DOJ and FBI seize China-linked QScan and QTRouter
The DOJ and FBI executed court-authorized domain seizures that rendered two PRC hacking platforms, QScan and QTRouter, inoperable. DOJ attributes them to the group QTFY at Nanjing Xinjiuwei, and names NASA, the Federal Reserve, DOE and the U.S. Senate among victims.

The Justice Department and FBI carried out court-authorized domain seizures that took down two complementary China-linked hacking platforms, QScan and QTRouter, according to the DOJ announcement. The action is a seizure of infrastructure, not an indictment: DOJ describes taking the tooling offline, and no charges are announced with it.
The instrument matters here. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures, out of the Southern District of California, "made QScan and QTRouter inoperable." This is not a takedown notice that redirects a website. It is severing the fixed callback addresses the malware needs to function, which is why disabling the domains disables the platforms themselves.
Who DOJ says ran it
DOJ attributes the platforms to a PRC state-sponsored group it calls QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司). The two tools work as a pair: QScan scans and automatically infects thousands of internet-of-things devices worldwide, which are then folded into QTRouter, an "obfuscation network" that routes intrusions through compromised IoT devices, commercial proxies, and leased servers so the traffic appears to originate outside the PRC. The point of the whole apparatus is deniability: making Chinese state intrusions look like they come from anywhere else.
Notably, DOJ does not tie this to Volt Typhoon or Salt Typhoon. QTFY is presented as its own operation, and one that sells: DOJ says it offers hacking services to paying customers including the PRC's Ministry of State Security and the People's Liberation Army.
The number the headline leaves out: seven federal victims
The scope is in the victim list, not the platform names. DOJ names, among the victims of QTFY intrusion activity, the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. That is a fiscal agency, a nuclear-and-grid department, the government's own prosecutors, and a chamber of Congress, reached through the same commodity IoT-to-proxy pipeline.
What a defender does this week
Do not read this as "the threat is gone." A seized obfuscation layer gets rebuilt, and the compromised IoT hosts underneath it stay compromised until they are patched or replaced. Three concrete moves this week: pull the seized domain indicators from the FBI notice and block plus alert on any egress to them, which surfaces hosts that were beaconing. Hunt outbound connections through residential proxies and low-reputation leased VPS ranges, the QTRouter pattern, rather than trusting geolocation to tell you where traffic really comes from. And inventory your internet-exposed IoT and edge devices, cameras, routers, NAS, since QScan's entire model is auto-infecting the ones left reachable and unpatched.
For related reading on state-linked intrusion tradecraft and cloud data theft, see our coverage of CISA's advisory on AI-assisted exploitation of Siemens S7 and the Azure data-theft campaign against Fortune 500 firms.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free