DOJ and FBI Seize China-Linked QScan and QTRouter Hacking Platforms Penetrating Seven Federal Networks

Source: X | @FBI

EXECUTIVE SUMMARY

The Department of Justice (DOJ) and Federal Bureau of Investigation (FBI) on August 26 executed court-authorized seizures of domains underpinning QScan and QTRouter, two hacking platforms built and operated by a People's Republic of China (PRC)-linked group. The platforms were confirmed to have penetrated systems at NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

ANALYSIS

QScan functioned as an automated vulnerability scanner that continuously probed internet-connected devices for exploitable weaknesses, silently enrolling compromised machines into the QTRouter network. QTRouter then combined that infected device pool with commercial virtual private servers and proxy services, allowing operators to route malicious traffic through systems based outside China. The result was an attack infrastructure designed to make intrusions appear to originate from ordinary American or foreign residential devices, not Chinese networks.

Court documents identify the operator as QTFY, a group employed by Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that investigators say built and maintained both platforms on behalf of PRC state-sponsored intelligence objectives. The relationship between Nanjing Xinjiuwei and PRC intelligence services has not been characterized in detail in public DOJ filings, but the confirmed victim set, concentrated in US federal government and sensitive financial infrastructure, is consistent with state-directed collection rather than criminal profit-seeking.

The seven confirmed victim organizations span financial policy, legislative intelligence, and federal scientific and medical research. The Federal Reserve and US Senate represent the most sensitive targets because they hold pre-decisional financial data and classified legislative information, respectively. Penetration of Federal Reserve systems could give an adversary advance knowledge of interest rate decisions, monetary policy deliberations, or banking system vulnerability assessments before any of it is made public.

The DOJ and FBI seized domain names that were hard-coded into the QScan and QTRouter malware itself. Because the malware needed to reach those specific domains to authenticate, receive commands, and update its active proxy list, taking control of the domains through court order rendered both platforms inoperable. Infected devices remain compromised, but operators can no longer task them or receive data from them through these platforms.

The QTFY case is the third PRC cyber operation affecting US government or critical infrastructure networks disclosed in August 2026, following the Storm-1175 N-able software supply chain campaign and the Suisun City emergency dispatch cyberattack. All three show pre-positioned access that Chinese threat actors maintained against US networks, in some cases for years before detection. Each new disclosure adds detail to how PRC state-sponsored groups hide their operational activity behind legitimate network addresses.

SOURCES

Previous
Previous

Colorado Neurosurgeon Indicted on Five Counts of Attempted Murder of Federal Officers

Next
Next

Bomb Threat Evacuates 800 Workers at Georgia Power Plant Yates Facility