The U.S. Department of Justice (DOJ) and Federal Bureau of Investigation (FBI) seized two hacking platforms used by a China state-sponsored group to target U.S. critical infrastructure and other sensitive networks. The court-authorized seizures targeted QScan and QTRouter, platforms operated by QTFY, a China-based group employed by Nanjing Xinjiuwei Network Technology Company. Victims of QTFY activity included the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.
According to court documents, QTFY provided computer hacking services to paying customers, including China’s Ministry of State Security and People’s Liberation Army. QScan was designed to scan and automatically infect thousands of internet-connected IoT devices worldwide, adding compromised systems to the QTRouter network. QTRouter combined those devices with commercial proxy service devices and leased virtual private servers to create an obfuscation network that concealed the China-based origin of cyber intrusions by making malicious communications appear to originate from systems outside China and potentially within targeted networks.
The seized domains were hard-coded into the QScan and QTRouter malware and were required for functions including communication and authentication, allowing the court-authorized action to render both platforms inoperable. The DOJ said the disruption forms part of a series of technical operations against China-sponsored hacking activity, following earlier FBI actions involving PlugX malware and botnets linked to Flax Typhoon and Volt Typhoon.
The FBI and National Security Agency published a cybersecurity advisory providing indicators of compromise by QTFY based on their analysis of QTFY malicious cyber activity dating back to at least 2018. The FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division investigated this hacking activity and led this disruption effort.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Todd Blanche, Attorney General, said in a Wednesday media statement. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel. “These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking – and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”
“Today’s announcement demonstrates the Justice Department’s steadfast commitment to going on the offensive against cyber threats to national security,” according to John A. Eisenberg, assistant attorney general for national security. “These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.”
“We’re taking the fight to PRC-sponsored cybercriminals to protect the critical services Americans rely on every day,” said U.S. Attorney Adam Gordon for the Southern District of California.
“The FBI remains relentless in our efforts to counter nation state cyber actors, taking decisive action against those threatening the United States and our critical infrastructure,” said Special Agent in Charge Mark Remily of the FBI San Diego Field Office. “Through complex investigations, aggressive technical operations, and strong partnerships, FBI San Diego will continue to identify, disrupt, and impose costs on our cyber adversaries. We are committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”
The DOJ also identified that QTFY computer hacking services include QScan and QTRouter, which work in conjunction. QScan scans and automatically infects thousands of IoT devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers.
QTRouter then serves as an ‘obfuscation network,’ meaning it allows QTFY and other malicious cyber actors to conceal the PRC origin of their computer intrusion activities because the malicious communications appear to originate from computers, such as those compromised by QScan, that are outside of the PRC and may even be local to the targeted networks. Since the seized domains were hard-coded into the QScan and QTRouter malware and used for essential tasks, such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable.
The 18-page affidavit document identified that “Not only do QTFY actors use these products themselves, but they also sell access to QScan and QTRouter to others. These products work in conjunction. QTFY actors and their customers can use QScan to automatically scan and exploit thousands of vulnerable IoT devices worldwide, which QTFY actors can then add as botnet nodes in the QTRouter obfuscation network.”
It added that “QTFY actors and their customers use QTRouter to obfuscate their identities. For example, by routing their malicious internet traffic through IoT devices (compromised by QScan) local to their victims, these Chinese hackers can blend in with legitimate users and remain undetected when scanning and attacking critical infrastructure and other targets.”
The latest DOJ disruption is among a series of court-authorized technical operations against indiscriminate hacking activities by the PRC. In 2025, the FBI removed PlugX surveillance malware from over 4,000 U.S. computers after they had been infected by the PRC-sponsored hacker group Mustang Panda. In 2024, the FBI disabled a botnet consisting of hundreds of thousands of infected internet-of-things devices, which the PRC-sponsored hacking group Flax Typhoon was providing to customers in the Chinese government.
In 2023, the FBI disrupted a different botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal their exploitation of U.S. and foreign critical infrastructure.
In addition, Lumen Technologies’ threat intelligence group, Black Lotus Labs, published a description of QTFY’s tactics, techniques, and procedures.


