PlatformsQScan (scanner)
QTRouter (obfuscation)
OperatorQTFY
Nanjing Xinjiuwei
Network Technology
CustomersMinistry of State
Security (MSS)
People's Liberation
Army (PLA)
VictimsNASA, Federal Reserve
DOE, DOJ, HHS
NIH, US Senate
Seized domainsqtproxy[.]xyz
qt-proxy[.]org
qt-team[.]com
What happened
The Department of Justice and FBI announced court-authorized domain seizures on August 26, 2026, targeting three domains hard-coded into the QScan and QTRouter malware platforms. Court documents unsealed in the Southern District of California describe QTFY as a People's Republic of China state-sponsored group whose members are employed by Nanjing Xinjiuwei Network Technology Company and who built and operated the two platforms as a commercial hacking service sold to China's Ministry of State Security, the People's Liberation Army, and other customers. QScan is a scanning and exploitation tool designed to automatically identify vulnerable internet-of-things devices and compromise them at scale. The court affidavit notes QScan processed more than two million scanning and exploitation tasks on a single day in 2024. Compromised devices were then folded into QTRouter, an obfuscation network composed of compromised IoT devices, commercial proxy services, and leased virtual private servers. QTRouter's purpose was to route QTFY and customer attack traffic through systems outside China, including devices located on networks adjacent to or within target organizations, making the traffic appear to originate from legitimate systems rather than from Chinese infrastructure. The DOJ confirmed that QTFY's victims include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The three seized domains, qtproxy.xyz, qt-proxy.org, and qt-team.com, were hard-coded into both QScan and QTRouter and used for essential functions including authentication and command-and-control communication. Because those functions depended on the seized domains, the court-authorized seizures rendered QScan and QTRouter immediately inoperable. This is the latest in a series of US government operations against China-linked cyber infrastructure following the 2025 PlugX takedown that removed the malware from more than 4,000 US computers and the prior Flax Typhoon IoT botnet disruption.
Why it matters
The QScan and QTRouter seizure disrupts an active operational capability that was generating revenue for a China-state-linked company by selling hacking services to Chinese intelligence and military agencies. The victim list is not the result of a broad campaign that happened to reach those organizations. The DOJ affidavit treats NASA, the Federal Reserve, DOE, and the US Senate as specific targets, not collateral exposure. QTRouter's design, routing traffic through compromised IoT devices local to target networks, was specifically intended to defeat attribution and network-based blocking by making the attacker's traffic indistinguishable from trusted internal or local network traffic. Organizations with critical infrastructure may have seen QTRouter-routed traffic appear as originating from their own networks or from trusted adjacent systems and treated it as legitimate. The seizure disrupts current campaigns but does not retroactively close any access QTFY or its customers had already established through these platforms.
Don't miss
The DOJ's description of QTRouter as routing traffic through devices on networks local to the target deserves specific attention for threat hunters. An organization that was targeted through QTRouter may have logs showing internal-looking or geographically local traffic associated with reconnaissance, lateral movement, or data exfiltration that did not trigger external threat detection because the source appeared to be a nearby or internal address. The three seized domains, qtproxy.xyz, qt-proxy.org, and qt-team.com, should be searched across historical DNS and network logs as indicators of QScan and QTRouter activity. Any historical outbound DNS queries or connections to those domains from internal systems indicate potential compromise of those systems by QScan or contact with QTRouter infrastructure. The FBI has not published a comprehensive indicator-of-compromise list accompanying this seizure, but the seized domains are the most specific indicator available from the public court documents.
Potential actions
- Search historical DNS query logs and network flow data for any connections to qtproxy.xyz, qt-proxy.org, and qt-team.com originating from systems in your environment. These three domains were hard-coded into QScan and QTRouter for authentication and C2. Internal systems connecting to these domains were either compromised by QScan or were in contact with QTRouter infrastructure. Any such connections warrant incident investigation regardless of when they occurred.
- Review historical network traffic for anomalous activity appearing to originate from IoT devices, home routers, or other edge devices on networks local to your environment, particularly for traffic destined at sensitive internal systems. QTRouter's design specifically used compromised local-network devices to route attack traffic, meaning successful QTRouter-routed intrusions would appear in logs as coming from network-adjacent addresses rather than from external Chinese infrastructure.
The Sip
QScan compromised thousands of IoT devices automatically. QTRouter routed attack traffic through devices local to the target, so it looked like it came from inside. The DOJ seized the three hard-coded domains and both platforms stopped working immediately. Check your DNS and network logs for those three domains. Any hits warrant investigation.