Report Ads

US Justice Department Seizes Chinese State-Sponsored QScan and QTRouter Hacking Platforms

Cybersecurity Systems
Stay Secure in a World of Growing Cyber Threats. [TechGolly]

Table of Contents

The United States Department of Justice and the Federal Bureau of Investigation have seized core internet domains powering two sophisticated Chinese state-sponsored cyber espionage platforms known as QScan and QTRouter. Federal prosecutors unsealed court-authorized seizure warrants in the Southern District of California, taking down critical digital infrastructure that Chinese intelligence operatives used to breach sensitive federal agencies, major financial regulators, academic institutions, and critical infrastructure networks worldwide.

According to federal affidavits and intelligence advisories, a state-sponsored threat group known as QTFY built and operated the malicious platforms. The hackers operated under the commercial cover of Nanjing Xinjiuwei Network Technology Company, a China-based cybersecurity firm that sells stolen intelligence and bespoke intrusion tools to China’s primary civilian spy agency, the Ministry of State Security, and the People’s Liberation Army. The coordinated law enforcement takedown seized the primary control domains hard-coded into the malware, severing the operators’ access to thousands of infected intermediate relay nodes and rendering the platforms inoperable.

The scope of the targeting exposed by federal investigators spans the highest levels of the United States government and international commerce. Court documents revealed that the hacking ring carried out cyber intrusions and attempted attacks against the National Aeronautics and Space Administration, the Federal Reserve Board of Governors, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the United States Senate. By dismantling the proxy network that obscured these attacks across more than 130 countries, federal law enforcement delivered a major blow to Beijing’s global cyber espionage operations.

A Major Disruption of Global Botnet and Cyber Espionage Infrastructure

The joint operation executed by the FBI Cyber Division, the FBI San Diego Field Office, and the Department of Justice represents a significant enforcement success in countering foreign cyber threats. State-sponsored hackers frequently use multi-tier proxy networks to hide the true geographic origin of their network intrusions, making attribution and real-time defense difficult for corporate and government network administrators.

By seizing the centralized command-and-control domains that coordinated QScan and QTRouter, federal authorities disrupted a digital quartermaster operation that had functioned continuously since at least May 2018. The platforms served as an automated intrusion pipeline, enabling Chinese intelligence agencies to outsource the tedious work of discovering software vulnerabilities, compromising intermediate devices, and routing malicious network traffic.

United States Attorney General Todd Blanche emphasized that the technical takedown proves law enforcement will aggressively disable foreign state-sponsored malicious software. FBI Director Kash Patel stated that the court-authorized seizure dismantled a global botnet used by Chinese actors to hide the origins of their attacks, fulfilling federal cyber strategy directives to defend the homeland by disabling adversary infrastructure.

Unpacking the Court-Authorized Domain Seizures in San Diego

The legal authority for the takedown originated from the United States District Court for the Southern District of California, where a federal judge signed seizure orders authorizing law enforcement to take control of the malicious domains. Once the seizure orders took effect, registry operators redirected the web traffic destined for QScan and QTRouter servers to secure government-controlled domain name servers.

This domain-sinkholing maneuver produced immediate operational results:

  • Severing communication between infected intermediate router nodes and the central command servers operated by Nanjing Xinjiuwei in China.
  • Preventing the threat group from issuing new automated scanning scripts or deploying secondary malware payloads to compromised devices.
  • Capturing real-time telemetry from remaining infected systems, allowing federal cybersecurity analysts to identify ongoing enterprise breaches and notify affected victims.
  • Depriving Chinese military and civilian intelligence units of a trusted, multi-year operational relay network that cost millions of dollars to build and maintain.

Federal cyber defense teams noted that while advanced threat groups will eventually attempt to construct replacement proxy networks, rebuilding an infected botnet spanning thousands of global devices requires substantial time, capital, and engineering effort.

High-Profile Victims from NASA and the Federal Reserve to the US Senate

The list of confirmed targets and compromised entities detailed in federal court filings illustrates the strategic intelligence priorities of the Chinese government. The threat group targeted organizations holding critical aerospace designs, economic policy data, sovereign energy secrets, and high-level political communications.

Among the prominent government victims identified in federal court records:

  • The National Aeronautics and Space Administration, where FBI agents investigated an attempted intrusion against space agency networks that failed because engineers had already patched the targeted software vulnerability.
  • The Federal Reserve, where hackers sought access to confidential monetary policy deliberations, banking oversight records, and financial stability models.
  • The United States Senate, where threat actors targeted legislative staff communications, foreign relations briefings, and internal committee databases.
  • The Department of Energy, including national laboratories conducting research into nuclear energy, advanced materials, and supercomputing.
  • The Department of Health and Human Services and the National Institutes of Health, where hackers targeted proprietary biomedical research, vaccine development pipelines, and clinical trial records.

In addition to federal agencies, the hackers infiltrated networks belonging to four unnamed commercial technology and manufacturing corporations located in the United States and South Korea.

The group also targeted regional hospitals, telecommunications carriers, electrical power utilities, commercial banks, and defense industrial base contractors, demonstrating an indiscriminate appetite for intellectual property and critical infrastructure access.

Technical Anatomy of the QScan and QTRouter Cyber Arsenal

The effectiveness of the QTFY hacking campaign stemmed from the technical pairing of two complementary software platforms. Rather than relying on human hackers to manually scan individual corporate firewalls, the group automated the entire initial-access pipeline.

QScan functioned as an automated global reconnaissance and infection engine, while QTRouter acted as a dynamic traffic-routing and obfuscation layer.

Together, the two platforms created an automated supply chain of compromised devices that allowed state-sponsored operators to launch stealthy network attacks without revealing their physical IP addresses in China.

QScan’s Automated Scanning and IoT Infection Engine

The entry point of the operation was QScan, a distributed scanning platform that continuously scoured the global internet for vulnerable edge-routing devices, consumer electronics, and smart hardware. The software targeted known software vulnerabilities, default administrative passwords, and unpatched firmware bugs across popular commercial hardware brands.

The mechanics of the QScan automated engine operated through a multi-step loop:

  • Scanning billions of public IP addresses across the internet to locate exposed network ports associated with home routers, digital video recorders, and network-attached storage arrays.
  • Automatically executing pre-packaged software exploits against unpatched firmware to gain root administrative access on target devices.
  • Installing lightweight, memory-resident malware payloads that co-opted the processing power and network bandwidth of the infected hardware.
  • Enrolling the newly compromised hardware into a centralized inventory database, categorizing each device by geographic location, connection speed, and internet service provider.

By infecting thousands of consumer and enterprise Internet of Things devices worldwide, QScan built a massive, self-replenishing pool of computing hardware that operated without the knowledge or consent of the physical device owners.

QTRouter’s Obfuscation Proxy Network Across 130 Countries

Once QScan successfully compromised an internet-connected device, it integrated the hardware directly into the QTRouter network. QTRouter functioned as an operational relay service that combined infected Internet of Things hardware, leased virtual private servers, and commercial proxy services into a unified obfuscation network.

The resulting botnet gave Chinese state hackers access to operational relay points located in more than 130 countries:

  • The platform maintained an active directory of thousands of live proxies, allowing operators to select specific exit nodes based on target parameters.
  • Hackers could route attack traffic through multiple proxy hops, bouncing packets across several continents before reaching final target networks.
  • The software dynamically replaced offline or patched proxy nodes with newly infected hardware discovered by QScan, maintaining continuous network uptime.
  • Leased commercial virtual private servers provided high-bandwidth data exfiltration channels to move large volumes of stolen files back to servers in China.

This multi-layer proxy architecture created an effective operational shield. When corporate security operations teams detected an unauthorized login or data breach, forensic logs pointed toward an infected residential home router in Ohio or a commercial security camera in South Korea, completely concealing the state-sponsored operators in Nanjing.

Simulating Legitimate Local Traffic to Bypass Security Firewalls

The most dangerous tactical capability provided by QTRouter was its ability to perform proximity-based traffic spoofing. Modern enterprise security tools, including automated web application firewalls and security information management platforms, utilize geographic IP filtering to block suspicious connection attempts originating from foreign adversaries like China or Russia.

QTRouter bypassed these geographic security defenses through localized traffic routing:

  • When targeting an electrical utility in the American Midwest, the hackers routed their attack commands through a compromised residential cable modem located in the exact same municipal area.
  • When targeting a government ministry in Seoul, operators routed traffic through infected commercial broadband routers within South Korea.
  • Network connection requests appeared as ordinary, legitimate residential web browsing traffic, evading automated anomaly-detection algorithms.
  • Authentication requests bypassed geographic login blocks, allowing operators to conduct slow, low-volume password-spraying attacks without triggering security alarms.

By making foreign cyberattacks appear as local network traffic, QTFY operators maintained long-term, persistent access inside victim networks for months or years without being discovered.

Unmasking the Contractor Ecosystem: Nanjing Xinjiuwei and the QTFY Group

The Justice Department’s unsealed affidavits provide detailed insight into the commercial ecosystem that powers China’s state-sponsored cyber offensive programs. While Western military cyber commands generally rely on uniformed military personnel, China has constructed a sprawling commercial market comprising private technology contractors, security research firms, and hacker-for-hire enterprises.

The commercial firm at the center of the dismantled infrastructure is the Nanjing Xinjiuwei Network Technology Company. Operating from modern office facilities in Jiangsu province, the company marketed itself as a standard commercial software and network security enterprise.

In reality, federal prosecutors proved that Nanjing Xinjiuwei operated as a dedicated digital quartermaster, building custom cyber tools, executing intelligence collection contracts, and selling stolen data directly to Chinese military and intelligence agencies.

Cyber Mercenaries Supplying China’s Ministry of State Security and Military

Court documents revealed direct financial and operational links between Nanjing Xinjiuwei and key departments of the Chinese government. The company’s primary commercial clients included China’s civilian intelligence agency, the Ministry of State Security, and various operational units of the People’s Liberation Army.

The contractor model provides significant strategic advantages for Chinese intelligence agencies:

  • Government agencies can rapidly scale offensive cyber capabilities by hiring specialized private software engineering teams rather than training military recruits.
  • Private contractor firms compete aggressively for government intelligence bounties, driving rapid innovation in exploit discovery and automated hacking tools.
  • The Chinese government maintains a layer of plausible deniability, routinely claiming that international cyberattacks are carried out by independent criminal groups rather than state organs.
  • Contractor firms manage the ongoing overhead of leasing foreign servers, registering fake domain names, and maintaining botnet infrastructure.

The Justice Department’s indictment demonstrates that United States law enforcement will pierce the corporate veil of private front companies, exposing the direct connections between commercial contractors and state intelligence directives.

Seven-Year Operational History of Critical Infrastructure Intrusions Since 2018

The federal affidavit documented that the QTFY threat group maintained uninterrupted operational campaigns targeting critical infrastructure and sensitive networks since at least May 2018. Over this seven-year operational history, the group adapted its tactical methodologies to exploit emerging software vulnerabilities and evade evolving cybersecurity defenses.

The group’s long-term targets reflected systematic economic and strategic intelligence collection:

  • Infiltrating American power grid operators and regional municipal water distribution authorities to pre-position access credentials for potential future disruption.
  • Compromising commercial telecommunications service providers to monitor the private communications of targeted political figures, human rights activists, and defense officials.
  • Exfiltrating proprietary research data from leading pharmaceutical developers and biotechnology research labs in the United States and allied nations.
  • Stealing commercial financial models, merger documentation, and investment strategies from major banking institutions.

The extended lifespan of the QTFY infrastructure underscores the resilience of commercial hacking platforms. By maintaining automated tools like QScan, the group sustained continuous intelligence operations across multiple presidential administrations and fluctuating geopolitical cycles.

Industry Collaboration and Private Sector Threat Hunting

The successful disruption of QScan and QTRouter resulted from a close public-private partnership between federal law enforcement and commercial cybersecurity research teams. In modern cyber defense, private threat intelligence firms possess global network telemetry that allows them to spot malicious infrastructure long before government agencies detect specific corporate intrusions.

Security researchers at Lumen Black Lotus Labs played a central role in mapping the QTFY network architecture. Threat hunters at the firm tracked the group’s operational relay boxes, server infrastructure, and malware updates for more than 18 months before formal law enforcement action commenced.

By sharing proprietary threat telemetry with the FBI Cyber Division in San Diego over a year-long joint investigation, private researchers provided the forensic evidence required for federal prosecutors to secure court-authorized seizure warrants.

Black Lotus Labs Tracking and Inter-Agency Cyber Intelligence Sharing

The private-sector investigation tracked the underlying communication patterns that connected intermediate compromised devices back to command servers in Nanjing. Analysts observed that despite the operators’ efforts to hide their tracks behind commercial proxy services, the software exhibited distinct cryptographic handshakes and consistent network beaconing behaviors.

Lumen and federal partners analyzed the group’s operational footprint:

  • Mapping thousands of active proxy nodes across commercial internet service providers in North America, Europe, and Asia.
  • Identifying the hard-coded primary and backup domain names that infected routers used to receive new operational commands.
  • Correlating malicious scanning bursts with known vulnerability disclosures in consumer router firmware.
  • Providing defensive telemetry to major internet backbone providers to null-route malicious traffic and protect enterprise clients.

The collaboration illustrates how inter-agency intelligence sharing between the FBI, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and private security vendors creates an active defense network capable of dismantling complex state-sponsored infrastructure.

Academic and Scientific Research Targeting in the United States and South Korea

A distinct characteristic of the QTFY hacking campaign was its intense focus on university research laboratories and scientific academic institutions. Security researchers noted that the group frequently prioritized academic networks due to the open, collaborative nature of international scientific research.

The hackers targeted cutting-edge scientific research programs:

  • Infiltrating university computer science and electrical engineering departments, developing next-generation artificial intelligence models and quantum computing algorithms.
  • Targeting materials science laboratories developing advanced composite alloys and semiconductor manufacturing substrates.
  • Exfiltrating clean-energy research data from university laboratories funded by Department of Energy research grants.
  • Compromising academic medical centers in the United States and South Korea conducting advanced oncology and genetic sequencing research.

Academic institutions often maintain open network architectures that facilitate data sharing among international researchers, making them vulnerable to automated scanning platforms like QScan.

The Justice Department and FBI released comprehensive technical indicators to help university chief information security officers identify and purge residual QTFY malware from campus networks.

Strategic Implications for the US-China Cyber Warfare Landscape

The seizure of QScan and QTRouter marks a broader evolution in how the United States government confronts state-sponsored cyber espionage. For years, Western responses to foreign hacking were limited to issuing diplomatic demarches, unsealing symbolic indictments against foreign military officers who remained out of reach of American law enforcement, and publishing voluntary security advisories.

Today, the Department of Justice and United States Cyber Command are deploying aggressive, operational disruption strategies. Law enforcement agencies are obtaining court orders to remotely access private servers, delete malware from infected consumer routers, and seize command domains to collapse adversary infrastructure in real time.

This proactive approach aims to impose tangible operational and financial costs on foreign intelligence agencies and their commercial contractor networks.

Active Defense Strategies and Disruption Operations Under the FBI and DOJ

The disruption of the Nanjing Xinjiuwei platforms follows a series of high-profile federal operations targeting foreign botnet infrastructure. Federal authorities have established specialized cyber operational units designed to execute rapid, court-authorized technical takedowns:

  • Executing court-authorized operations to neutralize the Volt Typhoon and Flax Typhoon botnets that targeted critical American infrastructure.
  • Seizing illicit cryptocurrency payment channels and digital escrow accounts used by commercial hacking firms to monetize stolen data.
  • Working with international law enforcement partners in Europe and Asia to coordinate simultaneous server takedowns across multiple foreign jurisdictions.
  • Enforcing aggressive sanctions through the Department of the Treasury against commercial front companies that provide cyber tools to foreign military units.

Attorney General Todd Blanche and FBI Director Kash Patel stated that federal law enforcement will continue to surge technical operations to shape adversary behavior, disrupting foreign cyber infrastructure before state hackers can execute destructive attacks against critical systems.

Hardening Critical Infrastructure and Domestic IoT Networks Against Future Botnets

While domain seizures provide immediate relief, government officials and cybersecurity experts emphasize that long-term security requires addressing the root vulnerabilities that allow botnets to proliferate. Millions of outdated, unpatched Internet of Things devices remain connected to the public web, providing foreign threat actors with an endless supply of potential proxy nodes.

Defending the national digital ecosystem requires comprehensive hardware and network hardening:

  • Mandating modern cybersecurity standards for consumer and industrial smart devices, including requirements for automatic firmware updates and randomized default passwords.
  • Encouraging enterprise network administrators to implement zero-trust network architectures that verify every connection attempt regardless of geographical origin.
  • Deploying automated endpoint detection and response software across all municipal utilities, healthcare providers, and local government agencies.
  • Accelerating the retirement of legacy edge-routing hardware that has reached end-of-life support from original equipment manufacturers.

Unless device manufacturers and network operators secure vulnerable edge devices, foreign state actors will continue attempting to build automated scanning platforms to replace dismantled infrastructure.

The Justice Department’s successful seizure of the QScan and QTRouter platforms marks a critical victory in the defense of American digital infrastructure. By dismantling an automated hacking network that compromised NASA, the Federal Reserve, the United States Senate, and critical utilities across 130 countries, federal law enforcement has severed a vital intelligence pipeline used by China’s Ministry of State Security and the People’s Liberation Army. The takedown exposes the commercial contractor ecosystem in Nanjing that builds cyber weapons for foreign intelligence services, proving that the United States will use every legal and technical tool to protect its sensitive networks. As state-sponsored cyber warfare intensifies, proactive infrastructure disruptions and public-private intelligence partnerships will remain essential to securing the digital foundation of the global economy.

EDITORIAL TEAM
EDITORIAL TEAM
Al Mahmud Al Mamun leads the TechGolly editorial team. He served as Editor-in-Chief of a world-leading professional research Magazine. Rasel Hossain is supporting as Managing Editor. Our team is intercorporate with technologists, researchers, and technology writers. We have substantial expertise in Information Technology (IT), Artificial Intelligence (AI), and Embedded Technology.