The FBI and U.S. Department of Justice announced on August 26 that court-authorized domain seizures disabled QScan and QTRouter, two platforms allegedly used by the China-linked QTFY group for cyber espionage against U.S. critical infrastructure and sensitive government networks. The department said the hard-coded domains supported essential communication and authentication, making both platforms inoperable after their seizure.

Court documents attribute QTFY to China-based Nanjing Xinjiuwei Network Technology Company and allege that it sold hacking services to customers including China’s Ministry of State Security and People’s Liberation Army. The Justice Department identified NASA, the Federal Reserve, the departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the U.S. Senate as victims of QTFY intrusion activity. Those claims are allegations described by U.S. authorities and court filings.

According to the Justice Department, QScan scanned for targets and automatically infected thousands of internet-connected devices worldwide. Compromised devices were then incorporated into QTRouter alongside commercial proxy devices and leased virtual private servers. This structure enabled operators to route malicious traffic through systems outside China, sometimes near a targeted network, obscuring the source of intrusion activity.

Lumen Technologies’ Black Lotus Labs independently described a broader service that connected QScan reconnaissance with Fast Labyrinth encrypted relays, QTRouter access devices, and a QTProxy node-management system. The researchers said telemetry showed overlap between QScan discoveries and later operational sessions directed at target organizations. The FBI and NSA also released an advisory based on QTFY activity observed since at least 2018.

The seizures targeted qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com, according to reporting on the unsealed affidavit. Because the domains were embedded in the platforms, authorities said the action cut operators off from core functions rather than merely removing public websites. The disruption follows earlier U.S. operations against PlugX infections and botnets associated with the China-linked Mustang Panda, Flax Typhoon, and Volt Typhoon activity clusters.

Network defenders should review the FBI and NSA advisory for published indicators, examine unusual outbound connections, and restrict unnecessary internet exposure of routers, firewalls, network-attached storage, and other edge devices. Organizations should also apply vendor updates, replace unsupported equipment, and avoid treating the takedown as proof that every compromised device or related access path has been remediated.