Drooid Logo
Back to story perspectives

Full Breakdown

U.S. Disrupts Chinese State-Sponsored Hacking Platforms QScan and QTRouter

8/26/2026, 9:04:30 PM

Operation Overview

On August 26, the United States announced that it had seized the domain names used by two cyber-espionage platforms, “QScan” and “QTRouter.” The platforms were operated by a China-based firm, Nanjing Xinjiuwei Network Technology Company, and were employed by the state-sponsored group identified as “QTFY.” According to a Justice Department affidavit, the infrastructure supported intrusions into multiple U.S. government networks, including the Department of Justice, NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and four unnamed companies in the United States and South Korea. The campaign has been active since at least 2018.

Background & Context

Cyber-security analysts note that private contractors in China frequently provide offensive services to government agencies. The Ministry of State Security and the People’s Liberation Army are listed as clients of Nanjing Xinjiuwei. Over the past decade, the number of firms offering niche offensive capabilities has grown sharply, creating a market for “hacker-for-hire” operations that can be directed at foreign targets.

Data & Statistics

  • Platforms seized: QScan (used to scan and automatically infect vulnerable IoT devices) and QTRouter (an “obfuscation network” comprising compromised IoT devices, commercial proxy services, and leased virtual private servers).
  • Victim count: at least eight U.S. agencies and companies, plus additional targets in South Korea, as identified in the affidavit.
  • Operational timeline: 2018 – 2026, the period during which the infrastructure was used for “critical-infrastructure and other sensitive network” compromises.

Official Statements & Responses

The FBI highlighted that the compromised domains were hard-coded into both QScan and QTRouter malware, enabling follow-up attacks against U.S. agencies. Attorney General Todd Blanche emphasized that federal law-enforcement had “disabled the PRC’s malicious software” and pledged continued use of all tools to protect American critical infrastructure.

Verbatim Quotes

  • “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” — Attorney General Todd Blanche, said attorney
  • “These tools were used by PRC cyber actors to hide the origin of their attacks,” — FBI Director Kash Patel, said FBI director

Impact and Next Steps

Disrupting QScan and QTRouter removes a key layer of anonymity for the QTFY group, limiting its ability to conduct large-scale IoT-based intrusions. The operation follows earlier U.S. actions, such as the 2025 removal of the PlugX surveillance malware linked to the Mustang Panda group. Officials indicated that continued monitoring of Chinese-origin cyber-infrastructure will be a priority, though no specific future operations were announced.