DOJ seized the domains behind QScan and QTRouter, platforms it says scanned the internet for vulnerable devices and hid malicious traffic, the latest in a series of FBI disruptions since 2023.
On Aug. 26, the Justice Department and FBI seized the domains behind two platforms: QScan, which scans the internet for vulnerable devices, and QTRouter, which reroutes malicious traffic through compromised devices to obscure its origin. Both are now inoperable, according to the DOJ press release.
Court documents identify the operator as QTFY, employed by the China-based Nanjing Xinjiuwei Network Technology Company. DOJ says the group sold network access to paying customers including China's Ministry of State Security and the People's Liberation Army.
The named U.S. targets include NASA, the Federal Reserve, the departments of Justice, Energy, and Health and Human Services, the National Institutes of Health, and the U.S. Senate. Additional alleged victims span hospitals, telecoms, power companies, financial institutions, and defense contractors, including four unnamed companies in the U.S. and South Korea.
A supporting affidavit says the infrastructure has been in continuous use since at least 2018, and that QScan recruited thousands of devices into the QTRouter network worldwide. The FBI's San Diego field office led the investigation.
DOJ said the action continues a string of similar disruptions: PlugX in 2025, Flax Typhoon in 2024, and Volt Typhoon in 2023. Officials have not said how long the intrusions lasted at any specific target or whether they caused damage.