
On August 26, 2026, the U.S. Justice Department and FBI obtained court-ordered seizures that disabled QScan and QTRouter, two hacking platforms tied to a Chinese state-linked group. The tools, used since at least 2018, had breached the U.S. Senate, NASA, and the Department of Energy.
The seizure cut off three hard-coded domains controlling the malware. The group behind the platforms, QTFY, operates through a private company in Nanjing and receives payments from China’s Ministry of State Security. The tools formed an industrial-scale espionage pipeline that could scan and exploit over 2 million targets daily.
The takedown was surgical. On August 24, a federal court in Southern California granted seizure warrants for three domains — qtproxy.xyz, qt-proxy.org, and qt-team.com. Two days later, on August 26, the domains were seized, and two hacking platforms that had run for eight years went dark. The platforms formed a pipeline: one tool scanned the internet for vulnerable devices, the other turned the compromised machines into a covert network. That pipeline had reached the U.S. Senate, NASA, the Federal Reserve, and the Department of Energy. The cost to use it was a contract with a private company in Nanjing.
The precise mechanism of the shutdown is what makes it unusual. The platforms relied on hard-coded domains for authentication and command-and-control. Seize the domains, and the entire architecture — the scanning modules, the botnet, the proxy chains — loses coordination. The Department of Justice described the action as rendering the platforms inoperable. The Justice Department characterized the operation as part of a broader strategy to use court-authorized technical measures to preempt state-sponsored hackers targeting U.S. critical infrastructure.
The industrialisation of a covert channel
The court documents from the Southern District of California identify the operator as Nanjing Xinjiuwei Network Technology Company, a private firm in the People’s Republic of China. Its employees, operating under the group name QTFY, include former members of the People’s Liberation Army who use their military relationships to obtain contracts for offensive cyber operations. According to court documents unsealed in the Southern District of California, payments from China’s Ministry of State Security to the company indicate that Nanjing Xinjiuwei conducts malicious cyber activities on behalf of the PRC government. The contracting structure creates a buffer: a nominally private entity takes on the technical and legal risk while state clients rent the tools.
The seized platforms were built for volume. QScan bundled more than 200 exploit modules and could process over 2 million scanning or exploitation tasks in a single day during 2024, according to court documents and the DOJ’s August 26 announcement. It targeted internet-facing services — VPNs, IoT endpoints, corporate gateways — and automatically infected thousands of devices worldwide. QScan’s architecture is easier seen than read.
The infected devices were then enrolled into QTRouter, an obfuscation network that blended compromised IoT routers running customized OpenWrt firmware with commercial proxy services and leased virtual private servers. The result was a covert channel that let QTFY, and other paying customers, route malicious traffic through American and European infrastructure, making it appear to originate close to its targets. FBI Director Kash Patel described the platforms as a global botnet used by PRC cyber actors. “These tools were used by PRC cyber actors to hide the origin of their attacks,” Patel said.
The victim list bears out the scale. In 2024, QTFY breached three Department of Energy national laboratories and the National Institutes of Health by exploiting a zero-day vulnerability in Ivanti Cloud Services Appliance. An attempted intrusion at NASA in August 2019 exploited CVE-2019-11510, a critical flaw in Ivanti’s Pulse Secure VPN. QTFY later exploited the same vulnerability in 2020 during the COVID-19 pandemic to attack a medical center in Ohio. The FBI had investigated the NASA attempt then; the platforms kept operating for seven more years. A network of nominally private firms in China conducts hacking for state intelligence services, and when one platform or contractor is exposed, others in the ecosystem keep running.
| Entity | Current rule | New rule or obligation | Effective date |
|---|---|---|---|
| United States | FISMA-mandated risk-based security programs for federal agencies | CIRCIA incident-reporting rules for critical infrastructure operators, mandatory notification for substantial cyber incidents | Final rule expected 2026-2027 |
| European Union | NIS1 Directive with varying national implementations | NIS2 Directive, harmonised cybersecurity duties for essential and important entities, with stronger reporting timelines | Member state transposition by October 2024; enforcement phasing through 2027 |
| Australia | Security of Critical Infrastructure Act requiring risk management programs | Enhanced sector-specific powers for cyber incident response, with mandatory reporting obligations for critical infrastructure | Amendments effective 2025; ongoing phased enforcement |
| Source: U.S. Office of Management and Budget / CISA; European Commission; Australian Department of Home Affairs | |||
The race between infrastructure and its disruption
What the QTFY case reveals is a structural shift in how Chinese espionage is provisioned. The Ministry of State Security and the PLA increasingly depend on a market of enabling companies — Nanjing Xinjiuwei, Shanghai Powerock, and others — that sell modular tools and infrastructure to multiple state clients. Lumen’s Black Lotus Labs described QTRouter as an infrastructure quartermaster for multiple China-nexus espionage units, warning that such quartermaster-style infrastructure lowers the barrier for different Chinese groups to reuse the same covert channels. Commercial threat intelligence firm Verisq AI confirmed that the platforms relied on U.S.-registered services and global IoT devices to mask the geographic origin of attacks, blurring jurisdictional lines.
This industrialisation changes what a takedown can achieve. Seizing domains temporarily severs the control infrastructure, but the underlying asset pool — compromised routers, rented servers, the same pool of exploitable devices — remains. In June 2026, Black Lotus Labs reported a significant resurgence of a Volt Typhoon-linked botnet, which surged to 1,500 compromised routers and IoT devices just weeks before the QTFY domains were seized. The pattern suggests that while a domain seizure can disable one group’s toolkit, the ecosystem that supplies the botnets regenerates. The question is not whether a successor to QScan and QTRouter will appear, but which contractor’s name will be on it.
Beyond the headline
The power behind it
Behind the seized domains sits a contracting model that lets Chinese intelligence agencies outsource both technical risk and legal exposure to nominally private firms. Companies like Nanjing Xinjiuwei provide modular tools and infrastructure that multiple state clients can rent, turning offensive capability into a service market. That structure gives Beijing deniability while ensuring that, when one platform is burned, another contractor can step in with new infrastructure built on the same pool of compromised devices and commercial proxies.
The bigger picture
The QTFY takedown illustrates how cyber espionage has shifted from bespoke campaigns to industrialised platforms that blur lines between state and criminal activity. Rather than building unique infrastructure for each operation, Chinese actors can rely on reusable scanning, exploitation, and proxy networks that serve many customers at once. This changes the calculus for defenders: they are not just hunting a single intrusion, but dismantling shared utilities that underpin an entire ecosystem of state-aligned operations.
The reach
One non-obvious impact falls on Western cloud and hosting providers whose infrastructure quietly underpinned QTRouter’s proxy chains. Because QTFY blended leased virtual private servers and commercial proxy services into its obfuscation network, providers in North America and Europe inadvertently became intermediaries for Chinese espionage traffic. That exposure is already driving closer scrutiny of abuse-report handling, customer vetting, and law-enforcement cooperation in the infrastructure-as-a-service sector, with potential compliance costs and policy changes for those firms.
The patch window is now narrower than the attacker’s
With the QScan and QTRouter platforms neutralised, the immediate risk from this specific toolchain drops. The larger risk does not. The same pool of unpatched IoT devices and end-of-life VPN appliances remains, and the enabling-company model guarantees that replacement infrastructure is already being assembled. Here is what the takedown means in practice.
- Western IT Security Manager with Federal Agency Exposure
You need to review network logs for indicators of compromise tied to QScan and QTRouter immediately, particularly for traffic to the three seized domains. Ensure all Ivanti Pulse Secure VPN, Citrix VPN, and Ivanti Cloud Services Appliance instances are patched against CVE-2019-11510, CVE-2019-19781, and the 2024 zero-day. CISA’s joint advisory on China-linked botnets, released August 26, contains specific signatures and IOC lists.
- Western Cloud/Hosting Provider Executive
Your infrastructure may have carried QTRouter traffic without your detection. Audit customer vetting and abuse-detection processes now — law-enforcement inquiries about traffic originating from your services are likely. The takedown notice identifies U.S.-registered services as part of the platform’s infrastructure pool, which means providers who cannot show robust abuse handling will face regulatory questions under forthcoming CIRCIA rules.
- Western Manufacturer of IoT Devices
The QScan platform specifically targeted routers and cameras running OpenWrt-based firmware and devices with weak default credentials. If your products fall into those categories, issue security advisories for vulnerable models, collaborate with CISA on botnet disruption efforts, and be prepared for customers asking whether their devices are enrolled in a Chinese state-linked proxy network. The reputational damage arrives faster than the patch.
- US-based Investor in Cybersecurity Firms
The takedown reinforces demand for threat-intelligence firms that can map enabling-company ecosystems and for incident-response providers that handle state-nexus intrusions. Assess your portfolio for exposure to the Ivanti and Citrix vulnerability footprint across critical infrastructure sectors. The shift from bespoke campaigns to reusable, service-model infrastructure means that detection products built for single-actor attribution are less valuable than those that can trace shared covert channels across multiple groups.
FAQ
What kinds of IoT devices did QScan target, and how would owners know?
QScan targeted a broad range of internet-exposed devices, including small-office and home-office routers, network video recorders, IP cameras, and other OpenWrt-based systems. Many of these devices receive infrequent firmware updates and often ship with weak default credentials. Owners typically only notice compromise if bandwidth usage spikes or devices become intermittently unreachable.
What are the incident reporting requirements for U.S. critical infrastructure operators?
Under the Cyber Incident Reporting for Critical Infrastructure Act of 2022, CISA’s forthcoming final rule will require covered entities in designated sectors to report substantial cyber incidents and ransomware payments within defined timelines. Private operators of energy, finance, health, and transport infrastructure should expect obligations to notify CISA promptly if they detect QTFY-related activity, including compromises of VPNs or IoT gateways linked to critical operations.
What data does a compromised VPN appliance expose?
Past advisories on CVE-2019-11510 and related Ivanti flaws explain that exploiting these vulnerabilities can allow attackers to read session caches, configuration files, and credential stores on VPN gateways. That may expose usernames, passwords, and multi-factor tokens reused elsewhere in an enterprise. Recommended remediation includes invalidating all sessions, forcing credential resets, examining logs for suspicious access, and rebuilding or reimaging appliances where integrity cannot be assured.
Explainer
- QTFY
- A China-linked hacking group that created and operated the QScan and QTRouter malware platforms. The group’s members work for Nanjing Xinjiuwei, a private company that receives payments from China’s Ministry of State Security. QTFY actors include former members of the People’s Liberation Army who leverage their military relationships to secure contracts for offensive cyber operations.
- IoT botnet
- A network of compromised internet-connected devices — routers, cameras, digital video recorders — enslaved by malicious software and controlled remotely. Botnets are used to launch attacks or route malicious traffic. QTRouter blended compromised IoT devices with commercial proxy services and leased virtual private servers to create a covert channel that made Chinese espionage traffic appear to originate from non-PRC locations.
- CVE-2019-11510
- A critical vulnerability in Ivanti’s Pulse Secure VPN disclosed and patched in April 2019. The flaw allowed unauthenticated attackers to read arbitrary files, including session caches and credential stores, from vulnerable gateways. QTFY exploited this vulnerability against a medical center in Ohio in 2020 and attempted to use it against NASA in August 2019.
- FISMA
- The Federal Information Security Modernization Act, which requires U.S. federal agencies to implement risk-based security programs under guidance from the Office of Management and Budget and CISA. It mandates reporting of significant incidents such as the QTFY intrusions, and works alongside the forthcoming CIRCIA rules to create layered reporting obligations for federal and private critical infrastructure operators.





