Skip to content

ProductNot yet confirmed elsewhere1 publisher2 min readPublished

DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory

A court order killed two Chinese contractor hacking platforms because their command domains were hard-coded into the malware. The pivot hardware they infected is still nobody's asset.

The Product Desk

How we use AISend a correction

Photograph accompanying DOJ takedown puts hijacked cameras and routers on the critical-path asset inventory
Photo: abcnews.com

What happened

  • The Justice Department and FBI said Wednesday they had obtained a court order to shut down three domains used to run a China-based hacking operation.
  • The government names NASA, the Department of Energy, the Federal Reserve and the Justice Department itself among the victims.
  • One tool, QScan, automatically infected thousands of internet-connected devices worldwide and enrolled them in a controlled proxy network called QTRouter.
  • In September 2024 the group used an Ivanti Cloud Services Appliance zero-day against several agencies and an unnamed US security device manufacturer.
  • The FBI ties the group to eight years of activity, including vulnerability scanning and exploitation of VPN flaws to enter federal agencies.

Why it matters

  • constraint An indicator-of-compromise list is only usable where something can be queried, and consumer-grade network hardware usually has no agent, no retained logs and no owner in the asset register.
  • exposure A camera's risk is now set by what its network can reach and by who is buying access to it, which drags low-value hardware into procurement and vendor review.
  • decision Security teams have to decide whether a takedown that killed the current binaries counts as remediation or as a window before the operators stand up new infrastructure.
  • precedent Naming a corporate employer rather than pseudonymous handles builds the record for action against a company, its officers and anyone doing business with it.

The seizure worked because of a build defect on the attacker's side. qtproxy.xyz, qt-proxy.org and qt-team.com were hard-coded into both QScan and QTRouter, and the malware needed them for communication and authentication, so removing the domains left both tools inoperable [14][15]. That is a coding choice, not a capability loss, and the Justice Department's own wording is that the crackdown "should free" the affected IoT devices [19], a forecast about hardware nobody has inspected.

The throughput is the number worth keeping. On a single day in 2024, according to the FBI, QScan processed over two million scanning and penetration testing tasks [9], which works out to roughly 23 per second sustained across the full 24 hours [18]. The library behind it held more than 200 proof-of-concept exploits written in Python and was described as designed for large-scale employment [8]. None of that is research. It is a sweep of known holes at industrial volume, and it explains the target selection: cheap network hardware is abundant, findable and unowned.

The devices were transport. QTRouter mixed the infected hardware with commercial proxies and virtual private servers to conceal that the operators were in China, routing traffic through a rotating set of addresses [10][11]. Routers, security cameras and smart appliances end up on the critical path [4] not because anything valuable sits on them, but because the address in front of a federal service has to look ordinary.

What survives a domain seizure is the org chart. The affidavit says QTFY includes former People's Liberation Army members who use those relationships to obtain contracts and subcontracts supporting offensive cyber operations [5]. Federal agents say a Chinese company, Nanjing Xinjiuwei Network Technology Company, employs the group and has business relationships with the Ministry of State Security [6], and investigators say QTFY sold its hacking services to paying customers including the MSS and the PLA [12]. A contractor with a customer list treats three lost domains as a cost of doing business. The FBI's 36-page advisory, with indicators of compromise and a target list running through defense, telecommunications and higher education [16], is the part of this that outlives the takedown.

What to watch

  • Whether the US identifies the "US security device manufacturer" breached through the Ivanti zero-day.
  • Whether previously infected devices begin beaconing to replacement domains, which would show the seizure bought weeks rather than a shutdown.
  • Whether indictments or sanctions follow against Nanjing Xinjiuwei Network Technology Company or named QTFY individuals.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence68
Adoption71
Hype gap+14
Incentives62
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On Wednesday the Justice Department and the FBI announced they had secured a court order to shut down three internet domains linked to the hacking operations.

    ReportedSupportedView cited source
  2. [2]

    The US uncovered the operation while investigating a China-based group dubbed QTFY that has been developing hacking tools since 2018.

    ReportedSupportedView cited source
  3. [3]

    Victims included NASA, the Department of Energy, the Federal Reserve and the Department of Justice, among others.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. pcmag.com

    1 article · August 26, 2026

    US: China Hijacked IoT Devices to Breach NASA, Federal Agencies | PCMag

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories