Federal law enforcement disrupted a Chinese state-sponsored cyber-espionage operation by seizing internet domains used to run QScan
and QTRouter
hacking platforms. The infrastructure targeted multiple U.S. government agencies, including the Justice Department, NASA, the Federal Reserve, and the Senate.
Federal Agencies and Sensitive Networks Targeted Since 2018
The Justice Department revealed that a coordinated cyber campaign compromised critical infrastructure and sensitive government networks. According to court documents unsealed in the Southern District of California, the intrusion campaign relied on custom malware designed to infiltrate federal institutions and private firms.
Investigators discovered that the threat actors targeted high-profile targets across the federal government, attempting to siphon valuable intelligence.
- The U.S. Department of Justice
- The Federal Reserve
- The U.S. Senate
- The Department of Energy
Beyond Washington’s primary institutions, court filings show that the group’s computer infrastructure was deployed against hospital systems, power companies, telecommunications providers, financial institutions, and defense contractors. An affidavit filed in the case notes that the activity has persisted since at least 2018, utilizing varying levels of access depending on the target.
How the QScan and QTRouter Hacking Ecosystem Operated
The operation depended on a complex digital ecosystem designed to mask the true origin of cyber intrusions. U.S. officials explained that the infrastructure utilized thousands of compromised internet-of-things devices scattered across the globe.
The primary tool, QScan, functioned as a scanning and exploitation platform that infected vulnerable internet-connected devices and enrolled them into a larger network. Once compromised, those devices fed into QTRouter, which served as an obfuscation network routing malicious traffic through third-party hardware to obscure the attackers’ actual location.
Court documents trace the origin of the platforms to a China-based firm known as the Nanjing Xinjiuwei Network Technology Company. The firm allegedly employed a hacker group designated as QTFY
, whose paying customers included the People’s Republic of China’s Ministry of State Security and the People’s Liberation Army.
Law Enforcement Disruption and Domain Seizures
Federal authorities countered the campaign by executing court-ordered seizures of internet domains hard-coded into the malware’s core functions. Taking down domains such as qtproxy.xyz, qt-proxy.org, and qt-team.com cut off authentication and communication pathways, rendering both QScan and QTRouter entirely inoperable.

FBI Director Kash Patel noted that the operation successfully dismantled a global botnet utilized by Chinese state-sponsored hackers to target U.S. critical infrastructure while actively concealing their tracks.
The Rise of Private Chinese Offensive Cyber Contractors
Cybersecurity analysts point out that intelligence agencies and military branches in Beijing increasingly outsource high-profile digital intrusions to commercial contractors.

While the Chinese Embassy in Washington did not immediately respond to requests for comment—and Beijing routinely denies involvement in malicious hacking campaigns—the disruption represents a direct technical blow to the private contractors servicing state intelligence objectives.
Broader Patterns in U.S. Cyber Operations
Wednesday’s domain seizures fit into an escalating series of technical interventions by U.S. agencies against state-aligned cyber campaigns. Federal law enforcement has increasingly moved beyond passive defense to actively dismantle foreign botnets before intrusions can cause widespread damage.
| Year | Target Operation | Disrupted Malware / Botnet |
|---|---|---|
| 2026 | Nanjing Xinjiuwei / QTFY | QScan and QTRouter platforms (Domains seized by DOJ) |
| 2025 | Mustang Panda | PlugX surveillance malware removed from over 4,000 U.S. computers |
| 2024 | Flax Typhoon | Botnet of hundreds of thousands of compromised devices disabled |
| 2023 | Volt Typhoon | Botnet used to conceal critical infrastructure attacks disrupted |