Cyber Security News

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms linked to China, QScan and QTRouter. This court-authorized operation aims to disrupt attacks against U.S. critical infrastructure and sensitive government networks.

Unsealed court documents from the Southern District of California revealed that these platforms were operated by a state-sponsored group from the People’s Republic of China, identified as QTFY.

This group is allegedly affiliated with Nanjing Xinjiuwei Network Technology Company, a Chinese firm accused of providing offensive cyber services to clients including the Ministry of State Security and the People’s Liberation Army.

FBI Seizes China State-Sponsored Hacker Platforms

Investigators reported that QTFY’s hacking activities impacted various high-value U.S. targets, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate.

QScan and QTRouter were integral components of QTFY’s infrastructure-as-a-service model. QScan was responsible for scanning the internet and automatically compromising vulnerable Internet of Things (IoT) devices on a large scale.

Once infected, these devices were enrolled in QTRouter, which functioned as a network of compromised IoT hardware, commercial proxy services, and leased virtual private servers.

This infrastructure served as an obfuscation layer for QTFY and its customers. Instead of connecting directly from Chinese-controlled servers, attackers could route malicious traffic through compromised devices in other countries.

This method made it seem like the activity originated from legitimate systems outside China, potentially even from devices located near the victim’s environment.

This proxy-based architecture complicates incident response and attribution. Security teams may initially identify a seemingly local IP address, consumer router, or connected device as the source of suspicious traffic.

At the same time, the actual operator remains several layers removed. This model also allows threat actors to rapidly change their infrastructure, avoiding reliance on dedicated command-and-control servers.

The domain seizures were intended to turn off this ecosystem at a crucial moment. The seized domains were hard-coded into the QScan and QTRouter malware, which rely on them for communication and authentication.

By taking control of these domains, law enforcement rendered the malware platforms inoperable, preventing infected devices from continuing to support the QTFY-controlled network.

This operation follows earlier U.S. technical disruptions targeting PRC-linked botnets and malware. In 2025, the FBI removed PlugX surveillance malware from over 4,000 U.S. systems infected by Mustang Panda.

In 2024, authorities disrupted a large IoT botnet associated with Flax Typhoon, while a 2023 operation targeted infrastructure used by Volt Typhoon to conceal critical-infrastructure intrusions.

The FBI and the National Security Agency also issued a cybersecurity advisory outlining indicators of compromise associated with QTFY activity dating back to at least 2018.

Organizations are encouraged to review this advisory, investigate unusual outbound connections from IoT devices, rotate credentials, segment unmanaged devices, and promptly patch any internet-exposed equipment.

This seizure illustrates how disrupting domain-based infrastructure can impose significant operational challenges on state-backed threat actors, even when they rely on globally distributed, compromised devices rather than traditional malware command-and-control servers.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…

28 minutes ago

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…

31 minutes ago

TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices

TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an…

43 minutes ago

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine…

2 hours ago

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution…

2 hours ago

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ,…

2 hours ago