FBI seizes QScan and QTRouter, the tools China used to hide hacks through home devices
Court papers unsealed in San Diego say QTFY, tied to Nanjing Xinjiuwei, scanned IoT gear in more than 130 countries and relayed attacks on NASA, the Senate, the Federal Reserve and energy and health networks.


San Diego3 min read
Last updated
The Justice Department and the FBI said on 26 August that they had seized the domains that kept two Chinese hacking platforms alive. The tools are QScan and QTRouter. Court papers unsealed in the Southern District of California attribute them to a group the bureau calls QTFY, working through Nanjing Xinjiuwei Network Technology Company.
QScan scanned the public internet for weak internet-of-things devices, infected them and fed them into QTRouter. QTRouter then mixed those devices with commercial proxy nodes and rented virtual private servers. Traffic that started in China left the last hop looking like a home router or camera in one of more than 130 countries.
FBI Director Kash Patel said the platforms were used to hide the origin of attacks on U.S. critical infrastructure. The affidavit lists NASA, the U.S. Senate, the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and the Justice Department itself among the victims. Power companies, telecoms and hospital systems appear in the same set of papers.
The company and the payments
Prosecutors say Nanjing Xinjiuwei sold stolen data and hacking services to Chinese military and intelligence customers. Court documents cite payments from the Ministry of State Security to the firm as evidence that the work was done for the state. The People's Liberation Army is named as another customer in the same file. QTFY is described as sitting inside a mix of hackers-for-hire and government clients.
The group has been active for nearly a decade on the FBI's timeline. In May 2024, according to the affidavit, it used a newly public flaw in Check Point equipment and pulled server settings and account data from more than 300 U.S. organisations. Speed after a disclosure is the pattern the bureau wants to underline. QScan was built to find the next weak device at scale, not to sit on a single stolen password.
What the seizure actually did
The operation took the domains that QScan and QTRouter used for command, communication and authentication. Without those names, the platforms could not reach the infected devices in the usual way. Lumen, a backbone provider, said it also null-routed some of the domains. Three domains are named in follow-on coverage as the ones seized on Wednesday.
A domain seizure does not wipe every compromised router. Devices in homes and small offices can stay infected until someone patches or replaces them. What it does is cut the path the operators used to talk to the herd. Rebuilding that path means new domains, new certificates and a period in which the old implants go quiet.
The bureau framed the action as part of a wider set of technical operations against PRC-sponsored hacking and tied it to the White House cyber strategy. It is the latest public takedown in a line that has included other botnets built on routers and cameras. The legal work ran through FBI San Diego and the Cyber Division.
What readers should take from the victim list
The list is unusual for how many civilian agencies sit next to the Senate and NASA. Energy, health and the central bank are not side targets in this affidavit. They are named. That is the information gain in the package: the concealment layer was generic IoT, and the destinations were the institutions that run money, power and medical research.
Beijing has not accepted the attribution in the papers unsealed this week. The company named in Nanjing has not issued a detailed public reply in English-language coverage. The facts that can be checked are the court venue, the tool names, the domain seizures, the victim list in the affidavit and the claim that MSS money moved to the firm that sold the service.
For operators of small networks the practical step is the same as after every router botnet case. Change default passwords. Patch the models named in vendor advisories. Treat a cheap camera on the guest network as a relay that someone else can rent.
Continue reading
- News
Carney plans a Turkey visit this month, the first dedicated one by a Canadian prime minister
Almanaque Digital DeskOttawa
- News
Palace says Charles will not apologise for slavery on the Caribbean tour
Almanaque Digital DeskLondon
- News
Sheinbaum wants a bill next week ordering platforms to pull violent posts