The Justice Department and FBI announced Wednesday that they had carried out court-authorized seizures of internet domains tied to two hacking platforms, QScan and QTRouter, disrupting a campaign that federal officials say breached some of the country's most sensitive networks. Court documents unsealed in the Southern District of California name the National Aeronautics and Space Administration, the Federal Reserve, the Department of Justice itself, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate among the targets.
The filings attribute the platforms to a group identified only as "QTFY," which investigators say is a People's Republic of China state-sponsored operation employed by the Nanjing-based Xinjiuwei Network Technology Company. According to the affidavit, QTFY did not act alone in the sense of pursuing its own targets exclusively — prosecutors allege the group also sold its hacking capabilities to paying clients, including China's Ministry of State Security and the People's Liberation Army, a hackers-for-hire arrangement that investigators say has become increasingly common in Chinese state-linked cyber operations.
How QScan and QTRouter Worked Together
The two platforms were designed to complement one another. QScan functioned as a reconnaissance and exploitation tool, continuously scanning the internet for vulnerable connected devices — everything from routers to other so-called smart hardware — and automatically infecting them; the affidavit states that on a single day in 2024, QScan carried out more than two million scanning and exploitation attempts. Devices compromised by QScan then fed into QTRouter, which blended them with commercial proxy services and leased virtual private servers to build what the department calls an obfuscation network. That layer let QTFY's traffic appear to originate almost anywhere except China, including, in some cases, from a device sitting near the very network being attacked.
The Domains Behind the Network
Investigators seized three domains — qtproxy.xyz, qt-proxy.org and qt-team.com — that were hard-coded into the QScan and QTRouter malware for essential functions such as authentication and communication between infected devices and their operators. Because both platforms depended on those addresses to function, officials said the court-authorized takeover left QScan and QTRouter inoperable, at least in their current form.
A Campaign Dating Back to at Least 2018
The affidavit traces QTFY's intrusion activity back to 2018, describing a campaign with mixed results over the years. An attempt to breach NASA's network in August 2019 by exploiting a VPN vulnerability reportedly failed. The group had more success in 2024: intrusions in May affected defense contractors, financial institutions and universities, according to a joint cybersecurity advisory cited in coverage of the case, while a September wave of breaches hit three Department of Energy national laboratories, an HHS-affiliated health agency and a U.S. security-device manufacturer. As recently as March 2026, the group reportedly scanned for vulnerabilities and attempted, without success, to penetrate the U.S. Senate and a U.S. hospital system. Four additional companies in the United States and South Korea were also reportedly affected.
Officials Cast the Takedown as Part of a Wider Campaign
Attorney General Todd Blanche framed the action as a warning to other state-linked hacking operations, saying "state-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted." FBI Director Kash Patel described the takedown as the disruption of "a global botnet and hacking platform used by Chinese state-sponsored hackers," adding that the tools existed specifically to mask the origin of the group's intrusions. The department credited the FBI's San Diego Field Office and Cyber Division, the U.S. Attorney's Office for the Southern District of California, and the National Security Cyber Section of the Justice Department's National Security Division with leading the investigation and the disruption effort.
Officials described Wednesday's seizures as the latest in a series of technical operations aimed at dismantling hacking infrastructure linked to Beijing, following a 2025 effort in which the FBI removed PlugX malware from more than 4,000 infected U.S. computers tied to a separate group known as Mustang Panda. Chinese authorities have consistently denied past U.S. allegations of state-sponsored hacking, and did not immediately respond to requests for comment on the QTFY case.





