HackMyIP
← Back to News
2026-08-26 The Record

US DoJ Takedown Disables Chinese QScan and QTRouter Hacking Tools

APTMalwareIncident Response

The U.S. Department of Justice announced on Wednesday the takedown of two Chinese state-sponsored hacking platforms, "QScan" and "QTRouter," operated by Nanjing Xinjiuwei Network Technology Company on behalf of China's Ministry of State Security (MSS) and the People's Liberation Army (PLA). The seizure disabled both tools because their core domains were hard-coded into the platforms for communication and authentication, rendering them immediately inoperable. According to an unsealed affidavit, the infrastructure had been used since at least 2018 to breach multiple federal agencies, including the Federal Reserve, the Department of Energy, the Department of Justice itself, the U.S. Senate, and NASA, as well as the Department of Health and Human Services and the National Institutes of Health.

QScan functioned as a scanning platform that autonomously crawled the internet to identify and infect vulnerable IoT devices such as home routers and security cameras, feeding thousands of compromised machines into a global botnet. QTRouter acted as an obfuscation layer, routing malicious traffic through infected endpoints so that attacks appeared to originate from local or unrelated sources, complicating attribution efforts. The combined toolset allowed a state-sponsored group tracked as "QTFY" to mask its operations across more than 130 countries while targeting U.S. critical infrastructure, telecommunications providers, power companies, financial institutions, defense contractors, and hospitals. Defenders investigating suspicious traffic can use a VPN/proxy detector to flag connections routed through known anonymizing nodes, and a port scanner to identify exposed IoT services that may have been swept up in QScan-style mass exploitation.

Investigators traced the operation back to a 2019 intrusion attempt against NASA, in which QTFY exploited a vulnerability in Pulse Secure VPN appliances. Analysts followed the IP addresses and email accounts used in that attack to locations tied to Nanjing Xinjiuwei. FBI Assistant Director Brett Leatherman said the company "sells stolen data and hacking services to Chinese military and intelligence agencies" and operates "within a complex network of hackers-for-hire and government clients in China," adding that QTFY also served unspecified customers outside of MSS and PLA control. The affidavit confirms the investigation continued through a 2024 intrusion against the U.S. Senate, though it does not specify which members or committees were affected. Researchers examining domains linked to the seized infrastructure can perform a WHOIS lookup to verify whether a registrar action has been taken in connection with the takedown.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Port Scanner →DNS Leak Test →Privacy Checkup →

Related Guides

Learn the background behind this story:

Signs your router is hacked →Wi-Fi security checklist →How to find your router's IP →