Pull to refresh
Logo
US seizes China-linked hacking platforms QScan and QTRouter

US seizes China-linked hacking platforms QScan and QTRouter

Force in Play

FBI operation disables cyber intrusion tools used against US agencies since 2018

Yesterday: QScan and QTRouter domains seized

Overview

Updated 37 minutes ago

The US Justice Department and FBI seized three internet domains on August 26, disabling two hacking platforms that Chinese state-sponsored operators used against NASA, the Federal Reserve, the Justice Department, and the US Senate. The takedown shut down QScan and QTRouter, tools the group known as QTFY had run since at least 2018.

QScan automatically infected thousands of internet-connected devices worldwide. QTRouter routed malicious traffic through those devices so attacks appeared to originate from computers near the target, not from China. The seized domains were hard-coded into both platforms, so the operation made them inoperable.

Why it matters

Chinese state hackers used these platforms for eight years to reach US government agencies and critical infrastructure. They now need to rebuild.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

8
Years of QTFY intrusion activity
Campaign documented since at least 2018, targeting US agencies and critical infrastructure.
3
Domains seized
qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, hard-coded into both malware platforms.
7
Federal agencies identified as victims
NASA, Federal Reserve, Department of Energy, Justice, Health and Human Services, NIH, and the Senate.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 3 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

January 2018 August 2026

5 events Latest: Yesterday
Tap a bar to jump to that date
  1. QTFY begins operations

    Origins

    QTFY starts operating QScan and QTRouter, targeting US networks and critical infrastructure.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

May 2014

PLA Unit 61398 indictments (2014)

The DOJ indicted five officers of China's People's Liberation Army Unit 61398, charging them with hacking US companies including Westinghouse Electric and US Steel. It was the first time the US charged state-sponsored Chinese hackers with crimes.

Then

China denied the allegations and rejected the charges. None of the five officers faced trial in US courts.

Now

Set a precedent for prosecuting state hackers and established the DOJ's pattern of pairing technical takedowns with criminal charges.

Why this matters now

Shows the DOJ has a track record of pursuing criminal accountability for Chinese state hackers, which could apply to QTFY members.

2023

Volt Typhoon botnet disruption (2023)

The FBI disrupted a botnet used by the PRC-sponsored hacking group Volt Typhoon to conceal exploitation of US and foreign critical infrastructure, including water utilities and energy systems.

Then

Volt Typhoon's infrastructure was disrupted, forcing the group to find new ways to hide its operations.

Now

Demonstrated the FBI's technical takedown playbook against Chinese hacking groups, later applied to QTFY.

Why this matters now

Direct precedent for the QScan and QTRouter seizure, which used the same court-authorized technical disruption approach.

2024

Flax Typhoon botnet disablement (2024)

The FBI disabled a botnet of hundreds of thousands of compromised internet-of-things devices that the PRC-sponsored Flax Typhoon group provided to Chinese government customers for cyberattacks.

Then

The botnet was disabled, denying Flax Typhoon its obfuscation infrastructure overnight.

Now

Showed the scale of Chinese IoT-based proxy networks and the FBI's ability to dismantle them through domain seizures.

Why this matters now

Same attack pattern as QTFY: compromising IoT devices and routing attacks through them. The takedown method was nearly identical.

Sources

(10)