Product1 distinct publisher2 min readPublished
A court order killed two Chinese contractor hacking platforms because their command domains were hard-coded into the malware. The pivot hardware they infected is still nobody's asset.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The seizure worked because of a build defect on the attacker's side. qtproxy.xyz, qt-proxy.org and qt-team.com were hard-coded into both QScan and QTRouter, and the malware needed them for communication and authentication, so removing the domains left both tools inoperable [14][15]. That is a coding choice, not a capability loss, and the Justice Department's own wording is that the crackdown "should free" the affected IoT devices [16], a forecast about hardware nobody has inspected.
The throughput is the number worth keeping. On a single day in 2024, according to the FBI, QScan processed over two million scanning and penetration testing tasks [9], which works out to roughly 23 per second sustained across the full 24 hours [1]. The library behind it held more than 200 proof-of-concept exploits written in Python and was described as designed for large-scale employment [8]. None of that is research. It is a sweep of known holes at industrial volume, and it explains the target selection: cheap network hardware is abundant, findable and unowned.
The devices were transport. QTRouter mixed the infected hardware with commercial proxies and virtual private servers to conceal that the operators were in China, routing traffic through a rotating set of addresses [10][11]. Routers, security cameras and smart appliances end up on the critical path [4] not because anything valuable sits on them, but because the address in front of a federal service has to look ordinary.
What survives a domain seizure is the org chart. The affidavit says QTFY includes former People's Liberation Army members who use those relationships to obtain contracts and subcontracts supporting offensive cyber operations [5]. Federal agents say a Chinese company, Nanjing Xinjiuwei Network Technology Company, employs the group and has business relationships with the Ministry of State Security [6], and investigators say QTFY sold its hacking services to paying customers including the MSS and the PLA [12]. A contractor with a customer list treats three lost domains as a cost of doing business. The FBI's 36-page advisory, with indicators of compromise and a target list running through defense, telecommunications and higher education [17], is the part of this that outlives the takedown.
Ranked by verification strength, evidence, and original report placement.
On Wednesday the Justice Department and the FBI announced they had secured a court order to shut down three internet domains linked to the hacking operations.
The US uncovered the operation while investigating a China-based group dubbed QTFY that has been developing hacking tools since 2018.
Victims included NASA, the Department of Energy, the Federal Reserve and the Department of Justice, among others.
The hijacked IoT network included routers, security cameras and smart appliances.
A US affidavit used to obtain the court order states that QTFY actors include former members of China's People's Liberation Army and that they use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations.
Federal agents claim a Chinese company, Nanjing Xinjiuwei Network Technology Company, has been employing the QTFY group and has business relationships with China's Ministry of State Security.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Court-record detail, single publisher
The technical and attribution detail is unusually concrete for a takedown story - a court order, a quoted affidavit, named seized domains, a named employer company, a specific Ivanti Cloud Services Appliance zero-day campaign, and a 36-page FBI advisory with indicators of compromise. But every fact in the cluster is filtered through one outlet's reading of government statements, with no independent corroboration, no CVE identifier, no response from the accused parties, and no post-seizure verification of remediation.
Large real footprint, unmeasured cleanup
Operational reality is well established on the attacker side: thousands of IoT devices enrolled, over two million scanning and penetration-testing tasks in one day, breaches at NASA, the Department of Energy, the Federal Reserve and the DOJ, plus defense, telecom and higher-education targeting. On the defender side the observable action is the domain seizure and the FBI advisory; how many organizations have actually run the IOCs or cleaned devices is not reported.
Takedown framed as closure it may not be
Slightly overstated. The reporting faithfully relays DOJ's claim that hard-coded domains made QScan and QTRouter 'inoperable' and that the crackdown 'should free' infected devices, which reads as case-closed; yet the FBI simultaneously published indicators of compromise for organizations to check themselves, and nothing in the cluster measures residual compromise, patch status of the Ivanti appliance, or re-infection risk if the operators re-point their malware. Attribution language is also carried from an adversarial affidavit without any rebuttal.
Government-sourced enforcement narrative
Nearly all substance originates with the parties announcing their own enforcement win: DOJ and FBI statements plus an affidavit written to obtain the order. Those actors have a clear interest in presenting the operation as identified, attributed and neutralized. No countervailing voice - Chinese government, Nanjing Xinjiuwei, Ivanti, or an independent researcher - appears in the cluster to test the claims, and the single publisher is a consumer-technology outlet relaying the announcement rather than auditing it.
Specific but uncorroborated
Confidence is moderate: the underlying event (a court-ordered domain seizure with a published FBI advisory) is highly likely to be accurate and is the kind of fact that would be quickly contradicted if wrong, and the technical specifics are unusually granular. It is held down by the single-publisher cluster, the absence of any independent or opposing source, missing identifiers such as the Ivanti CVE, and an unverified remediation outcome.
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026