FBI Seizes Domains Behind China-Linked Hacking Operation

The FBI and DOJ seized QScan and QTRouter domains allegedly used by China-linked hackers to target U.S. agencies and critical infrastructure.

Aug 27, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Justice Department said Wednesday it seized domains that powered two hacking platforms, QScan and QTRouter, disrupting infrastructure allegedly used by a China-linked group to target US government agencies, critical infrastructure and other sensitive networks.

The platforms were operated by QTFY, which the DOJ says is employed by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose customers allegedly include China’s Ministry of State Security and People’s Liberation Army. The campaign dates back to at least 2018, according to an FBI affidavit.

The alleged victims include NASA, the Federal Reserve, the Department of Energy, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the US Senate. The FBI also said the operation targeted power companies, hospitals, financial institutions and defense contractors.

Not every attempted intrusion succeeded. The affidavit showed that QTFY unsuccessfully targeted a NASA VPN vulnerability in 2019 and scanned Senate and hospital networks in March 2026. A successful activity included data theft from unnamed defense contractors, financial institutions, and universities in 2024.

A hacking network built to hide in plain sight

QScan was used to scan networks and compromise vulnerable internet-connected devices, turning some of them into proxy nodes. QTRouter then helped route hacking traffic through those devices, leased servers and commercial proxy services.

That made it appear that an attack originated somewhere other than China, potentially even from a device near the victim.

Lumen described the broader infrastructure as a cyber “quartermaster” that supplies reconnaissance, routing and concealment services to other Chinese threat actors. Its research found the operators also co-opted commercial Chinese “Airport” proxy networks, allowing malicious traffic to blend into ordinary internet activity.

“It gives them a massive amount of plausible deniability to utilize networks like this,” Lumen researcher Damon Rouse said, per The Wall Street Journal.

The seized domains were hard-coded into QScan and QTRouter, meaning their removal caused the platforms to stop functioning, according to the DOJ. The operation highlights a growing problem for defenders: attackers no longer need to build every piece of their infrastructure themselves.

Lumen said shared, multi-tenant proxy networks allow state-backed groups to reuse infrastructure across campaigns while hiding among legitimate traffic. That weakens defenses based mainly on blocking suspicious IP addresses or geographic locations.

Advertisement

“This is a very long-lasting campaign,” Rouse told WIRED, adding that the company behind it had “very close ties to the highest levels of the People’s Liberation Army.”

What comes next

The FBI and the National Security Agency have released technical indicators associated with QTFY to help defenders detect related activity. The agencies have also carried out previous disruptions against China-linked botnets, including operations involving Mustang Panda, Flax Typhoon and Volt Typhoon.

The domain seizures made the tools inoperable, but no individuals have been charged, and researchers doubt the group is finished. Rouse said the takedown is “an egg-on-the-face moment for them” but predicted they’ll pivot and stand up new infrastructure.

What this means for security teams

The QScan and QTRouter takedown is a reminder that malicious traffic does not always come from an obviously suspicious place. By routing attacks through compromised devices, leased servers, and commercial proxy networks, QTFY could make malicious activity appear to originate outside China and, in some cases, from infrastructure near the targeted network.

For security teams, the FBI and the NSA have released indicators of compromise associated with QTFY that organizations can use to search for related activity. The operation also demonstrates the challenge of identifying attackers that deliberately route their traffic through compromised or otherwise legitimate-looking infrastructure.

The seized domains made QScan and QTRouter inoperable, according to the Justice Department, but the broader technique is not unique to these platforms. For defenders, the takedown offers another reason to look beyond the apparent location of suspicious traffic when investigating potential intrusions.

Also read: See how T-Mobile physically cut a network cable to disrupt China-linked Salt Typhoon hackers attempting to maintain access to its network.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.