FBI and DOJ seize China-linked QScan and QTRouter hacking platforms used against NASA, the Federal Reserve, and the U.S. Senate
The Justice Department and FBI seized domains behind two Chinese state-linked hacking platforms, QScan and QTRouter, tied to breaches of NASA, the Federal Reserve, and other U.S. agencies. Per justice.gov.
The U.S. Justice Department and FBI announced court-authorized seizures of domains used by 'QScan' and 'QTRouter', two hacking platforms operated by a Nanjing-based, PRC state-sponsored group called QTFY (Nanjing Xinjiuwei Network Technology Company). According to DOJ, QTFY's paying clients included China's Ministry of State Security and the People's Liberation Army, and confirmed victims of QTFY intrusion activity included NASA, the Federal Reserve, the Department of Energy, DOJ, HHS, NIH, and the U.S. Senate. QScan scanned and infected IoT devices worldwide; QTRouter used those devices plus proxy services and leased VPS as an obfuscation network. The FBI and NSA also published a joint cybersecurity advisory the same day, based on QTFY activity tracked since at least 2018. This is the fourth major disruption of a Chinese state-linked hacking network since 2023, following Volt Typhoon (2023), Flax Typhoon (2024), and the PlugX malware removal from 4,000+ U.S. computers (2025). Visuals and voiceover are AI-generated. Source: justice.gov (DOJ Press Release 26-972), SecurityAffairs.