US seizes China-linked hacking platforms QScan and QTRouter
Force in PlayFBI operation disables cyber intrusion tools used against US agencies since 2018
Yesterday: QScan and QTRouter domains seizedNew here? Follow stories to track developments over time. Create a free account to get updates when stories you care about change.
Overview
Updated 37 minutes agoThe US Justice Department and FBI seized three internet domains on August 26, disabling two hacking platforms that Chinese state-sponsored operators used against NASA, the Federal Reserve, the Justice Department, and the US Senate. The takedown shut down QScan and QTRouter, tools the group known as QTFY had run since at least 2018.
QScan automatically infected thousands of internet-connected devices worldwide. QTRouter routed malicious traffic through those devices so attacks appeared to originate from computers near the target, not from China. The seized domains were hard-coded into both platforms, so the operation made them inoperable.
Why it matters
Chinese state hackers used these platforms for eight years to reach US government agencies and critical infrastructure. They now need to rebuild.
Questions about this story
Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.
No questions yet — be the first to ask.
Key Indicators
Voices
Curated perspectives — historical figures and your fellow readers.
Play
Exploring all sides of a story is often best achieved with Play.
WHO SAID WHAT?
Can you match the quotes to the right people?
- points for each correct match.
- time bonus when you answer in under seconds.
- streak bonus once you hit correct in a row.
— Who said this?
Tip: press 1– to answer.
points — sign up to put that on the leaderboard.
Higher or Lower
A number from this story, against one from elsewhere in the news — guess which is bigger, then keep the chain going. 5 rounds, 3 strikes; a miss costs a strike and resets your streak.
Keyboard: ↓/L lower · ↑/H higher
0 points — sign up to put that on the leaderboard.
Connections
Sixteen names from the news. Find the four hidden groups of four. Four mistakes max.
Sign up to keep a daily streak — a new puzzle lands every day.
Exit debate?
Your progress in this debate will be lost.
- 1 Two AI personas square off on this story.
- 2 You predict who'll win each round — correct picks earn XP.
- 3 One crossfire question is yours to fire. Pick it carefully.
Couldn't generate a topic
Select Your Champions
Choose one persona for each side of the debate
DEBATE TOPIC
Choose personas with different perspectives for a more dynamic debate.
Select debater for this side:
No debate personas available right now.
Select debater for this side:
No debate personas available right now.
Who's Got This Round?
Make your prediction before the referee scores
The referee scores both sides on
Round Results
Set the Crossfire
Pick the question both personas must answer in the final round
Debate Oracle! You called every round!
Sharp Instincts! You know your debaters!
The Coin Flip Strategist! Perfectly balanced!
The Contrarian! Bold predictions!
Inverse Genius! Try betting the opposite next time!
XP Breakdown
Prediction History
People Involved
Organizations Involved
China-based hacking group employed by Nanjing Xinjiuwei that offered services to China's Ministry of State Security and the People's Liberation Army.
China-based firm in Nanjing whose employees reportedly constitute the QTFY hacking group.
US federal law enforcement agency that announced and executed the QScan and QTRouter domain seizures.
US federal investigative agency that carried out the technical operation to disable QScan and QTRouter.
Threat research division of Lumen Technologies that analyzed QTFY's methods and warned about future resilience.
Timeline
January 2018 August 2026
-
QScan and QTRouter domains seized
Latest EnforcementDOJ and FBI seize three domains, making QScan and QTRouter inoperable and disrupting QTFY operations.
-
PlugX malware removed
EnforcementFBI removes PlugX surveillance malware from over 4,000 infected US computers.
-
Flax Typhoon botnet disabled
EnforcementFBI disables botnet of hundreds of thousands of IoT devices run by PRC-sponsored Flax Typhoon group.
-
FBI disrupts Volt Typhoon botnet
EnforcementFBI disrupts botnet used by PRC-sponsored Volt Typhoon to hide exploitation of critical infrastructure.
-
QTFY begins operations
OriginsQTFY starts operating QScan and QTRouter, targeting US networks and critical infrastructure.
Historical Context
3 moments from history that rhyme with this story — and how they unfolded.
PLA Unit 61398 indictments (2014)
The DOJ indicted five officers of China's People's Liberation Army Unit 61398, charging them with hacking US companies including Westinghouse Electric and US Steel. It was the first time the US charged state-sponsored Chinese hackers with crimes.
China denied the allegations and rejected the charges. None of the five officers faced trial in US courts.
Set a precedent for prosecuting state hackers and established the DOJ's pattern of pairing technical takedowns with criminal charges.
Shows the DOJ has a track record of pursuing criminal accountability for Chinese state hackers, which could apply to QTFY members.
Volt Typhoon botnet disruption (2023)
The FBI disrupted a botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal exploitation of US and foreign critical infrastructure, including water utilities and energy systems.
Volt Typhoon's infrastructure was disrupted, forcing the group to find new ways to hide its operations.
Demonstrated the FBI's technical takedown playbook against Chinese hacking groups, later applied to QTFY.
Direct precedent for the QScan and QTRouter seizure, which used the same court-authorized technical disruption approach.
Flax Typhoon botnet disablement (2024)
The FBI disabled a botnet of hundreds of thousands of compromised internet-of-things devices that the PRC-sponsored Flax Typhoon group provided to Chinese government customers for cyberattacks.
The botnet was disabled, denying Flax Typhoon its obfuscation infrastructure overnight.
Showed the scale of Chinese IoT-based proxy networks and the FBI's ability to dismantle them through domain seizures.
Same attack pattern as QTFY: compromising IoT devices and routing attacks through them. The takedown method was nearly identical.
