FBI seizes QScan and QTRouter domains used against NASA, the Fed and the Senate
Justice Department filings say Nanjing Xinjiuwei ran the platforms for China’s Ministry of State Security and the PLA. The Senate was hit in 2026. Energy labs and NIH were breached in September 2024.


Washington3 min read
Last updated
The Justice Department and the FBI said on Wednesday they had seized internet domains hard-coded into two hacking platforms, QScan and QTRouter. Court papers unsealed in the Southern District of California describe the platforms as the work of a China-based group the government calls QTFY, employed by Nanjing Xinjiuwei Network Technology Company. Paying customers, the filings say, included China's Ministry of State Security and the People's Liberation Army.
QScan scans and infects internet-of-things devices at scale. Those devices, plus commercial proxy nodes and leased virtual private servers, feed QTRouter. The point of the second platform is to hide the true source of an intrusion by making the traffic look as if it came from a compromised camera, router or rented server outside China. Because the seized domains handled command, control and authentication, the government says both tools stopped working when the names were taken.
The victim list in the affidavit reaches back to 2018. It includes NASA, the Federal Reserve, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the United States Senate. Hospitals, telecom operators, power companies, financial firms and defence contractors appear as a class of targets. Four unnamed companies in the United States and South Korea are listed as well.
Access was uneven. An attempt on NASA networks in August 2019, aimed at a virtual private network flaw, failed. In September 2024 the operators got into three Energy Department laboratories, NIH, an HHS component and a US security-device maker. The Senate compromise is dated to 2026. The filings do not describe what was taken from any of those networks. Attorney General Todd Blanche called the seizure the latest in a run of technical operations against Chinese state-sponsored hacking.
The timing sits one month before a planned meeting in Washington between Donald Trump and Xi Jinping. Artificial intelligence and advanced technology are expected to dominate that agenda. Beijing routinely denies that it sponsors this kind of activity. The Chinese embassy in Washington did not immediately comment. Nanjing Xinjiuwei could not be reached through public listings.
QTFY's business model is the part of the case that travels beyond a single botnet takedown. The group, on the government's account, did not only hack for the Chinese state. It sold the same tooling to the state. That is a vendor relationship, not a unit inside an intelligence service. If the affidavit is accurate, shutting the domains wounds a contractor more than it wounds the MSS or the PLA, both of which can hire another shop.
The technical detail that made the seizure possible is also the detail that limits it. Hard-coded domains are a single point of failure. Operators who rebuild will not make that mistake twice. Compromised IoT devices remain in place. The QTRouter idea, blending bot traffic with paid proxies, will reappear under new names because it works. The government's claim is narrower: these two platforms, as wired last week, no longer answer.
For the named American institutions the practical question is older than Wednesday's announcement. NASA was probed seven years ago. Energy labs and NIH were entered two years ago. The Senate was entered this year. Domain seizure does not tell those networks what left their servers. That work sits with the agencies' own incident teams and with the classified side of the FBI case.
Blanche's phrase, "indiscriminate hacking activities," is doing a lot of work. The target set in the affidavit is not indiscriminate. It is a map of American scientific, financial and legislative infrastructure, plus a handful of allied firms in South Korea. The indiscriminate layer is the IoT harvest that built the hiding place. The directed layer is who QTFY's customers chose to walk through once the path was open.




