FBI and DOJ Seize QScan and QTRouter, China-Linked Tools Used Against NASA and the Senate
US authorities seized the domains behind QScan and QTRouter, two hacking platforms the Justice Department ties to the China-based group QTFY. Officials say the tools helped hide intrusions at NASA, the Federal Reserve, the Senate, and other federal networks. Here is what defenders should verify.
WASHINGTON. The Justice Department and FBI have seized the internet domains that ran two China-linked hacking platforms, QScan and QTRouter, which federal prosecutors say were used to hide cyberattacks against some of the U.S. government's most sensitive networks, including NASA, the Federal Reserve, the Department of Justice, the Department of Energy, and the U.S. Senate.
In court documents unsealed in the Southern District of California on Aug. 26, 2026, the government attributed the two tools to a People's Republic of China (PRC) state-sponsored group it calls QTFY, which it says is employed by a China-based firm, Nanjing Xinjiuwei Network Technology Company. According to a joint FBI and National Security Agency advisory published the same day, QTFY's activity traces back at least eight years, to 2018. And because the seized domains were hard-coded into both tools and used for core functions such as communication and authentication, the Justice Department says the seizures made QScan and QTRouter inoperable.
This is a disclosure story, not a how-to. What follows is what the government actually announced, why the "obfuscation network" framing matters more than the victim list, and the specific things a federal or critical-infrastructure security team should verify this week. The operational details of how the tools work belong in the government's advisory, and that is where defenders should pull them from.
What the Government Actually Seized
The action is a domain seizure, not an indictment. The Justice Department and FBI obtained court-authorized warrants and took control of the domains that both tools were built to call home. The Record reported that three domains were seized: qtproxy.xyz, qt-proxy.org, and qt-team.com. No individual operators were named or charged in the announcement, and the government did not describe QTFY members being arrested. This was infrastructure disruption: take the hard-coded domains, and the platforms lose the ability to communicate and authenticate.
The seizure did not arrive alone. The FBI and NSA published a joint cybersecurity advisory carrying indicators of compromise (IOCs) drawn from analysis of QTFY activity going back to at least 2018, and Lumen Technologies' Black Lotus Labs released a companion writeup of the group's tradecraft. That pairing, a takedown plus published indicators, is the part defenders can act on: the domains are gone, but the historical footprint on a victim network does not disappear because a domain was seized.
The government was blunt about the intent behind the tools. "These tools were used by PRC cyber actors to hide the origin of their attacks," said FBI Director Kash Patel in the Justice Department's announcement. Attorney General Todd Blanche framed it as one in a sequence, calling it "the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People's Republic of China."
Who QTFY Is, and Who Paid for the Access
The most consequential claim in the court filings is about the business model. According to the Justice Department, QTFY offered computer hacking services to paying customers, and among those customers were the PRC's Ministry of State Security (MSS) and the People's Liberation Army. In other words, the government is describing a contractor: a private company, Nanjing Xinjiuwei Network Technology Company, selling access and obfuscation to a state intelligence service.
Court documents cited by the government go further, stating that Nanjing Xinjiuwei received payments from the MSS and that the group's ranks included former members of the People's Liberation Army. Those are the government's allegations, laid out in a seizure affidavit rather than tested at trial, and they should be read as such. But they fit a pattern U.S. investigators have described repeatedly: state-directed intrusion work outsourced to nominally commercial Chinese firms, which lets the state buy capability and deniability at the same time. This is the "hacker-for-hire" contractor model that has become central to how the U.S. characterizes Chinese advanced persistent threat activity.
The reach the government describes is broad. CNBC, The Register, and others reported that beyond the named federal agencies, the affidavit and related reporting point to targeting across hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The Justice Department itself named only federal victims: NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. No specific non-federal victim organization has been named publicly, so treat the wider sector list as characterized scope rather than a confirmed roster.
Why the "Obfuscation Network" Framing Is the Real Story
The victim list is what makes headlines, but the mechanism is what matters to a defender. The Justice Department describes QTRouter as an "obfuscation network," and that phrase carries the whole point of the operation. The tools' job was not to break down doors so much as to make the people breaking down doors invisible.
Here is the high-level version, which is as far as this piece will go: the government says QScan roped compromised internet-connected devices into a pool, and QTRouter combined that pool with commercial proxy services and rented servers to route intrusion traffic. The effect the government describes is that malicious activity looked like it came from ordinary machines outside China, sometimes machines sitting close to the target's own network. Attribution and detection both get harder when the traffic hitting your perimeter looks domestic and mundane.
For a security team, that reframes the takedown. Seizing the domains ends this particular obfuscation layer, but it does not undo eight years of traffic that already looked benign at the time. If your organization is in one of the targeted categories, the relevant question is not "were we protected against QScan," but "would we have noticed traffic that was deliberately shaped to look like it came from a normal, local source." That is a hunting question, not a patching one, and it is why the published indicators matter more than the domain seizure.
It is also why context helps. This is the same contractor-and-proxy pattern security teams have been tracking across a string of China-nexus disclosures, from the Cisco Talos reporting on UAT-10147 to the FBI's own earlier classification of a China-linked breach of surveillance systems as a "major cyber incident." The tooling changes; the model of buying access, hiding origin, and staying resident does not.
What Is Confirmed, and What Isn't
The confirmed facts are the ones the government stated directly. The Justice Department and FBI seized domains hard-coded into QScan and QTRouter; they attributed both tools to QTFY, tied to Nanjing Xinjiuwei Network Technology Company; they named seven federal victims; and they said the seizures rendered the tools inoperable. The FBI-NSA advisory dates the activity to at least 2018, and the court filings allege MSS payments to the company.
Several things being discussed around this story are not established, and it is worth stating them plainly:
The government has not specified what data classes were stolen from the named agencies, or the scope of any exfiltration. No individual operators have been indicted or arrested as part of this announcement; it is a seizure action. There is no stated allied or international coordination in the Justice Department's release, unlike some prior operations. The department lists Volt Typhoon, Flax Typhoon, and Mustang Panda as separate, earlier PRC operations it disrupted, and does not claim QTFY overlaps with those groups, with Salt Typhoon, or with APT41, so any equivalence drawn elsewhere is inference, not government attribution. And, again, no non-federal victim organization has been named. Weigh follow-on reporting that fills these gaps against what the primary documents actually say.
What Federal and Critical-Infrastructure Teams Should Do Now
The useful response to a disclosure like this is not to fear a tool that is now inoperable. It is to use the published indicators to check whether the tool, or the actors behind it, ever touched your network. The domains are dead; the dwell time is the risk. Here is the priority order.
● Defender Action Checklist After the QTFY seizure, what federal and critical-infrastructure IT teams should verify, in priority order. |
1 → Pull the Published Indicators Ingest the QTFY IOCs from the FBI-NSA joint advisory (IC3) and Black Lotus Labs before anything else. They are the concrete artifacts to hunt with. |
2 → Hunt Historic Telemetry Search stored network, DNS, and endpoint logs against those indicators across the long window the advisory covers, back toward 2018, not just recent data. |
3 → Run an Assume-Breach Review Long-dwell access is the threat model here. Look for persistence and quiet residency, not just perimeter alerts that would have fired at the time. |
4 → Coordinate With CISA Report findings and pull guidance through CISA and your sector ISAC rather than working the problem in isolation. |
● If an Indicator Matches Treat it as an active intrusion, not a curiosity. Open incident response, preserve evidence, and notify per your legal and regulatory obligations. |
Source: DOJ and FBI announcement, Aug. 26, 2026, and the FBI-NSA joint advisory. Diagram: The CyberSignal. |
A defender-action checklist for the QTFY seizure, in priority order. Source: DOJ, FBI, and the FBI-NSA joint advisory.
Concretely: pull the QScan and QTRouter indicators the FBI and NSA published and load them into your hunting and detection tooling first. Search your stored telemetry against them across the full window the advisory covers, because the exposure predates the takedown by years. Run the review on an assume-breach footing, since the whole design of an obfuscation network is to look normal in real time, which means the evidence you need is historical, not live. Route what you find through CISA and your sector information-sharing group. And if an indicator matches, do not file it as trivia: assume a foothold and open an incident. For agencies and operators of essential services, this is squarely a matter of critical-infrastructure security hygiene, and it is the kind of long-dwell review that only gets done if someone owns it this week.
My read: the seizure is a real win, but the inoperable-tools headline is the least important thing here, and treating it as the finish line would be a mistake. This is an assessment, not a government finding: the durable value of this operation is the eight-year footprint the advisory exposes, not the dead domains. An actor described as resident on federal networks since 2018, hiding behind traffic engineered to look local, is a dwell-time problem, and dwell-time problems are solved by hunting old logs, not by celebrating a takedown. The organizations that get value from this week are the ones that treat the published indicators as a reason to go looking, and the ones that assume the absence of an alert over the past several years proves nothing. The government did the disruption. The retrospective hunt is on you.
Primary Documents
- U.S. Department of Justice: Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers (Aug. 26, 2026)
- FBI and NSA joint cybersecurity advisory: QTFY indicators of compromise (Aug. 26, 2026)
- The Register: FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
- TechCrunch: US seizes domains of Chinese botnet used to hack NASA, Justice Department and the Senate
- The Hacker News: FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
- WIRED: FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure