ProductNot yet confirmed elsewhere1 publisher2 min readPublished
DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory
A court order killed two Chinese contractor hacking platforms because their command domains were hard-coded into the malware. The pivot hardware they infected is still nobody's asset.
The Product Desk

What happened
- The Justice Department and FBI said Wednesday they had obtained a court order to shut down three domains used to run a China-based hacking operation.
- The government names NASA, the Department of Energy, the Federal Reserve and the Justice Department itself among the victims.
- One tool, QScan, automatically infected thousands of internet-connected devices worldwide and enrolled them in a controlled proxy network called QTRouter.
- In September 2024 the group used an Ivanti Cloud Services Appliance zero-day against several agencies and an unnamed US security device manufacturer.
- The FBI ties the group to eight years of activity, including vulnerability scanning and exploitation of VPN flaws to enter federal agencies.
Why it matters
- constraint An indicator-of-compromise list is only usable where something can be queried, and consumer-grade network hardware usually has no agent, no retained logs and no owner in the asset register.
- exposure A camera's risk is now set by what its network can reach and by who is buying access to it, which drags low-value hardware into procurement and vendor review.
- decision Security teams have to decide whether a takedown that killed the current binaries counts as remediation or as a window before the operators stand up new infrastructure.
- precedent Naming a corporate employer rather than pseudonymous handles builds the record for action against a company, its officers and anyone doing business with it.
The seizure worked because of a build defect on the attacker's side. qtproxy.xyz, qt-proxy.org and qt-team.com were hard-coded into both QScan and QTRouter, and the malware needed them for communication and authentication, so removing the domains left both tools inoperable [14][15]. That is a coding choice, not a capability loss, and the Justice Department's own wording is that the crackdown "should free" the affected IoT devices [19], a forecast about hardware nobody has inspected.
The throughput is the number worth keeping. On a single day in 2024, according to the FBI, QScan processed over two million scanning and penetration testing tasks [9], which works out to roughly 23 per second sustained across the full 24 hours [18]. The library behind it held more than 200 proof-of-concept exploits written in Python and was described as designed for large-scale employment [8]. None of that is research. It is a sweep of known holes at industrial volume, and it explains the target selection: cheap network hardware is abundant, findable and unowned.
The devices were transport. QTRouter mixed the infected hardware with commercial proxies and virtual private servers to conceal that the operators were in China, routing traffic through a rotating set of addresses [10][11]. Routers, security cameras and smart appliances end up on the critical path [4] not because anything valuable sits on them, but because the address in front of a federal service has to look ordinary.
What survives a domain seizure is the org chart. The affidavit says QTFY includes former People's Liberation Army members who use those relationships to obtain contracts and subcontracts supporting offensive cyber operations [5]. Federal agents say a Chinese company, Nanjing Xinjiuwei Network Technology Company, employs the group and has business relationships with the Ministry of State Security [6], and investigators say QTFY sold its hacking services to paying customers including the MSS and the PLA [12]. A contractor with a customer list treats three lost domains as a cost of doing business. The FBI's 36-page advisory, with indicators of compromise and a target list running through defense, telecommunications and higher education [16], is the part of this that outlives the takedown.
What to watch
- Whether the US identifies the "US security device manufacturer" breached through the Ivanti zero-day.
- Whether previously infected devices begin beaconing to replacement domains, which would show the seizure bought weeks rather than a shutdown.
- Whether indictments or sanctions follow against Nanjing Xinjiuwei Network Technology Company or named QTFY individuals.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence68
- Adoption71
- Hype gap+14
- Incentives62
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On Wednesday the Justice Department and the FBI announced they had secured a court order to shut down three internet domains linked to the hacking operations.
- [2]
The US uncovered the operation while investigating a China-based group dubbed QTFY that has been developing hacking tools since 2018.
- [3]
Victims included NASA, the Department of Energy, the Federal Reserve and the Department of Justice, among others.
- [4]
The hijacked IoT network included routers, security cameras and smart appliances.
- [5]
A US affidavit used to obtain the court order states that QTFY actors include former members of China's People's Liberation Army and that they use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations.
- [6]
Federal agents claim a Chinese company, Nanjing Xinjiuwei Network Technology Company, has been employing the QTFY group and has business relationships with China's Ministry of State Security.
- [7]
According to the Justice Department, QScan scans and automatically infects thousands of internet-of-things devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices.
- [8]
The FBI says QScan contains a database of over 200 proof-of-concept exploits written in Python and was designed for large-scale employment.
- [9]
The FBI says that on a single day in 2024, QScan processed over two million scanning and penetration testing tasks.
- [10]
QTRouter used commercial proxies and virtual private servers to mask that the hackers accessing the infected IoT devices were based in China.
- [11]
The affidavit says QTRouter hides a user's true IP address by routing the user's network traffic through various IP addresses.
- [12]
Federal investigators claim QTFY offered its computer hacking services to paying customers, including the PRC's Ministry of State Security and the People's Liberation Army.
- [13]
In September 2024, QTFY carried out intrusions against several government agencies and an unnamed US security device manufacturer by exploiting a zero-day vulnerability in the Ivanti Cloud Services Appliance.
- [14]
The Justice Department secured a court order to take over qtproxy.xyz, qt-proxy.org and qt-team.com.
- [15]
The Justice Department said the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, so the court-authorized seizures made QScan and QTRouter inoperable.
- [16]
The FBI issued a 36-page advisory about QTFY warning that its activities also targeted the defense, telecommunications and higher education sectors, and including indicators of compromise so organizations can determine whether they were affected.
- [17]
The FBI has connected QTFY to hacking efforts dating back eight years, including scanning for network vulnerabilities and exploiting VPN-related flaws to break into federal agencies.
- [18]
Two million scanning and penetration testing tasks in one day is about 23 tasks per second sustained over 24 hours.
- [19]
The report states the crackdown should free the affected IoT devices.
Sources
1 independent publisher whose own reporting we read for this story.
- pcmag.comUS: China Hijacked IoT Devices to Breach NASA, Federal Agencies | PCMag
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Edge Device Asset InventoryFollow
- State-Sponsored Cyber OperationsFollow
- Enterprise Appliance Zero-DaysFollow
- Cyber Mercenary ContractingFollow
- IoT and Edge Device BotnetsFollow
- Law Enforcement TakedownsFollow
Entities
- QTFYFollow
- QScanFollow
- QTRouterFollow
- Nanjing Xinjiuwei Network Technology CompanyFollow
- U.S. Department of JusticeFollow
- Federal Bureau of InvestigationFollow
- Ministry of State Security (PRC)Follow
- People's Liberation ArmyFollow
- Ivanti Cloud Services ApplianceFollow
- NASAFollow
- US Department of EnergyFollow
- Federal ReserveFollow
- PCMagFollow