Security1 publisher2 min readPublished
OmniTrust's Sequino says the QScan takedown leaves the hijackable edge devices in place
The DOJ and FBI pulled down two platforms a commentary attributes to Chinese state-sponsored operators. The same piece argues the routers and gateways recruited into those relays are still deployed and still weakly governed.
The Watch · Security desk

What happened
- The takedown leaves the hardware behind the relays as it was: attackers had hijacked large numbers of routers, gateways and other connected edge devices and turned them into anonymous relays.
- Sequino argues the disruption does not fix the underlying weaknesses in the environments those relays were used to probe.
- His prescription is a device lifecycle program built on product blueprints, SBOMs and CBOMs for supply-chain provenance, and hardware-backed enforcement such as secure boot and authenticated updates.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A hijacked gateway in a water system or a hospital sits next to processes that move physical things, so the failure class there includes physical damage and risk to human life, not just data loss and recovery cost.
- constraint A seizure re-provisions nothing, and the devices inside factories, hospitals, airports and utilities can only be redesigned by their manufacturers and operators.
- cost Secure boot, signed firmware and hardware-backed identity are decided at design and provisioning, so closing this gap is a purchasing and refresh expense for asset owners rather than a patch window.
Edge gear gets recruited because it is hard to account for. The commentary lists the properties that make it attractive to state-sponsored operators: widely deployed, often long-lived, and difficult to inventory, authenticate, patch or replace [8]. Airports, hospitals, water systems, power infrastructure and industrial plants all run connected devices that directly influence real-world operations [7]. An enterprise breach usually costs data, downtime and recovery; in operational technology the consequences can include physical damage and risk to human life [6].
On the takedown itself the record here is thin. The column does not date the seizure, count the hijacked devices or name a victim [14]. It is an SC Media Perspectives column by David Sequino, co-founder and chief executive of OmniTrust [9]. What it asserts about the operation is that the DOJ and FBI removed QScan and QTRouter, platforms used by Chinese state-sponsored hackers [1], and that the seizure took away infrastructure the adversaries were using to hide activity and probe targets, including critical infrastructure [2].
The structural claim does not depend on those missing details. Attackers had hijacked large numbers of routers, gateways and other connected edge devices and turned them into anonymous relays [3]. Seizing the control platform does not alter the devices. "Law enforcement can disrupt one network. If those devices remain poorly protected, adversaries can build another," Sequino wrote [4].
His remedy is a lifecycle program: product blueprints defining authorized identities, keys, software layers and manufacturing environments; SBOMs and CBOMs for supply-chain provenance; and hardware-backed enforcement through secure boot, signed software, hardware-backed identity and authenticated updates [10]. Most of that is set during design, provisioning and manufacturing, which is procurement work with a hardware refresh attached [16]. It is also the category OmniTrust sells into [9]. The narrower technical point in the column applies beyond the pitch: a certificate can establish identity, and it does not prove that firmware is authentic, that a device was provisioned correctly, that keys remain protected, or that the system is still trustworthy years later [11].
For an operator with OT in scope, the usable part of this is an inventory question. Which gateways face the internet, who holds their keys, and will they accept unsigned firmware [10]. Sequino's own framing of trust starts at product design and runs through enrollment, deployment, updates, field service and retirement [13]. No takedown accelerates that schedule. "Because the next proxy network will come," he wrote [15].
What to watch
- A DOJ or FBI affidavit naming device models and counts would turn this argument into an actual remediation list for OT owners.
- A successor proxy network recruiting from the same router and gateway population would test the column's central prediction.
- Any procurement rule that makes hardware-backed identity and authenticated updates a purchase condition for OT edge gear.