Independent reporting on American politics
STATE BEACON

DOJ and FBI seize QScan, QTRouter domains, disabling China‑state‑sponsored botnet

On 26 August 2026 the Justice Department and FBI announced a court‑authorized seizure of the QScan and QTRouter domains, cutting off the command‑and‑control infrastructure of a botnet linked to a Chinese state‑sponsored hacking group.

By State Beacon·
Seized server rack containing the QScan and QTRouter command‑and‑control hardware in an FBI evidence room

The U.S. Department of Justice and the Federal Bureau of Investigation announced on 26 August 2026 that they had seized the Internet domains used by the QScan and QTRouter malware platforms, rendering both systems inoperable.

Operation details

The press release from the Justice Department states that the court‑authorized seizures were intended to "deny malicious cyber actors access to two complementary hacking platforms known as ‘QScan’ and ‘QTRouter,’" which had been used to target U.S. critical‑infrastructure and other sensitive networks. Attorney General Todd Blanche was quoted as saying the action was "a step to stop state‑sponsored malicious hacking." The seizure was carried out jointly by DOJ and FBI agents, and the domains were taken down under a court order filed on the same day.

Malware platform functions

According to the DOJ release, QScan is a scanning tool that automatically infects thousands of Internet‑of‑Things (IoT) devices worldwide. Once compromised, those devices are added to the QTRouter network, which aggregates the infected endpoints, commercial proxy services, and leased virtual private servers into a single botnet. The seized domains were hard‑coded into both pieces of malware and were used for essential tasks such as communication and authentication. By removing the domains, the government effectively broke the command‑and‑control channel, making the platforms inoperable.

Victims and attribution

The Justice Department identified a list of high‑profile U.S. agencies that had been compromised by the QTFY‑operated botnet. These include the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The operation also attributes the hacking activity to QTFY, a PRC‑state‑sponsored hacking group that offers computer‑hacking services to customers such as the Ministry of State Security and the People’s Liberation Army. The Chinese company behind QTFY is identified as Nanjing Xinjiuwei Network Technology Company.

U.S. agencies listed as victims of the QTFY botnet
Agency Sector
National Aeronautics and Space Administration (NASA) Aerospace / Research
Federal Reserve Financial Services
Department of Energy Energy / Utilities
Department of Justice Law Enforcement
Department of Health and Human Services Health Care
National Institutes of Health Medical Research
U.S. Senate Legislature
Source: U.S. Department of Justice press release, 26 August 2026

Implications and open questions

Disabling the QScan and QTRouter domains cuts off the primary communication pathway for the botnet, which the DOJ describes as a "global botnet used to target U.S. critical infrastructure." The immediate effect is the loss of control for the operators of QTFY, potentially preventing further malicious activity that relied on the compromised IoT devices. However, the press release does not disclose how many devices remain compromised after the seizure, nor does it indicate whether the botnet can be reconstituted using alternative domains or infrastructure.

Law‑enforcement officials have not provided a timeline for any follow‑up actions, such as indictments of individuals associated with QTFY or civil penalties against the Chinese corporate sponsor. The statement also leaves unanswered whether the seizure will have a measurable impact on the broader ecosystem of state‑sponsored cyber operations originating from the People’s Republic of China.

Timeline

  • 26 August 2026 – DOJ and FBI announce court‑authorized seizure of the QScan and QTRouter domains, rendering the platforms inoperable.

Future reporting will track any additional disclosures from the Justice Department, including possible indictments, remediation guidance for affected U.S. agencies, and any evidence of residual botnet activity.