The FBI Disabled Hacking Tools That Hid Behind Infected Routers
U.S. authorities seized three domains and disabled QScan and QTRouter, tools allegedly used by a China-linked group to scan targets and conceal attacks behind infected devices. The action disrupted the platforms, but did not arrest their operators or reveal the full impact of every reported intrusion.
U.S. authorities seized three internet domains and disabled two connected hacking platforms that allegedly helped China-linked operators scan for vulnerable systems and disguise attacks behind compromised routers and other devices. The Justice Department says QScan and QTRouter were used against government agencies and critical infrastructure from at least 2018.
The 30-second summary
- What happened? The Justice Department and FBI seized domains hard-coded into QScan and QTRouter, making both platforms inoperable.
- Why does it matter? The tools combined automated vulnerability scanning with a proxy network built from hacked internet-connected devices, helping attackers hide where intrusions originated.
- What is the catch? The public record does not show that every named target was breached, how much data was stolen, or how long the disruption will last. China denies sponsoring cyberattacks.
Key Number: An FBI affidavit says QScan processed more than two million scanning and exploitation tasks on a single day in 2024.
Two tools performed different jobs
According to the Justice Department’s August 26 announcement, QScan searched the internet for exposed systems, tried known exploits and infected vulnerable Internet of Things devices. Those devices could then join QTRouter, an obfuscation network that also used commercial proxy services and rented servers.
The result was a distributed relay system. An attack launched from China could appear to come from a compromised router near the victim or from ordinary VPN traffic elsewhere. That made malicious activity harder to separate from legitimate connections and complicated attribution.
Why three domain seizures were enough
The seized domains were embedded directly in the malware and used for communication and authentication. Redirecting control of them cut essential links that QScan and QTRouter needed to operate. A joint NSA and FBI warning also released detection indicators and advised organizations to update exposed devices, isolate critical systems from edge equipment and hunt for evidence of compromise.
The government attributes the platforms to a group it calls QTFY, allegedly employed by Nanjing Xinjiuwei Network Technology Company and serving customers that included China’s Ministry of State Security and military. Reuters reports that China’s embassy said it was unfamiliar with the specific case and that Beijing opposes cyberattacks.
A broad victim and target list
Authorities named NASA, the Federal Reserve, the departments of Justice, Energy, and Health and Human Services, the National Institutes of Health, and the U.S. Senate in the court record. Hospitals, power companies, telecom providers, financial institutions and defence contractors were also targeted. The disclosure follows earlier evidence that cyberattacks had reached water-system controls in several U.S. states, although the operations are not presented as the same campaign.
Before we overstate the result
The seizure disabled infrastructure, not the people or expertise behind it. No individual charges were announced. WIRED’s reporting says the activity appeared focused mainly on espionage, but the attackers had changed relay methods before and are expected to rebuild. The filings also distinguish successful intrusions from unsuccessful attempts, so the list of targets should not be read as a list of equally compromised networks.
What defenders can do now
The technical advisory gives network operators indicators to search for, but the wider lesson is operational: internet-facing routers, VPN gateways and other edge devices can become both entry points and cover for attacks on somebody else. Patching them, separating them from sensitive systems and watching unusual outbound connections matter even when the device itself stores little valuable data.
Verified topics and entities
Sources and citations4 sources
External references used to support the reporting in this article.
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers
- NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity
- US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate
- FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
Published by
NewTqnia Technology Policy Desk
An institutional editorial team within NewTqnia