U.S. authorities seized the infrastructure behind two hacking platforms after investigators linked them to a Chinese state-sponsored group and customers including the MSS and PLA
- The FBI seizes core domains powering QScan and QTRouter, dismantling a Chinese state-sponsored hacking network active since 2018.
- Court filings show QScan ran over 2 million daily scanning operations in 2024, compromising credentials across 300 American organizations.
- The operation exposes how Chinese intelligence agencies like MSS contract private commercial vendors to execute wide-scale cyber reconnaissance.
Chinese hackers used hijacked routers, cameras and other internet-connected devices to conceal attacks against NASA, the Federal Reserve and the U.S. Senate as part of an operation dating back to at least 2018, U.S. authorities said. The Justice Department and FBI seized domains used by two platforms at the center of the operation, saying the action made them inoperable.
The platforms, QScan and QTRouter, were allegedly operated by QTFY, a Chinese state-sponsored group employed by Nanjing Xinjiuwei Network Technology Company. Court documents identify the Department of Justice, Department of Energy, Department of Health and Human Services and National Institutes of Health among the other government targets.
Hospitals, telecommunications companies, financial institutions, power companies and defense contractors were also allegedly targeted. The operation extended beyond the United States, with four unnamed companies in the U.S. and South Korea also identified in the government filings.
Hijacked Devices Became A Cloak
QScan allegedly scanned the internet for vulnerable devices and automatically infected thousands of them. Those devices were then added to the QTRouter network, which also included commercial proxy services and leased virtual private servers.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseQTRouter functioned as an obfuscation network, allowing malicious traffic to appear as though it came from computers outside China. In some cases, the traffic could appear to originate from devices near the network being targeted, making the underlying source harder to identify.
The scale of the operation was substantial. An FBI affidavit said QScan processed more than 2 million scanning and exploitation tasks in a single day in 2024 and contained more than 200 exploit modules.
MSS And PLA Were Alleged Customers
The Justice Department said QTFY offered hacking services to paying customers including China’s Ministry of State Security and the People’s Liberation Army. Prosecutors allege that the services gave customers access to infrastructure for scanning networks, compromising vulnerable devices and concealing the origin of their operations.
The arrangement points to a model in which state-backed hackers could use an existing infrastructure rather than build their own scanning and concealment systems for each operation. Lumen Technologies’ Black Lotus Labs separately described QTFY as an infrastructure “quartermaster” supporting China-linked cyber operations.
More Than 300 U.S. Organizations Hit
An FBI affidavit alleges that QTFY exploited a newly disclosed Check Point vulnerability in 2024 and obtained settings and credentials from more than 300 U.S. organizations. The government also identified three Department of Energy national laboratories among the alleged targets.
The listed targets span government, energy, healthcare, telecommunications, finance and other critical sectors. The breadth of the targets suggests the platforms were used across multiple types of networks rather than for a single narrowly defined campaign.
What Was Actually Taken?
The U.S. government has identified the organizations it says were targeted but has not published a comprehensive assessment of the damage. It has not disclosed what information was taken from NASA, the Federal Reserve or the Senate, how long attackers maintained access to individual systems or whether every affected network has been fully remediated.
The allegations establish intrusion activity, but they do not establish that sensitive information was stolen from every organization named in the filings. The seizure of the platforms also does not by itself establish that every foothold created through them has been removed.
The FBI and National Security Agency released indicators of compromise covering QTFY activity dating back to at least 2018. FBI Director Kash Patel said the operation disrupted a global botnet and hacking platform used by Chinese state-sponsored hackers to conceal the origin of their attacks.
FBI Took Down The Infrastructure
The seized domains were hard-coded into QScan and QTRouter and were required for functions including communication and authentication, according to the Justice Department. Taking control of those domains therefore rendered the two platforms inoperable, officials said.
The operation follows earlier U.S. efforts to disrupt China-linked botnets and malware infrastructure. The FBI removed PlugX surveillance malware from more than 4,000 U.S. computers in 2025, disabled a large IoT botnet linked to Flax Typhoon in 2024 and disrupted infrastructure used by Volt Typhoon in 2023.
China’s embassy in Washington did not provide any comment on the issue, while Beijing has repeatedly denied allegations that it sponsors cyberattacks against foreign governments and organizations.
The latest seizure disrupts the platforms identified by U.S. investigators, but it does not provide a public accounting of the full impact on the organizations allegedly targeted. The government has yet to disclose how much access the hackers obtained or what data, if any, was ultimately removed from the named networks.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





