The Justice Department and FBI seized the domains behind two hacking platforms built by a Chinese state-sponsored group, disrupting infrastructure that had been used to target U.S. government agencies and critical infrastructure for years, officials announced August 26.
What Was Seized
The tools, known as QScan and QTRouter, were developed by a group tracked as QTFY, which court documents tie to a Nanjing-based company. QScan scans and automatically infects internet-connected devices worldwide, feeding them into the QTRouter network, a mix of compromised consumer devices, commercial proxy services, and leased virtual private servers. QTFY routed its hacking traffic through machines outside China, including some planted near the networks it was targeting, to disguise where the activity was actually coming from.
Who Was Targeted
Confirmed victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, with some of the intrusions dating back to at least 2018.
Official Response
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” FBI Director Kash Patel said in a statement announcing the operation.
What Comes Next
Seizing the domains disrupts QTFY’s existing infrastructure, but officials have not said whether any individuals tied to the group have been charged, and state-sponsored hacking groups have historically rebuilt similar infrastructure after previous takedowns. The government has not detailed what specific data, if any, was confirmed stolen from the named agencies.







