Signal DOJ, FBI Disable China-Linked QTFY Hacking Platforms Targeting U.S. Agencies
Summary
The U.S. Department of Justice and FBI announced on August 26, 2026 court-authorized seizures of domains tied to QScan and QTRouter, hacking platforms operated by China state-sponsored group QTFY, affiliated with Nanjing Xinjiuwei Network Technology Company. Victims of QTFY's intrusion activity reportedly include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. QScan automatically scans and infects internet-connected devices such as industrial systems and smart-home devices, feeding them into the QTRouter network. QTRouter functions as an obfuscation network that disguises the Chinese origin of malicious traffic, making it appear to originate from compromised devices outside China or even local to the target's own network. Because the seized domains were hard-coded into both pieces of malware for communication and authentication, the seizures rendered QScan and QTRouter inoperable. According to the supporting affidavit, QScan processed more than two million scanning and exploitation tasks in a single day in 2024.
Classification
Evidence 1
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure U.S. Department of Justice 2026-08-26 accessed 2026-08-29T13:47:38+00:00
Part of trends 2
Directly linked issues 0
No objects.
Relation types: supports
Public id: fm-33fa83b8ab41
