DOJ and FBI dismantle QScan and QTRouter hacking platforms allegedly used by Chinese state-linked QTFY against U.S. agencies

The U.S. says it disabled two Chinese hacking platforms used to break into federal agencies and other sensitive networks, including the Federal Reserve, DOJ, the U.S. Senate, NASA, and healthcare and critical-infrastructure victims. According to a DOJ affidavit, QScan was used to scan for and infect internet-connected devices such as routers and cameras, while QTRouter acted as an obfuscation network to relay attacks and hide their origin. The infrastructure was allegedly operated by Nanjing Xinjiuwei Network Technology Company for users tied to China’s Ministry of State Security, the People’s Liberation Army, and other customers, with FBI tracking activity back to 2018 and linking one 2019 NASA attack to a Pulse Secure VPN exploit.
Why it matters: This matters because the same infrastructure was used to hide real-world intrusions into government, healthcare, telecom, energy, and defense networks for years. Defenders should review past traffic and compromises involving QScan/QTRouter-linked infrastructure, especially around edge devices and older VPN intrusion activity, and treat this as a concrete indicator of China-linked operational tradecraft.

Sources

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
Eduard Kovacs 2026.08.27 98% relevant
This article is a direct report on the same DOJ/FBI disruption of QTFY's QScan scanning-and-exploitation platform and QTRouter obfuscation botnet, adding details on victim sectors, examples of targeted and successfully hit organizations, the role of Nanjing Xinjiuwei Network Technology, and the list of vendors whose flaws QTFY exploited.
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
2026.08.27 99% relevant
This article is a direct report on the same FBI/DOJ action, adding specific victim names including NASA, the Department of Energy, the U.S. Senate, the Federal Reserve, DOJ, HHS, and NIH, plus detail that QTFY used QScan to compromise IoT devices and QTRouter as an obfuscation network and exploited CVE-2019-11510 and CVE-2019-19781 in earlier intrusions.
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
info@thehackernews.com (The Hacker News) 2026.08.26 98% relevant
This article appears to cover the same FBI disruption of QTFY infrastructure, adding reporting emphasis that the China-linked platforms were used to steal data from U.S. organizations.
US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
2026.08.26 100% relevant
This article appears to establish a distinct new story: the DOJ/FBI takedown of the QScan and QTRouter platforms and the attribution of their use to the China-linked QTFY operation targeting U.S. government and critical-sector victims.
← Back to all stories