The US Department of Justice and FBI announced the seizure of two hacking platforms operated by a Chinese state-sponsored group on Wednesday, disrupting what officials called a years-long campaign targeting NASA, the Federal Reserve, the Senate, and multiple federal agencies.
Court documents unsealed in the Southern District of California identified the group as “QTFY,” employed by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose clients included China’s Ministry of State Security and the People’s Liberation Army. The group operated two complementary tools: QScan, a vulnerability scanning and exploitation platform, and QTRouter, an obfuscation network used to hide the origin of attacks.
How the Platforms Worked
QScan scanned and automatically infected thousands of internet-of-things devices worldwide, which were then added to the QTRouter network. That network of compromised IoT devices, commercial proxies, and leased virtual private servers served as an “obfuscation network,” allowing hackers to make their traffic appear to originate from endpoints outside China and sometimes even near the targeted networks themselves.
Because the seized domains were hard-coded into both QScan and QTRouter malware, the court-authorized seizures made both platforms immediately inoperable. A joint cybersecurity advisory from the FBI, NSA, and US Cyber Command’s Cyber National Mission Force detailed the full scope of QTFY’s operations dating back to at least 2018.
A Decade of Intrusions
An affidavit filed in the case identified victims including the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the US Senate. The hackers also hit cleared defense contractors, energy companies, telecommunications firms, financial institutions, and universities across the United States and South Korea.
QTFY exploited both zero-day and known vulnerabilities across a wide range of products. Among the tools in their arsenal: exploits for Ivanti CSA, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, CrushFTP, and BeyondTrust Remote Support. The FBI noted that on a single day in 2024, QScan processed over two million scanning and penetration testing tasks.
Lumen Technologies’ Black Lotus Labs, which tracked QTFY for over 18 months, described the group as a “digital quartermaster” supplying hacking infrastructure to Chinese government clients. The company said targeting extended “throughout the western world and beyond, especially with regard to academia.”
Senior Officials Respond
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.” – Attorney General Todd Blanche
FBI Director Kash Patel described the seizure as part of a broader effort to dismantle Chinese cyber operations. “These tools were used by PRC cyber actors to hide the origin of their attacks,” Patel said, adding that the action supports “President Trump’s Cyber Strategy for America.”
The FBI also revealed that QTFY scanned for vulnerabilities at a US children’s hospital in June 2021 and attempted to access a US election system in June 2026, though neither attempt was successful. Successful intrusions included data exfiltration from defense contractors, financial institutions, and universities in May 2024.
Part of a Pattern
The QTFY seizure is the latest in a series of US law enforcement actions against Chinese state-sponsored hacking infrastructure. In 2025, the FBI removed PlugX malware from over 4,000 US computers. In 2024, the agency disabled a botnet of hundreds of thousands of infected IoT devices used by the Flax Typhoon group. In 2023, the FBI disrupted Volt Typhoon’s botnet used to conceal exploitation of US critical infrastructure.
The Chinese Embassy in Washington responded by saying China “firmly opposes and combats all forms of cyberattacks” but accused the US of using cybersecurity issues to “smear or discredit China.” Nanjing Xinjiuwei did not immediately respond to requests for comment.
The FBI also published indicators of compromise for QScan and QTRouter, urging network defenders to review the joint cybersecurity advisory and check for signs of intrusion. Organizations using Fortinet, Ivanti, Citrix, or Microsoft Exchange products were particularly urged to verify patch status and review access logs for suspicious activity.
discussion