DOJ and FBI Seize Domains Tied to China-Linked Hacking Platforms QScan and QTRouter
The Justice Department and FBI said Wednesday they carried out court-authorized seizures of domain names tied to two hacking platforms, QScan and QTRouter, in an operation that U.S. authorities said shut down infrastructure used by China state-sponsored hackers to target U.S. critical infrastructure and other sensitive networks.
According to a Justice Department press release summarizing court documents unsealed in the U.S. District Court for the Southern District of California, QScan and QTRouter worked as a two-part system. DOJ said QScan was used to scan the internet and automatically infect thousands of internet-of-things devices worldwide. QTRouter, DOJ said, was built from compromised internet-connected devices, commercial proxy devices and leased virtual private servers, and functioned as an “obfuscation network” designed to make malicious traffic appear to come from outside China, sometimes even looking local to the targeted network. The seized domains were hard-coded into both platforms for essential communication and authentication, DOJ said, so taking control of them rendered the platforms inoperable.
The allegations in the court filings have not been proven in court. DOJ said the unsealed documents allege that a People’s Republic of China state-sponsored group identified as QTFY, employed by Nanjing Xinjiuwei Network Technology Company, created and operated both platforms. The court papers also allege that QTFY sold hacking services to paying customers including China’s Ministry of State Security and the People’s Liberation Army.
DOJ said the court papers identify a range of U.S. victims, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate. The department did not say Wednesday whether any of those entities remained compromised, and the announcement did not describe whether data was stolen.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Attorney General Todd Blanche said, according to the DOJ press release.
The disruption effort was led by the FBI’s San Diego Field Office, the FBI Cyber Division, the U.S. Attorney’s Office for the Southern District of California and DOJ’s National Security Division, the department said.
For readers outside cybersecurity, the government is describing a common but potent setup: one platform allegedly used to find and compromise large numbers of internet-connected devices, and another allegedly used to route hacking traffic through those devices so the true operator is harder to identify. By targeting the domains the systems relied on to function, investigators aimed to break the underlying machinery rather than just block one stream of malicious traffic at a time.
The move fits a now-familiar pattern in U.S. cyber enforcement. In 2024 and 2025, U.S. authorities used similar court-authorized disruption tactics against China-linked cyber infrastructure, including actions targeting the Volt Typhoon, or KV, botnet in early 2024, the Flax Typhoon botnet in September 2024 and PlugX malware in January 2025.
DOJ said that, alongside Wednesday’s seizures, the FBI and National Security Agency released a cybersecurity advisory with indicators of compromise tied to QTFY dating to at least 2018. DOJ also said Lumen Technologies’ Black Lotus Labs published separate analysis of the group’s tactics the same day.