US seizes domains for Chinese QScan and QTRouter hacking tools | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The Department of Justice and FBI seized domains powering QScan and QTRouter, hacking tools linked to a Chinese state-sponsored group. The action, announced today, followed court authorisation and targeted infrastructure the department says was used against US critical infrastructure and other sensitive networks.

Court documents unsealed in the Southern District of California identify the group behind the platforms as QTFY, a People’s Republic of China state-sponsored operation employed by Nanjing Xinjiuwei Network Technology Company.

The filings name seven victims of QTFY intrusion activity: the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate.

Attorney General Todd Blanche commented: “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.

“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”

How QScan and QTRouter worked together

According to the court documents, QTFY sold computer hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. Those services centred on two linked tools.

QScan scanned the internet and automatically infected thousands of IoT devices worldwide. Once compromised, those devices were folded into QTRouter, a network QTFY controlled directly. QTRouter combined three sources of infrastructure: the IoT devices that QScan had compromised, commercial proxy service devices, and leased virtual private servers.

The department describes QTRouter as an “obfuscation network,” meaning it let QTFY and other malicious actors conceal the PRC origin of their intrusion activity. Traffic routed through compromised devices outside China, and in some cases through machines local to the target itself, so the malicious communications could appear to come from anywhere but Beijing.

FBI Director Kash Patel described the seizure as the disruption of “a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure.” He said the tools “were used by PRC cyber actors to hide the origin of their attacks,” and credited FBI San Diego, the FBI Cyber Division, and Justice Department partners with seizing the infrastructure and shutting the platforms down.

The seizures worked because the domains in question were hard-coded into both the QScan and QTRouter malware. Both tools depended on those domains for essential functions, including communication back to operators and authentication between infected devices. Removing that infrastructure from QTFY’s control left the malware unable to function, according to the department.

Assistant Attorney General for National Security John A. Eisenberg said the seizures “deny PRC-linked hackers access to tools they use to mount online attacks against our Nation’s critical infrastructure.” He called the operation evidence of “the Justice Department’s steadfast commitment to going on the offensive against cyber threats to national security.”

Part of a longer pattern of disruptions

Today’s action extends a run of court-authorised technical operations over the past few years that the department has taken against PRC-linked hacking groups:

  • 2025: The FBI removed PlugX surveillance malware from more than 4,000 US computers that had been infected by the PRC-sponsored group Mustang Panda.
  • 2024: The bureau disabled a botnet made up of hundreds of thousands of infected IoT devices that the PRC-sponsored group Flax Typhoon had been supplying to customers within the Chinese government.
  • 2023: The FBI disrupted a separate botnet that the PRC-sponsored group Volt Typhoon used to hide its exploitation of critical infrastructure in the United States and abroad.

FBI San Diego Special Agent in Charge Mark Remily said that the field office “will continue to identify, disrupt, and impose costs on our cyber adversaries” through what he called complex investigations, aggressive technical operations, and strong partnerships. Remily said the bureau remains “committed to dismantling the tools behind these state-sponsored crimes and protecting the American people from malicious cyber activity.”

The QTFY disruption arrived alongside two other releases. The FBI and National Security Agency published a cybersecurity advisory listing indicators of compromise associated with QTFY, drawn from analysis of activity the two agencies trace back to at least 2018.

Separately, Lumen Technologies’ threat intelligence unit – Black Lotus Labs – published its own account of QTFY’s tactics, techniques, and procedures, describing what it called a China-nexus state enablement model.

The seized domains disabled QScan and QTRouter by cutting off communication and authentication functions the malware needed to operate, but it does not disclose how many devices were part of the QTRouter network at the time of seizure, nor does it specify how long QTFY had operated the platforms before the disruption, beyond the FBI and NSA’s advisory referencing activity dating to 2018.

The court filings also do not detail the scale or duration of intrusions against the seven named victim organisations, including what data, if any, attackers accessed at NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, or the Senate.

QScan’s IoT-scanning function means exposed, poorly secured IoT devices remain the entry point that feeds the wider obfuscation network. Security teams reviewing perimeter exposure can cross-reference the FBI and NSA’s published indicators of compromise against device logs, particularly for IoT hardware with default or weak credentials, since that is the class of equipment QTFY’s tooling was built to absorb into QTRouter.

See also: Satellite IoT connections forecast to hit 197.7M by 2035

Banner for IoT Tech Expo by TechEx events.

Want to learn more about the IoT from industry leaders? Check out IoT Tech Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including AI & Big Data Expo and the Cyber Security Expo. Click here for more information.

Telecoms is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.



Click Here For The Original Source.

——————————————————–

..........

.

.