operations aimed at stopping the indiscriminate hacking activity sponsored by the People's Republic of China."
QScan Identified Targets, QTRouter Masked Attacks
These two platforms performed different functions within an integrated system for intelligence gathering, vulnerability exploitation, and traffic obfuscation. In a joint cybersecurity advisory prepared by the FBI, the National Security Agency, and the Cyber National Mission Force, it is indicated that QScan contained over 200 proof-of-concept exploits and processed over 2 million scanning and penetration testing tasks in a single day in 2024. During a campaign conducted in May 2024, data was stolen from more than 300 organizations worldwide.
QScan automatically compromised vulnerable internet-connected devices and added them to QTRouter, which combined the hacked devices with commercial proxy services and rented virtual private servers. Black Lotus Labs analyzed QTFY's infrastructure and characterized the group as an infrastructure provider supporting Chinese cyber operations. Routing traffic through devices located near victims created the appearance that malicious messages originated from legitimate local users.
FBI Director Kash Patel stated:
"Today, we announced the takedown of a global botnet and hacking platform used by Chinese state-sponsored hackers to attack US critical infrastructure. These tools were used by PRC cybercriminals to conceal the source of their attacks."
Compromised routers and other Internet of Things devices were also used to carry out financially motivated cybercrimes unrelated to state-sponsored operations. Previously, authorities dismantled a proxy network that included 369,000 hacked devices in 163 countries. This network allowed criminals to mask activities related to cryptocurrency account hijacking, bank fraud, ransomware use, and other schemes, earning its operators over $5.7 million.
Operation Expands Campaign to Disrupt Infrastructure
The latest seizures follow several court-authorized operations targeting state-sponsored Chinese cyber infrastructure. In January 2025, the FBI reported removing the PlugX spyware from approximately 4,258 US systems infected by the Mustang Panda group. Federal authorities also disrupted the "Flax Typhoon" botnet in 2024 and thwarted the "Volt Typhoon" botnet in 2023.
The federal approach to foreign cyber threats also extends beyond traditional court-authorized seizures and malware removal operations. A Presidential Memorandum from August 12 mandated the creation of a federally overseen cyber threat disruption program, allowing vetted US companies to propose missions against foreign criminal networks, with officials given 60 days to establish criteria, target vetting procedures, and safety measures.
Federal investigators are increasingly blocking the accounts, servers, domains, and network connections that enable foreign cyber operations. In a separate initiative conducted in May, technology companies joined a Department of Justice operation that blocked over 1.4 million accounts linked to fraud. Participants also blocked malicious internet traffic, decommissioned hosting infrastructure, and helped freeze over $3.8 million in cryptocurrency.
Individual users face different risks than sophisticated criminal groups targeting government agencies and critical infrastructure, although both may use malware and compromised devices. Common protective measures include updating software, avoiding suspicious downloads, and verifying websites before entering sensitive information. Phishing and fake websites can install malware or reveal passwords, while outdated routers can provide attackers with infrastructure to conceal intrusions.





