U.S. Seizes 3 Domains Powering China-Linked QScan, QTRouter Hacks Since 2018
Updated
Updated · Fox News · Aug 28
U.S. Seizes 3 Domains Powering China-Linked QScan, QTRouter Hacks Since 2018
3 articles · Updated · Fox News · Aug 28
Summary
Three seized domains knocked QScan and QTRouter offline after U.S. authorities said the tools had supported intrusion attempts against NASA, the Federal Reserve, DOJ and the U.S. Senate since 2018.
The Justice Department said China-linked group QTFY used QScan to scan for flaws and infect thousands of internet-connected devices, then routed attacks through QTRouter to mask their origin.
Court filings tied QTFY to Nanjing Xinjiuwei Network Technology and alleged it sold hacking services to China’s Ministry of State Security and the PLA; the Chinese Embassy denied the accusations.
The takedown fits a broader U.S. campaign against China-linked infrastructure, following PlugX removals from 4,000-plus computers in 2025 and earlier botnet disruptions tied to Flax and Volt Typhoon.
Did seizing QTFY's hacking domains truly eliminate the threat, or simply force a dangerous cyber adversary deeper underground?
How did a private foreign tech firm silently infiltrate America's most secure federal agencies and critical hospitals?
With military-grade malware targeting vulnerable health systems, what hidden dangers still lurk inside our critical infrastructure?
The August 2026 QTFY Takedown: How U.S. Authorities Disrupted China’s AI-Driven Cyber-Espionage Network Targeting Federal Infrastructure
Overview
In August 2026, the DOJ and FBI took down the QTFY hacking group by seizing their QScan and QTRouter platforms, cutting off their control over a vast network of compromised devices. QTFY, supported by specialized Chinese contractors, had used automated tools to scan for and exploit vulnerabilities in SOHO routers and IoT devices, making their attacks hard to trace and allowing them to breach sensitive U.S. institutions like NASA and the Senate. This led to major national security risks, as attackers harvested data globally. The incident highlights how decentralized, AI-driven cyber operations and poor device oversight leave critical infrastructure exposed to persistent threats.