Full Breakdown
FBI Disrupts China-Linked QTFY Hacking Platforms QScan and QTRouter
8/27/2026, 1:17:38 AM
Core Event
On August 26 2026 the U.S. Department of Justice and the FBI announced the seizure of three domains that powered the QScan and QTRouter hacking platforms. Prosecutors identified the platforms as tools of the Chinese state-sponsored group QTFY, operating through Nanjing Xinjiuwei Network Technology Company. The operation aimed to disable tools that enable large-scale scanning of vulnerable devices and the obfuscation of malicious traffic from compromised IoT devices, commercial proxies, and leased virtual private servers.
Background & Context
Since at least 2018, QTFY has offered “digital quartermaster” services—providing botnets of hacked IoT devices and access to proxy infrastructure—to customers that include China’s Ministry of State Security and the People’s Liberation Army. The tools were used to target U.S. federal agencies and critical-infrastructure operators.
Timeline
- 2018 onward – QTFY operates QScan and QTRouter, offering scanning and relay services.
- May 2024 – QTFY exploits a Check Point vulnerability, compromising more than 300 U.S. organizations.
- 2025 – FBI disrupts the PlugX botnet linked to Volt Typhoon.
- August 26 2026 – DOJ and FBI seize the domains, rendering the platforms inoperable.
Data & Statistics
- QScan contained code for over 200 distinct attacks and processed more than 2 million scanning or exploitation tasks on a single day in 2024.
- The botnet leveraged thousands of IoT devices worldwide, integrating them into the QTRouter relay network.
- Court documents list NASA, the Federal Reserve, the U.S. Senate, the Departments of Energy, Justice, Health and Human Services, the National Institutes of Health, and the DOJ among targeted agencies, as well as power companies, telecom providers, hospitals, banks, and defense contractors; the filing does not confirm successful breach of each.
Official Statements & Responses
- The DOJ described the seizure as part of an ongoing effort to dismantle foreign-sponsored hacking campaigns.
- FBI Director Kash Patel said QScan was used to locate weak spots while QTRouter concealed attack origins.
- Attorney General Todd Blanche asserted that state-sponsored malicious hackers “will be stopped and prosecuted.”
- Lumen Technologies’ Black Lotus Labs called Nanjing Xinjiuwei a “quartermaster” supplying ready-made services to Chinese cyber actors.
Verbatim Quotes
- “These tools were used by PRC cyber actors to hide the origin of their attacks,” — FBI Director Kash Patel
- “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted.” — General Todd Blanche, attorney
Why It Matters
The disruption shows how state-backed actors can outsource reconnaissance, exploitation, and traffic obfuscation to shared infrastructure. By commandeering everyday IoT devices and blending malicious traffic with legitimate activity, QTFY made attribution and IP-based blocking ineffective. Seizing the command-and-control domains represents a rare technical takedown that temporarily halts the specific tools, though the underlying business model may persist.
Conflicting Reports & Gaps
- An FBI affidavit notes a 2019 attempt against NASA failed because the agency had already patched the flaw, but other sources do not specify which agencies were successfully breached.
- DOJ documents list numerous high-profile targets but do not confirm the extent of data exfiltration or operational impact.
- No comment was obtained from Nanjing Xinjiuwei, leaving its current involvement unclear.
What’s Next
The DOJ indicated that the seized domains were essential for authentication and communication; their removal disables QScan and QTRouter until the operators rebuild the infrastructure. Federal authorities will continue monitoring for similar proxy-based services and pursue additional legal actions against entities that facilitate state-sponsored cyber operations.
